[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Emulate real ip's to access intranet hosts from outside

I think it is worth pointing out that port-forwarding has security implications.  If one of your services is compromised (even if it is not running as root) the attacker now has a good amount of access to your local/internal network.  I would only forward ports when absolutely needed and only to a service that I absolutely trusted.


-----Original Message-----
From: Ramon Acedo <ramon.acedo@upcnet.es>
To: debian-security@lists.debian.org
Date: 13 Feb 2002 15:33:01 +0100
Subject: Re: Emulate real ip's to access intranet hosts from outside

Hi again! 
Thanks for your quickly answers,

	I think I hadn't explained enough clearly in the first mail.
The problem is the following:
I have a SINGLE public ip with an associated domain. In that host I have
a DNS server, mail server, web, etc. The important point is at the DNS.
What i'd like to do is that the firewall forward all the packets
independently of the destiny port, which can be any, to a host of the
intranet with a private ip. The rule for decide which packets go to what
host in the intranet is the name that the client refered to.
  when I do a ftp to ftp.mydomain.net my DNS server would forward the
request to the host

I'd like to have a map like this:

ftp1.mydomain.net --->
ftp2.mydomain.net --->
www1.mydomain.net --->
www2.mydomain.net --->

and so on
But Actually in the internet all that names lookup to
and of course the 192.168.x.x is never seen from the internet

I know that apache can manage vhosts and I could redirect to a intranet
host all the web traffic coming to www2.mydomain.org, the same can be
done with wu-ftp or proftp where u can have multiple domains/dubdomains
and have different ftp root directorys depending on the name the client
used to contact it, and then I could set that roots pointing to nfs
mounted directories of the internal net, but what I'd like is that all
the traffic forward would depend on the name used by the client.

As I said it's not a port forwarding matter it would be a program which
could manage domain name vhosts and do some kind of bridging /
forwarding to the intranet depending on the name the client reffered.

So the idea is to emulate lots of real ips with just 1 public ip and 1
domain with all the subdomains I'd need.

Uh! I hope to have been clear enough this time, my English is not
perfect (I'm Spanish) so please let me know if u got the idea, ok?

Thanks a lot guys!

Ramon Acedo

To UNSUBSCRIBE, email to debian-security-request@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org

Reply to: