Re: Access limitation on wap gateway side.
Andreas Fink <[email protected]>
| Newsgroups | gmane.comp.mobile.kannel.devel |
|---|---|
| Message-ID | <[email protected]> |
On Donnerstag, Juni 5, 2003, at 09:50 Uhr, Vjacheslav Chekushin wrote: > Hi, list. > I have several WAP gateways on one host (bound to different > interfaces). > One of WAP gateways is allowed to go into private network, but others > not. > Therefore I must limit access to private network somewhere in WAP > gateway > internally. > > So we go to http connection limitation on WAP gateway side. > We must have following data flow (as I see it): > 1. Resolving. > 2. Check filters (must be configurable in config file?). > 3. If OK, then connect. > > Now both resolving and connecting going on socket.c > > There are two ways to implement it. > > 1. Dramatic changes: separate resolving and connecting, so http.c > first resolve host, next analize, next (if needed) make connection. > 2. Minor changes: write filter.[ch] with init and shutdown. > http.c inits and shutdowns filter part, but socket.c uses it to > check > resolved hosts. (Of course one extra parameter will be needed for > tcpip_connect_nb_to_server function (check filters or not). > > What people think about it? > I going to implement this functionality, and I want to choose right > way. > Is this functionality will be accepted? > How it must be configured? Any comments|advices? How about using a PROXY and do the filtering that way? Having this kind of filtering in Kannel can be pretty tricky. Andreas Fink Global Networks Switzerland AG ------------------------------------------------------------------ Tel: +41-61-6666333 Fax: +41-61-6666334 Mobile: +41-79-2457333 Global Networks, Inc. Clarastrasse 3, 4058 Basel, Switzerland Web: http://www.global-networks.ch/ [email protected] ------------------------------------------------------------------