From owner-freebsd-questions@FreeBSD.ORG Sat May 31 15:13:55 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0E130106564A for ; Sat, 31 May 2008 15:13:55 +0000 (UTC) (envelope-from peter@boosten.org) Received: from smtpq2.tilbu1.nb.home.nl (smtpq2.tilbu1.nb.home.nl [213.51.146.201]) by mx1.freebsd.org (Postfix) with ESMTP id B5D818FC12 for ; Sat, 31 May 2008 15:13:54 +0000 (UTC) (envelope-from peter@boosten.org) Received: from [213.51.146.190] (port=52105 helo=smtp1.tilbu1.nb.home.nl) by smtpq2.tilbu1.nb.home.nl with esmtp (Exim 4.60) (envelope-from ) id 1K2SmG-0003ur-36; Sat, 31 May 2008 17:13:52 +0200 Received: from cp268254-a.landg1.lb.home.nl ([84.25.65.88]:4947 helo=ra.egypt.nl) by smtp1.tilbu1.nb.home.nl with esmtp (Exim 4.60) (envelope-from ) id 1K2SmF-0000eD-N4; Sat, 31 May 2008 17:13:52 +0200 Received: from [127.0.0.1] (xp.egypt.nl [192.168.13.35]) by ra.egypt.nl (Postfix) with ESMTP id 31FAF39803; Sat, 31 May 2008 17:13:51 +0200 (CEST) Message-ID: <48416B2E.5080600@boosten.org> Date: Sat, 31 May 2008 17:13:50 +0200 From: Peter Boosten User-Agent: Thunderbird 2.0.0.14 (Windows/20080421) MIME-Version: 1.0 To: Thomas Mullins References: <537CB068C0C3DB4C857BB2719A89DC9102793F0A@mail2.wise.k12> In-Reply-To: <537CB068C0C3DB4C857BB2719A89DC9102793F0A@mail2.wise.k12> X-Enigmail-Version: 0.95.6 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Antivirus: avast! (VPS 080531-0, 05/31/2008), Outbound message X-Antivirus-Status: Clean X-Spam-Score: -0.0 (/) Cc: freebsd-questions@freebsd.org Subject: Re: Reverse proxy recommendation X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 31 May 2008 15:13:55 -0000 Thomas Mullins wrote: > Hello, > > We have three internal web servers that we make accessible to the > internet. Right now we simply use pf and port redirection. Works > great. > > But, we would like to tighten up security. I know you can do this with > squid, apache and a few others. Could someone please make a > recommendation on what solutions they have used or seen in the past? > I'm using squid as reverse proxy, for several internal hosts (just one squid reading the host-header), both as rp for 'normal' sites and as https front end. Peter -- http://www.boosten.org