[Search for users] [Overall Top Noters] [List of all Conferences] [Download this site]

Conference noted::seal

Title:SEAL
Moderator:GALVIA::SMITH
Created:Mon Mar 21 1994
Last Modified:Fri Jun 06 1997
Last Successful Update:Fri Jun 06 1997
Number of topics:1989
Total number of notes:8209

1913.0. "generic from out to in using telnet" by SNOFS1::stylia.sno.dec.com::snov14::stylianoua () Fri Apr 11 1997 05:42

Hi

I need confirmation on how the generic proxy works.


The solution is AFW NT on Intel.
A customer wants to allow users from the outside to telnet in to a certain host.

Does the generic proxy allow outside to inside telnet support using the generic proxy.

Aren't packets from the outside using port 25 dropped? Would I simply use another port number?

Regards
Andrew Stylianou

T.RTitleUserPersonal
Name
DateLines
1913.1Need another portOSL09::BJORNMYOpen but SecureMon Apr 14 1997 05:3610
    Note: port 25 is smtp, port 23 is telnet.
    
    You have to select another port, for instance 1001 on the firewall and
    set up the generic proxy to connect to port 23 on the host you want to
    connect to. You then do a telnet 1001 to the firewall and it will give
    you the login prompt on the internal server.
    
    Beware of security implications!
    
    Bj�rn
1913.2web generic proxyingSNOFS1::stylia.sno.dec.com::snov14::stylianouaFri Apr 18 1997 00:563
What about getting to internal web servers?

AS
1913.3CHEFS::zkodhcp-29-48-237.zko.dec.com::PITTGone with the winsock ...Fri Apr 18 1997 14:376
We've got a customer in the UK using generic relay for
inbound WWW access.  You should however discourage it
from a security point of view.  Can't the WWW Server be
placed in green net instead?

T
1913.4SNOFS1::stylia.sno.dec.com::snov14::stylianouaTue Apr 22 1997 00:3715
NT version
ok but would the user need to use the gatewayname.com:port
to get access or ip address.


Unix version - with screend implmentation to get to internal web servers.

If there were 2 web servers internally, say
www.site.com
www2.site.com

would the dns on the firewall resolve these names


Andrew S