Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 29 Dec 1998 13:32:27 +0200 (EET)
From:      pam@polynet.lviv.ua
To:        current@FreeBSD.ORG
Subject:   Transproxy: IPFilter or IPFW (was RE:wanton atticizing ...)
Message-ID:  <Pine.BSF.4.02.9812291320310.24995-100000@NetSurfer.lp.lviv.ua>
In-Reply-To: <199812281827.KAA29541@hub.freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help

Hi everybody,

In the discussion about transparent proxy support everybody should
remember about transparent support of other protocols besides HTTP. It is
only use of Host headers, that gives Squid ability to do transparency
without patching the source.

Taking into consideration other protocols - Telnet, FTP, POP3, etc proxy
needs to get information about connection destination and THAT is specific
for redirection scheme. E.g IPFilter has a ioctl to get destination.

I haven't seen any sample code for doing that under IPFW, should I use
getsockname or what? 

For me, it is extremely inconvinient to have two filtering solutions on
FreeBSD each having some unique features - Luigi's Dummynet for IPFW and
platform independence and supported by other applications like FWTK,
transparent proxy support of IPFilter :-(

Just my 0.02 cents 

Adrian Pavlykevych 			email: 		<pam@polynet.lviv.ua>
System Administrator			phone/fax:	+380 (322) 742041
State University "Lvivska Polytechnica"


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-current" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.02.9812291320310.24995-100000>