Re: I'm wandering here.


Subject: Re: I'm wandering here.
From: Jim Dory (jdory@gci.net)
Date: Tue Dec 03 2002 - 07:20:09 AKST


Mark-Nathaniel Weisman wrote:

>Hey all,
> Is anyone got some time to explain to me the concept of using
>mod_proxy with mod_rewrite to proxy incoming HTTP requests to another
>internal server?
>
I don't have the answer but thought I would just throw out this
usergroup reference site:
http://list.cobalt.com/mailman/listinfo/cobalt-users/

They have a ton of stuff on rewrites (they talk about it all day long,
it seems) but maybe none applies to redirects to a different server.
Might only be for internal virtual sites. Might not hurt for a quick
search through the archives though.

Here's a different take but don't know if it applies:

">I am using a RaQ XTR with two NICS as a firewall. Right now, the raq
> is only machine which is the only machine directly accessing the
> internet. I would like to do a few experiments using other
> machines. How do I set up ipchains to direct traffic to another
> machine, preferable from a small subset of locations.
>
> Theser are make believe to save typing: Say I have 1.2.3.1 to 1.2.3.8
> assigne as externand and I'm using a 192.168.1.x internal network. The
> raq is currently 1.2.3.1 and 1.2.3.2 to the outside world with a
> virtual site. The internal interface is 192.168.1.1. I want to add a
> local machine 192.168.1.2 and have all traffic to 1.2.3.3 go to
> 192.168.1.2 except for what I want to reject or deny with ipchains.

<snip - one subject at a time>

I think you want to use masquerading
Set up ipchains to use masq
The simplest way to get started is use the pmfirewall tool.
Look for it at http://pointman.org
Run the install script and answer "y" for masquerading.
enter the ports/mask.
Then if you have trouble come back with specific questions."

"Ohhh! If that is what you wnat, you need port forwarding.
"Port Forwarding is only called within masquerading functions so it
fits inside the same IPCHAINS rules. Masquerading is an extension to
IP forwarding. Therefore, ipportfw only sees a packet if it fits
both the input and masquerading rule sets."

http://www.thelinuxreview.com/howto/IP-MASQ/x1525.htm
but probably start here
http://www.thelinuxreview.com/howto/IP-MASQ/book1.htm

--"

Sorry if none of this applies..
cheers, Jim

--

--------- To unsubscribe, send email to <aklug-request@aklug.org> with 'unsubscribe' in the message body.



This archive was generated by hypermail 2a23 : Tue Dec 03 2002 - 08:19:36 AKST