in reply to Re: LWP and LocalIP/LocalPort
in thread LWP and LocalIP/LocalPort
The Short Answer:
The reason I want to set the local port as well is so the outgoing connection is predictable and filterable.
The Long Answer:
I've got a web server with MovableType running on it. One of the functions that MT performs is to send XML 'pings' or update notices to external web servers. This server and the firewall in front of it have both ingress and egress filtering in place. In other words, the web server is not allowed to contact stuff on the internet all by it's lonesome in case of virus/rootkit infection.
Now there is the quandry. I can't let this machine contact *:80 on the internet. That defeats the purpose of the egress filtering. But, if I can lock it down (kind of like Bind's query-source option) to a predictable IP/port, I can allow the software out, but other *:80 requests form the machine will still be blocked.
I could install tinyproxy in this machine to proxy those requests, but that's overkill when I should be able to specify the LocalIP/LocalPort in LWP.
|
---|
Replies are listed 'Best First'. | |
---|---|
Re: Re: Re: LWP and LocalIP/LocalPort
by jj808 (Hermit) on Oct 16, 2002 at 04:02 UTC | |
by jk2addict (Chaplain) on Oct 16, 2002 at 04:12 UTC |