Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Accessing an Internal HTTP Site

Status
Not open for further replies.

Gabriel2010

Technical User
Nov 14, 2003
82
US
Dear All,Hello

I've been looking into SSL VPN appliances & products such as those from e-Gap and Aventail. It seems just about every SSL VPN requires an Active X and/or a Java client to be able to run in the remote-user.

Considering a lot of companies block or do not allow Active x and JVM, it's sort kills the purpose of using it the 1st place. I have some info, however, has anyone been able to deploy one of these firewalls or SSL appliances to access an internal, plain HTTP site/Intranet?

We just want to be able to access this internal site w/o the need of installing additional client software on the end-user side.
I haven't worked on Check Point firewalls in a while, I do recall they had an "HTTP server" functionality. Was able to set up the SMTP server side (store & forward at the CP firewall) but never tried the HTTP server feature. As I recall, it would allow access to an internal web site using something like, https:/ websiteetc

Any information is gladly welcome.

Gabriel


Glad to be here!
 
You can just autorize any user to go to your web server via a security rules plus a nat rules that allow you to access web server.
Otherwise you have the fonctionnality of the Authority server that allow you to identifie user and allow them to access to a web server inside the VPN domain.

regards


LaNceLoT
 
Ok.

Meaning that the HTTP server component has to be set up?
Or is this done using the public IP of the server (
The Intranet web server is not SSL enabled.

The idea is not to use any IPSEC protocols/ports, just a plain SSL connection, preferably a link (HTTPS) at the browser where user can login to access intranet.

Also, making the intranet SSL-enabled is out of the question due to the confidential data.

Thanks!

Gabriel



Glad to be here!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top