Can I do this with a firewall? nat with Password!



Hi

We have a URL and access to it is controlled by source IP
address, as many of our users increasingly have dynamic IP address we are
looking for a quick solution without changing the current system which is
hosted off site.



The solution I'm thinking of is to register a new URL point it's "A" record
at firewall, set the firewall rules to check the user by prompting for
username / password, then set the it to forward everything back out to the
net by using Nat and on to the
original URL where a connection will be allowed as we will add the new
firewall's public
IP address to the access list.


It is essential that the traffic flow is kept via the firewall and the we
present the firewalls source IP address to the end system not the users.


So setting aside any concerns about how secure either system will be, would
this approach work? and examples?





.



Relevant Pages

  • [NEWS] Checkpoint FW-1 VPN Security Flaw
    ... affected versions permit remote users to determine if a Firewall ... username is valid without having to know the associated password, ... Internet Key Exchange (IKE) encryption scheme and affect all Checkpoint ... FP1 and NG FP2 use only the RFC standard notify message types. ...
    (Securiteam)
  • [NEWS] Checkpoint FW-1 VPN Security Flaw (updated)
    ... affected versions permit remote users to determine if a Firewall ... username is valid without having to know the associated password, ... Internet Key Exchange (IKE) encryption scheme and affect all Checkpoint ... FP1 and NG FP2 use only the RFC standard notify message types. ...
    (Securiteam)
  • [VulnWatch] vulnerabilities in fortigate firewall webinterface
    ... Several vulnerabilities in web interface of Fortigate firewall of which ... attacker to obtain a username and password of the Fortigate. ... Username and MD5 hash of password are stored in cookie. ... WEB FILTER LOG PARSES UNFILTERED SESSION DETAILS ...
    (VulnWatch)
  • [Full-Disclosure] vulnerabilities in fortigate firewall webinterface
    ... Several vulnerabilities in web interface of Fortigate firewall of which ... attacker to obtain a username and password of the Fortigate. ... Username and MD5 hash of password are stored in cookie. ... WEB FILTER LOG PARSES UNFILTERED SESSION DETAILS ...
    (Full-Disclosure)
  • Re: FC2--cant get SMB share from nautilus
    ... Firewall off, firewall on--no difference. ... the server? ... I was able to give it a username and password and get ... It always did for nautilus running under RH9. ...
    (Fedora)