LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 07-10-2012, 10:38 AM   #1
dilettante9
Member
 
Registered: Jun 2012
Location: U.S.
Distribution: Debian, Xubuntu
Posts: 46

Rep: Reputation: Disabled
Port forwarding: same incoming port, two different IP addresses?


At home, I have a mixed network with Linux and Windows computers. I have a cable Internet feed and, currently, am using an appliance firewall (Linksys WRT610, running Linux IP Tables "under the hood"). However, I am considering installing a configurable firewall (Endian, Smoothwall, ClearOS, or IPCop) on a Linux box.

Here's my question. I have an Apache web server running on a Debian box, and on a separate box I have Windows Home Server, which also does web serving of a sort--specifically, WHS provides a secure remote access portal allowing me to remote in to my network from anywhere on the public Internet.

My dilemma is that both the Apache web server and the WHS web server have the capacity to serve web content over SSL (so inbound on port 443), and port forwarding on the firewall has no way to know whether an incoming packet arriving on port 443 is bound for the machine running Apache, or the machine running WHS.

What I would LIKE to be able to do is to sort packets inbound on port 443 based on the URL--meaning some type of text or string-based matching on the URL and, depending on the match result, route that packet to either of the two separate IP addresses on my network (for the Linux Apache box or the WHS box).

I'm not sure how to achieve this, though, and would appreciate any hint or guidance that anyone has. From my (limited) understanding of IP Tables (which are behind Endian, IPCop, etc.), I don't believe that IP Tables in a firewall will be able to do this type of sophisticated routing.

What do I need? Some type of filtering or redirection utility? Like Squid or something? Any hints, suggestions, or tips as to where I might get started would be greatly appreciated.

Last edited by dilettante9; 07-10-2012 at 10:53 AM.
 
Old 07-10-2012, 10:53 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
nope, not possible. The HTTP data is inside the SSL, so you'd need to terminate it etc...

put a proxypass directive under apache and proxy the WHS requests through to windows
 
Old 07-10-2012, 10:59 AM   #3
dilettante9
Member
 
Registered: Jun 2012
Location: U.S.
Distribution: Debian, Xubuntu
Posts: 46

Original Poster
Rep: Reputation: Disabled
Thanks for the suggestion, Chris. I'll look into an Apache proxypass directive. I was thinking of attempting some type of redirection at the firewall using Squid or one of its plug-ins, but the Apache proxy idea sounds much simpler.

Last edited by dilettante9; 07-10-2012 at 11:17 AM.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Port Forwarding- Want to keep Port 587 incoming closed dman777 Linux - Networking 2 10-20-2011 09:33 PM
Warning: remote port forwarding failed for listen port 7869 windstory Linux - Newbie 1 08-02-2010 10:07 AM
Shorewall: port forwarding problem, port is closed even after forwarding Synt4x_3rr0r Linux - Networking 2 12-13-2009 04:36 PM
IPCHAINS port forwarding and IPTABLES port forwarding ediestajr Linux - Networking 26 01-14-2007 07:35 PM
port forwarding does not work on additional ip addresses antken Linux - Networking 1 02-10-2004 06:51 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 08:21 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration