18.07.2013 Views

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.2 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 9: Configuring Proxies<br />

Redirected proxy connections<br />

248<br />

Figure 122: Address<br />

redirection for inbound<br />

proxy<br />

Telnet server<br />

172.25.5.5<br />

internal<br />

network<br />

The <strong>Sidewinder</strong> <strong>G2</strong> proxy redirects<br />

(remaps) the Telnet session to address<br />

172.25.5.5 (but the address is<br />

concealed from the external network)<br />

redirect<br />

192.55.214.24<br />

<strong>Sidewinder</strong> <strong>G2</strong><br />

external<br />

network<br />

Telnet client<br />

192.55.214.25<br />

The client can access the internal<br />

server, but must use the <strong>Sidewinder</strong><br />

<strong>G2</strong> external address in the Telnet<br />

request<br />

With redirection configured, the connection is proxied to an address that is<br />

different from the original destination address. In Figure 122, a connection<br />

request from Internet address 192.55.214.25 is proxied to the external side <strong>of</strong><br />

the <strong>Sidewinder</strong> <strong>G2</strong> (192.55.214.24). The proxy then redirects the connection to<br />

172.25.5.5 and proxies the session to the internal host. From the external<br />

system’s point <strong>of</strong> view, the destination is 192.55.214.24, when in fact, the<br />

destination is really 172.25.5.5.<br />

Address redirection can also be applied to solve more complicated problems.<br />

Suppose you want to allow inbound Telnet connections to three different hosts<br />

on your internal network. If you configure your router to route multiple<br />

addresses to the <strong>Sidewinder</strong> <strong>G2</strong>, it can then accept the connections and proxy<br />

them through to hosts on the internal network. Redirected proxy connections<br />

provide the address translation between IP addresses which are valid and<br />

routed on the Internet and private IP addresses on the corporate network. So if<br />

you want to redirect all incoming connections to one <strong>of</strong> three hosts, then you<br />

must reserve three IP addresses for your <strong>Sidewinder</strong> <strong>G2</strong>, or use netmaps. (For<br />

information on using netmaps, see “Network objects” on page 105.)<br />

Note: To avoid using multiple <strong>Sidewinder</strong> <strong>G2</strong> addresses in this scenario, you could<br />

set up port redirection rather than address redirection (described in the following<br />

section).

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!