Dear List,
I believe there is an error in the following excerpt from the link: http://wiki.ipfire.org/en/configuration/network/proxy/wui_conf/access
[quote]
*Disable internal proxy access to Blue from other subnets:* = If the proxy is activated and used for both zones (blue and green), there is the possibility to reach the blue zone from the green zone via http or https over the proxy. At this moment the zone separation produced by IPTables is bypassed. If this should be prevented, a hook needs to be set.
[end quote]
I believe this text has it backward. That checkbox is to prevent the blue zone to access any IP outside the blue network not the other way around. If you agree I will change the text accordingly.
Honestly, I do not know. Maybe we can get information from one of the developers? Unless you know for certain? It sounds like you have used the proxy a lot more than I have. Do you know for sure which way it works?
If you already know and are just wanting to change it, do so. If you are asking what the checkbox actually does, we can ask the developers (I'll do it if you want, or you can simply post it on development@lists.ipfire.org and someone will answer).
I think Michael is out of pocket for the moment (maybe not, I'm not sure) but he could possibly answer this. He is on this mailing list.
Rod
On 09/06/2016 12:28 PM, Carlo Fusco wrote:
Dear List,
I believe there is an error in the following excerpt from the link: http://wiki.ipfire.org/en/configuration/network/proxy/wui_conf/access
[quote]
/Disable internal proxy access to Blue from other subnets:/ = If the proxy is activated and used for both zones (blue and green), there is the possibility to reach the blue zone from the green zone via http or https over the proxy. At this moment the zone separation produced by IPTables is bypassed. If this should be prevented, a hook needs to be set.
[end quote]
I believe this text has it backward. That checkbox is to prevent the blue zone to access any IP outside the blue network not the other way around. If you agree I will change the text accordingly.
-- Carlo Fusco
Documentation mailing list Documentation@lists.ipfire.org http://lists.ipfire.org/mailman/listinfo/documentation
documentation@lists.ipfire.org