Tavve zoneranger User Manual page 42

Table of Contents

Advertisement

Figure 14-1. Proxy Access Control Example
This figure shows two management application servers (10.10.1.2 and 10.10.1.3), only one of which
(10.10.1.3) contains a Ranger Gateway. The 10.10.1.2 server is assumed to be using the 10.10.1.3 server
to relay management traffic
10.10.1.2 initiates a request destined for device 10.1.1.22, the port configuration named portConfig-
will be selected. If the same application initiates a request for any other managed device, no matching
1
port configuration will be found, and the request will be discarded. According to the portConfig table,
the portConfig-1 port configuration allows ICMP proxy and SNMP proxy on UDP port 161.
Requests from 10.10.1.2 to 10.1.1.22 involving other transport protocols and/or ports will be discarded.
Referring back to the portMap table, if an application running on server 10.10.1.3 initiates a request to
any of the managed devices, the port configuration named portConfig-2 will be used, because the
destination address pattern will match all destination addresses. The portConfig table shows
*.*.*.*
that portConfig-2 allows ICMP proxy, SNMP proxy on UDP port 161, SSH proxy on TCP port 22,
and HTTPS proxy on port 443 (which will be translated to port 8443 before presenting the request to the
target device). Requests from 10.10.1.3 involving other transport protocols and/or ports will be
discarded.
Although standard well-known port values have been used in this example for each management
protocol, it is also possible to allow supported protocols to be used on non-standard ports (e.g. to
confuse, or hide from port scanners, for improved security).
7
A management application server with no Ranger Gateway installed can proxy traffic through a
Ranger Gateway installed within another server in a variety of ways, including SOCKS, joined
ZoneRanger proxy ports (i.e. 200xx), or by enabling IP forwarding on the Ranger Gateway server, and
configuring the other server to route management traffic to the Ranger Gateway server.
ZoneRanger 5.5 User's Guide
7
. According to the portMap table, if an application running on server
42

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents