----- "Howard" <[email protected]> wrote
> kswan wrote:
> Where I am now, the ProxyPass is being recognized.  Since the package
> I 
> am trying to link to uses https, I even went through the whole 
> unrecognized certificate "red alert" crap that Firefox throws up now.
> But then I see "Connecting to 10.10.1.2" in the lower left had corner
> of 
> the Firefox screen.  10.10.1.2 is the local address of the machine 
> _behind_ the proxy.  Why am I seeing that on the public side??? 
> Eventually the browser times out as the private IP cannot come back 
> (guessing) for all manner of routing reasons.
> 
> Here are snippets from the "mysite-ssl" file I building
> 
>      ProxyRequests Off
>      <Proxy *>
>       Order deny,allow
>       Allow from all
>      </Proxy>
> 
>      ProxyPass /mysite https://10.10.1.2
>      ProxyPassReverse /mysite https://10.10.1.2
> 
> There is something real obvious that I am missing.

I am guessing the last part that is necessary is the
    ProxyPreserveHost On

Remember that on a http 1.1 request, there is a Host header in the request
that tells the server what of any number of sites to serve up. Well if you
proxy the request in, without that directive, the internal server will see
the address as you placed in the 2nd argument to ProxyPass. If you preserve
the host, it will appear to the internal server as if it received the request
just like the browser made it.

Also for correctness, the ProxyPassReverse should have the URL for the site
as it would be reachable from outside of your network as the second argument.
Basically if the internal machine throws any of the 3xx codes, apache will
make sure the new location is correct based on your rule.

Between those 2, I think you can get rid of the remote browser seeing the
private address space. 

-- 
Steven Critchfield [email protected]

-- 
You received this message because you are subscribed to the Google Groups 
"NLUG" group.
To post to this group, send email to [email protected]
To unsubscribe from this group, send email to 
[email protected]
For more options, visit this group at 
http://groups.google.com/group/nlug-talk?hl=en

Reply via email to