Re: [fw-wiz] Transparent proxies and PMTUD on the (WWW) serverside

From: Carson Gaspar (carson_at_taltos.org)
Date: 08/28/03

  • Next message: Wade Burgett: "[fw-wiz] CISCO Hardware VPN Client Impact on Throughput"
    To: firewall-wizards@honor.icsalabs.com
    Date: Wed, 27 Aug 2003 20:49:08 -0400
    
    

    --On Wednesday, August 27, 2003 8:44 AM -0400 Rick Murphy
    <rmurphy@mitretek.org> wrote:

    > Again, why? The proxy should be slurping up bits from the client and
    > passing them up to the server (and vice-versa). The underlying IP stack
    > handles PMTUd. There's no reason for the proxy to need to know that the
    > PMTUd is taking place. (Or for the client to need to know, for that
    > matter.)

    Bzzzzt. Not if you enable transparent (or other) proxying which maintains
    the original source address (as was specified in the original example).
    This is usually given as a requirement for web servers, or other services
    that "need" to know who their clients are, and get unhappy when every
    request is from their own firewall.

    Of course, the definition of "proxy" becomes fuzzy. The same code that
    rewrites the outbound connection to fake it's source address needs to
    handle all relevant response packets, including (but not limited to) ICMP
    Would Fragment. Call it part of the proxy or not, it still needs to work
    correctly.

    -- 
    Carson
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    

  • Next message: Wade Burgett: "[fw-wiz] CISCO Hardware VPN Client Impact on Throughput"

    Relevant Pages

    • Re: ISA Server Problems, please help
      ... Based on the rules you have listed, SecureNAT clients should only be allowed ... The All access rule for SBS Internet Users ... Web Proxy and/or Firewall Client ... > header to the publishing server instead of the actual one. ...
      (microsoft.public.windows.server.sbs)
    • RE: Simple ISA 2004 questions
      ... You'd better create a new GPO for IE proxy, ... Run "gpmc.msc" in SBS server, ... ISA Server 2004 Query can give you some help. ... In the Microsoft Internet Security and Acceleration Server 2004 console, ...
      (microsoft.public.windows.server.sbs)
    • Re: 0xc0040017 FWX_E_TCP_NOT_SYN_PACKET_DROPPED bei 2 Servern von 6
      ... Ich habe mir nun auf einem Server, der sich bei MS Updateservices bedienen konnte, WSUS installiert. ... Log Time Client IP Destination IP Destination Port Protocol Action Rule Client Username Source Network Destination Network HTTP Method URL Error Information HTTP Status Code Original Client IP Client Agent Authenticated Client Service Server Name Referring Server Destination Host Name Transport MIME Type Object Source Source Proxy Destination Proxy ... Connection Unrestricted Internet access anonymous Internal External HEAD ...
      (microsoft.public.de.german.isaserver)
    • Re: Trend Micro and Proxy Server
      ... Access is from server console. ... ' under the Advanced proxy setting makes a difference. ... just turn off the proxy in the server's IE settings. ... Les Connor [SBS Community Member - SBS MVP] ...
      (microsoft.public.windows.server.sbs)
    • Re: ISA 2004 & companyweb
      ... Server, the traffic will still be handled by the ISA Server because the ... "Bypass proxy server for local addresses" option is disabled, ...
      (microsoft.public.windows.server.sbs)