18.07.2013 Views

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

Sidewinder G2 6.1.1 Administration Guide - Glossary of Technical ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Notes on selected proxy configurations<br />

4. [Optional] Set the keep _idle value using the sysctl command.<br />

The "keep idle" value allows you to specify the amount <strong>of</strong> time that will<br />

pass before a session’s periodic "keep alive" exchange will begin when<br />

no data is being exchanged. The default value is 7200. The following<br />

example will set the value to 300.<br />

sysctl -w net.inet.tcp.keepidle=300<br />

Important: You must also add this line to /etc/rc.local or it will be overwritten<br />

upon reboot.<br />

Notes on using the DNS proxy<br />

If you have many hosts on a trusted network that point to an external<br />

DNS server, and you want these hosts to use the unbound DNS server<br />

on the <strong>Sidewinder</strong> <strong>G2</strong> instead, you have two options:<br />

You can modify each <strong>of</strong> the individual hosts to point to the<br />

unbound DNS server.<br />

You can configure a DNS proxy rule on the <strong>Sidewinder</strong> <strong>G2</strong> that<br />

redirects the DNS traffic from the trusted burb in which the hosts<br />

reside to the unbound DNS server. This may be the preferred<br />

option if you have hundreds or thousands <strong>of</strong> local hosts, because<br />

you can make one change on the <strong>Sidewinder</strong> <strong>G2</strong> rather the<br />

hundreds or thousands <strong>of</strong> individual changes.<br />

When defining the DNS proxy rule, be sure to set the following<br />

information on the Source/Dest tab in the Proxy Rule window:<br />

— Set the Redirect Host field to 127.0.0.1<br />

— Set the NAT Address field to Localhost. The DNS proxy will not<br />

allow redirection to any other loopback addresses (127.2.0.1).<br />

Important: If your <strong>Sidewinder</strong> <strong>G2</strong> uses split DNS mode, do not create this type <strong>of</strong> proxy<br />

rule on the Internet burb, because traffic will bypass the Internet DNS name server.<br />

Configuring Proxies 8-27

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!