diff options
author | Reyk Floeter <reyk@cvs.openbsd.org> | 2008-06-11 18:21:21 +0000 |
---|---|---|
committer | Reyk Floeter <reyk@cvs.openbsd.org> | 2008-06-11 18:21:21 +0000 |
commit | ae29edd6b675a26c741a63b65725a7225af083bb (patch) | |
tree | c0e7a3d34d64cecff06dc7a1e8910c1bcf97a346 /etc/etc.socppc | |
parent | d4aa7b0d42217bd71d39e0188cb451fcd0c55f72 (diff) |
add support for "transparent" forwarding in relays: normally the l7
relay will connect to the target host with its own ip address, but
this mode will let it use the address of the client that is connecting
from the other side. for example, there is no need to add the
X-Forwarded-For HTTP headers for internal webservers in this mode
anymore since they magically see the remote client ip address in the
connection. it also allows to build fully-transparent ssl
encapsulation for tcp sessions and many other things...
based on an initial idea from dlg@ and pascoe@ (dlg's talk at opencon)
using the new BINDANY and divert-reply interfaces from markus@ (since n2k8)
ok markus@ pyr@
Diffstat (limited to 'etc/etc.socppc')
0 files changed, 0 insertions, 0 deletions