Re: Proxy advantage
Kevin Kadow <[email protected]> Tue, 16 Apr 2013 10:13:51 -0400
| Newsgroups | gmane.comp.security.firewalls.wizards |
|---|---|
| Message-ID | <CAMY_91v2XZgDTLspvm6+n9Ew4G6w_d9B4aDG3e08-uwtKT=k2A@mail.gmail.com> |
--===============2055619693== Content-Type: multipart/alternative; boundary=e89a8f2343819a82bc04da7afa76 --e89a8f2343819a82bc04da7afa76 Content-Type: text/plain; charset=ISO-8859-1 Does this only apply to an explicit proxy server? Does anybody deploy a transparent proxy server and not pass DNS down to the client? Can you call it a "best practice" when it is impossible to maintain in a large diverse network? Aside from applications which are just not proxy aware, even when the application correctly uses OS proxy settings for HTTP/HTTPS/FTP/etc, it may still rely on being able to resolve external names; result is an unmanageably large whitelist for DNS lookups. Same goes with "not advertising a default route" or restricting default route HTTP/HTTPS with ACLs. Great idea, but one which quickly becomes difficult to manage on a large scale network. Once you have any unproxyable applications needing connectivity to Akamai or a similar CDN, these controls are usually abandoned as unmaintainable. Kevin Kadow --e89a8f2343819a82bc04da7afa76 Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Does this only apply to an explicit proxy server?=A0=A0 Do= es anybody deploy a transparent proxy server and not pass DNS down to the c= lient?<br><div><div><div><div><br>Can you call it a "best practice&quo= t; when it is impossible to maintain in a large diverse network?=A0 Aside f= rom applications which are just not proxy aware, even when the application = correctly uses OS proxy settings for HTTP/HTTPS/FTP/etc, it may still rely = on being able to resolve external names; result is an unmanageably large wh= itelist for DNS lookups.<br> <br></div><div>Same goes with "not advertising a default route" o= r restricting default route HTTP/HTTPS with ACLs.=A0 Great idea, but one wh= ich quickly becomes difficult to manage on a large scale network.=A0 Once y= ou have any unproxyable applications needing connectivity to Akamai or a si= milar CDN, these controls are usually abandoned as unmaintainable.<br> <br></div><div>Kevin Kadow<br></div></div></div></div></div> --e89a8f2343819a82bc04da7afa76-- --===============2055619693== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ firewall-wizards mailing list [email protected] https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards --===============2055619693==--