18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 8-5. News server<br />

behind the <strong>Sidewinder</strong><br />

<strong>G2</strong><br />

news client<br />

news server<br />

internal<br />

network<br />

Notes on selected proxy configurations<br />

<strong>Sidewinder</strong><br />

<strong>G2</strong><br />

external<br />

network<br />

news feed<br />

In Figure 8-5:<br />

— Your feed site must send news through the <strong>Sidewinder</strong> <strong>G2</strong>.<br />

The <strong>Sidewinder</strong> <strong>G2</strong> forces the connection to go to the server<br />

you designate as your internal news server.<br />

— If the NNTP daemon on your news server is compromised, an<br />

attacker may have full access to the internal network.<br />

— This configuration normally requires a news proxy for each<br />

direction as follows: An internal-to-external proxy must be<br />

enabled to allow your news server to send information to the<br />

feed site. A second proxy allows the feed site to send news to<br />

the internal server. The connection in both directions is<br />

handled through the <strong>Sidewinder</strong> <strong>G2</strong>. If your internal news<br />

server’s address was visible to the Internet, you could set up<br />

an external-to-internal proxy from your feed site to your news<br />

server. This is usually not the case, since you normally do not<br />

want internal addresses to be visible on the Internet.<br />

Note: If you set up the news feed using the NNTP “pull” model, you will only need an<br />

internal-to-external proxy. (For more information, see Managing UUCP and Usenet,<br />

published by O’Reilly & Associates, Inc.)<br />

— Instead <strong>of</strong> a standard external-to-internal proxy, you set up an<br />

external-to-internal news proxy using port or address<br />

redirection. Redirecting a proxy allows you to reroute a<br />

connection to a specific host system using the same or<br />

different port number as the original connection request.<br />

When you set up a proxy redirection for news, you allow a<br />

connection between your feed site and the <strong>Sidewinder</strong> <strong>G2</strong>,<br />

then provide the address <strong>of</strong> your internal news server to the<br />

<strong>Sidewinder</strong> <strong>G2</strong> so it will reroute the proxy to that server.<br />

Important: If your news server is behind the <strong>Sidewinder</strong> <strong>G2</strong>, refer to “Redirected<br />

proxy connections” on page 8-5 for additional information.<br />

Configuring Proxies 8-21

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!