[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1755.0. "Can AV FW be configured no-proxy in browser?" by TENNIS::KAM (AltaVista Software 714/261-4133 DTN 535.4133) Sat Feb 01 1997 03:41

    This is part two of 1754, but with a different topic.  
    
    Is it possible to configure the AltaVista Firewall, such that the
    user's don't have to configure a PROXY for their browsers?  The present
    Firewall being used doesn't put this restriction on the user's, the
    Firewall handles it.
    
    Can we configure the Firewall to do this?
    
    	Regards,
    
T.RTitleUserPersonal
Name
DateLines
1755.1NCMAIL::SMITHBSun Feb 02 1997 09:461
Yeah, disable the web relay and punch a hole in the screen for port 80...
1755.2NT VersionTENNIS::KAMAltaVista Software 714/261-4133 DTN 535.4133Sun Feb 02 1997 11:489
    I assume when you mean punch a hole you're referring to 'screend'?  I
    forgot to mention that this is the AltaVista Firewall for Windows NT,
    which only supply Application-level Proxies and the 'screend'
    equivalent won't be available until the next version.
    
    Therefore, I assume that in the NT version this would not be possible?
    
    	Regards,
    
1755.3BIGUN::nessus.cao.dec.com::MayneWake up, time to dieSun Feb 02 1997 17:003
Besides which, not all Web servers work on port 80...

PJDM
1755.4NCMAIL::SMITHBMon Feb 03 1997 09:371
Then you are stuck unless you recommend a different firewall...
1755.5QUICHE::PITTAlph a ha is better than no VAX!Wed Feb 05 1997 08:2911
    I have previously had a discussion with firewall engineering about the
    possibility of a transparent WWW proxy.  It was only during this
    discussion that I became aware (for which, read Mark Smith gently
    pointed out to me!) that this cannot ever be a total solution.
    
    The problem is that a transparent proxy is tied to a particular port
    number.  In order to do transparent WWW proxy, you would have to tie it
    to every port number on which anyone ever runs a WWW Server - that list
    is infinite ...
    
    T