[c-nsp] Force all users on a 5300 to one web server

Elian Scrosoppi escrosoppi at ifxcorp.com
Sun Feb 27 11:51:43 EST 2005


I think you can use a 'DNS solution' (like a lockbox), a 'firewall solution' or a 'proxy solution'.

For example, with pf in OpenBSD you can do this:

rdr on INTERFACE/VLAN proto tcp from any to any port 80 -> THE_ONLY_IP_ADDRESS  port 80

and it works perfectly.

But its something difficult to find something for this if you dont give us more information about your net schema.

Greets,
--
Elian Scrosoppi
escrosoppi at ifxcorp.com


-----Original Message-----
From:	cisco-nsp-bounces at puck.nether.net on behalf of Robert Blayzor
Sent:	Sun 2/27/2005 10:34 AM
To:	Melvin C. Etheridge
Cc:	Cisco-Nsp
Subject:	Re: [c-nsp] Force all users on a 5300 to one web server
Melvin C. Etheridge wrote:
> I've tried policy routing but it's not working.
> 
> I can still view other pages.


I don't think anyone can help you unless you give more information,
including your existing configuration.

Are you looking to just transparently proxy all web traffic or just
allow them access to one web server/page and that's it?

-- 
Robert Blayzor, BOFH
INOC, LLC
rblayzor\@(inoc.net|gmail.com)
PGP: http://www.inoc.net/~dev/
Key fingerprint = 1E02 DABE F989 BC03 3DF5  0E93 8D02 9D0B CB1A A7B0

"Intel Inside" is a Government Warning requied by Law.
_______________________________________________
cisco-nsp mailing list  cisco-nsp at puck.nether.net
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/






More information about the cisco-nsp mailing list