[Date Prev][Date Next][Thread Prev][Thread Next][Thread Index]
Re: [fw1-gurus] Checkpoint NGX (R65) IPSO 4.2
We force ssl and just Nat our sp server. Depending on your requirements, that may be adequate
----- Original Message -----
From: fw1-gurus-bounces@xxxxxxxxxxxxxxxxxx <fw1-gurus-bounces@xxxxxxxxxxxxxxxxxx>
To: raypesek@xxxxxxxxxxxxxx <raypesek@xxxxxxxxxxxxxx>; fw1-gurus@xxxxxxxxxxxxxxxxxx <fw1-gurus@xxxxxxxxxxxxxxxxxx>
Sent: Wed Feb 04 11:44:08 2009
Subject: Re: [fw1-gurus] Checkpoint NGX (R65) IPSO 4.2
They want to implement a Sharepoint site with all resources internal, thereby needing either MS ISA or some other device that can perform reverse proxy. I think I have changed their mind and am now looking at a split back to back topology for their site implementation, but thanks for the reply.
Julie
-----Original Message-----
From: raypesek@xxxxxxxxxxxxxx [mailto:raypesek@xxxxxxxxxxxxxx]
Sent: Tuesday, February 03, 2009 7:02 PM
To: Perkins, Julie; fw1-gurus@xxxxxxxxxxxxxxxxxx
Subject: Re: [fw1-gurus] Checkpoint NGX (R65) IPSO 4.2
Hi Julie,
What are you trying to accomplish with the reverse proxy?
I haven't seen FW-1 used as a reverse proxy for several versions. In any event, I prefer to let a firewall be a firewall. I do have ISA behind FW-1and it's used for web surfing control. I also did this at my last job.
Ray
---- "Perkins wrote:
> Hello All - I am being asked by my applications team to setup reverse
> proxy on my Checkpoint so they don't have to buy MS ISA. I have read it
> can be done, my question is should it be done? Are there performance
> issues to consider?
>
>
>
> Any insight appreciated.
>
>
>
> Best regards,
>
>
>
> Julie Perkins
>
>
>
>
>
_______________________________________________
fw1-gurus mailing list
fw1-gurus@xxxxxxxxxxxxxxxxxx
http://lists.phoneboy.com/listinfo.cgi/fw1-gurus-phoneboy.com
_______________________________________________
fw1-gurus mailing list
fw1-gurus@xxxxxxxxxxxxxxxxxx
http://lists.phoneboy.com/listinfo.cgi/fw1-gurus-phoneboy.com
|