Re: Proxy advantage

Kevin Kadow <[email protected]> Tue, 16 Apr 2013 10:13:51 -0400
Newsgroups gmane.comp.security.firewalls.wizards
Message-ID <CAMY_91v2XZgDTLspvm6+n9Ew4G6w_d9B4aDG3e08-uwtKT=k2A@mail.gmail.com>
--===============2055619693==
Content-Type: multipart/alternative; boundary=e89a8f2343819a82bc04da7afa76

--e89a8f2343819a82bc04da7afa76
Content-Type: text/plain; charset=ISO-8859-1

Does this only apply to an explicit proxy server?   Does anybody deploy a
transparent proxy server and not pass DNS down to the client?

Can you call it a "best practice" when it is impossible to maintain in a
large diverse network?  Aside from applications which are just not proxy
aware, even when the application correctly uses OS proxy settings for
HTTP/HTTPS/FTP/etc, it may still rely on being able to resolve external
names; result is an unmanageably large whitelist for DNS lookups.

Same goes with "not advertising a default route" or restricting default
route HTTP/HTTPS with ACLs.  Great idea, but one which quickly becomes
difficult to manage on a large scale network.  Once you have any
unproxyable applications needing connectivity to Akamai or a similar CDN,
these controls are usually abandoned as unmaintainable.

Kevin Kadow

--e89a8f2343819a82bc04da7afa76
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Does this only apply to an explicit proxy server?=A0=A0 Do=
es anybody deploy a transparent proxy server and not pass DNS down to the c=
lient?<br><div><div><div><div><br>Can you call it a &quot;best practice&quo=
t; when it is impossible to maintain in a large diverse network?=A0 Aside f=
rom applications which are just not proxy aware, even when the application =
correctly uses OS proxy settings for HTTP/HTTPS/FTP/etc, it may still rely =
on being able to resolve external names; result is an unmanageably large wh=
itelist for DNS lookups.<br>
<br></div><div>Same goes with &quot;not advertising a default route&quot; o=
r restricting default route HTTP/HTTPS with ACLs.=A0 Great idea, but one wh=
ich quickly becomes difficult to manage on a large scale network.=A0 Once y=
ou have any unproxyable applications needing connectivity to Akamai or a si=
milar CDN, these controls are usually abandoned as unmaintainable.<br>
<br></div><div>Kevin Kadow<br></div></div></div></div></div>

--e89a8f2343819a82bc04da7afa76--

--===============2055619693==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
firewall-wizards mailing list
[email protected]
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

--===============2055619693==--