Security Basics mailing list archives

Re: A Good Reverse Proxy Product


From: "Michael Gorsuch" <michael () styledbits com>
Date: Wed, 30 Apr 2008 16:44:40 -0400

 First of all does this sound like the safest approach and if so can anyone provide the name of a good stable/secure 
reverse proxy product.

I currently use haproxy for these sorts of things.  It has worked out
just fine.  For a more robust solution, I am preparing to move towards
OpenBSD's relayd system which you may find interesting as well.  Model
it out in VMWare (or something similar) first if you can, just to get
a feel for how the configs work and to make sure that it is right for
you.

I would still consider placing a dedicated OWA server in the DMZ
behind the reverse proxy, as the proxy alone doesn't guarantee that
OWA cannot be compromised (at least to my tiny brain).

All the Best,

Michael Gorsuch
http://www.styledbits.com


Current thread: