IPfilter
[Top] [All Lists]

Re: Need a one-armed port forwarder

To: ipfilter@coombs.anu.edu.au
Subject: Re: Need a one-armed port forwarder
From: Håkan Källberg <hk@simulina.se>
Date: Fri, 5 Jan 2007 05:26:12 +0100
Delivered-to: sp-com-lists@consult.net
Delivered-to: ipfilter-list@securepoint.com
In-reply-to: <e2e114e10701041506m67880131jd675a13eb0a73aa3@mail.gmail.com>
Organization: Simulina GmbH
References: <20070104022152.GA11019@cc.umanitoba.ca> <459D23F8.60603@alcatel-lucent.com> <20070104224339.GA25637@cc.umanitoba.ca> <e2e114e10701041506m67880131jd675a13eb0a73aa3@mail.gmail.com>
Sender: owner-ipfilter@coombs.anu.edu.au
On Fri, Jan 05, 2007 at 10:06:54AM +1100, Corey Johnston wrote:
> You could try stunnel. Although it also wraps the connection in ssl.
> http://www.stunnel.org
> 
> I'm actually just playing with it after reading about it on Darren's blog.
> 
> Great functionality and seems to be quite fault tolerant.
> It also has an option for transparent mode to preserve the originating IP.
> (Having problems getting transparent mode going on Sol10 though...)

Hello! Many of the answerer, like this, seam to have mainly
TCP in mind. I once tried "reflection" with ip-filter for
an UDP "connection" - and failed... The scenario was some
Digium IAX2 ATAs, analog telephone adapters, connected to an
Asterisk server. These things can only be provisioned with a
static server IP number and cannot easily be reprogrammed in
the field.  This solution would have given some flexibility
with server placement and load distribution.

The only thing I want to say, is that there might be more
interesting cases for a general solution, not only for TCP.

Håkan

Attachment: pgpxzuEcbRcgp.pgp
Description: PGP signature

<Prev in Thread] Current Thread [Next in Thread>