RE: [fw-wiz] HTTPS, proxies, and remote developers.

From: Eugene Kuznetsov (eugene_at_datapower.com)
Date: 06/16/03

  • Next message: Gregory Austin: "Re: [fw-wiz] VA vs PT tool"
    To: "'Firewall-Wizards'" <firewall-wizards@honor.icsalabs.com>
    Date: Mon, 16 Jun 2003 13:44:33 -0400
    
    

    > me. The remote client does not like the idea.
    > What would be the easiest way to handle this situation? How would you
    > resolve a policy issue if one of your clients requires that you use
    > unencrypted traffic outbound from their network into yours.
    > (Their need to know for traffic on their network against your need for
    > security).

    Why not an outbound SSL proxy, where the developers open up an SSL
    session to the proxy, everything can be scanned in clear-text on the
    proxy, and then the proxy re-initiates an SSL connection to the
    mothership? This would also mean that only authorized staff on client
    site would be able to see the traffic, not everyone.

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Gregory Austin: "Re: [fw-wiz] VA vs PT tool"

    Relevant Pages

    • Re: ISA+Denied+WPAD
      ... I Have ISA instaled only with proxy. ... Original Client IP Client Agent Authenticated Client Service Server Name ... Referring Server Destination Host Name Transport MIME Type Object Source ... Information Network Interface Raw IP Header Raw Payload Source Port ...
      (microsoft.public.isa)
    • Re: ISA Server Problems, please help
      ... The All access rule for SBS Internet ... Web Proxy and/or ... > To accommodate the linux SecureNAT clients you should create a new Client ... ISA Server denies the specified Uniform Resource Locator. ...
      (microsoft.public.windows.server.sbs)
    • Re: question about events and proxy-server
      ... Whether or not the proxy causes problems will depend on a couple of factors: ... Does the proxy also do Network Address Translation (i.e. is the server's ... IP as seen by the client different than its IP as seen from the server). ...
      (microsoft.public.dotnet.framework.remoting)
    • Re: Need to Turn Off Proxy Server in SBS 4.5
      ... client machines (it is done by default when you install an SBS client)? ... IE's web proxy settings are disabled like you said, ... Server is internal only...no outside web or ftp serving. ...
      (microsoft.public.backoffice.smallbiz)
    • Re: Please enter password for HTTP proxy
      ... Web Proxy log: WEBEXTDyyyymmdd.log ... This newsgroup only focuses on SBS technical issues. ... |> on to the SBS server that hosts the ISA. ... |> sure the problematic clients also have Firewall Client installed. ...
      (microsoft.public.windows.server.sbs)

  • Quantcast