433
14.9 More Proxies
This menu lets you configure the following proxy services:
FTP proxy
FTP clients may use this proxy for their connections. Uploads and downloads are
supported. Connect to port 2121 or configure transparent proxying.
SIP proxy
The SIP proxy is used by SIP clients (e.g. VoIP telephones) to connect to the
internet. The proxy can be used in two different scenarios, either as a simple proxy
or as a basix VoIP registrar. The service enables clients to cope with the NAT
barrier of the gateway. Thus the clients can be connected from the local and the
internet side.
POP3/SMTP proxy
This proxy allows mail clients to contact any POP3 and SMTP server on the
Internet. It operates as a transparent proxy only.
SOCKS proxy
SOCKS is a generic proxy, running on port 1080. With SOCKS client software you
can usually add SOCKS proxy capabilities to applications without native SOCKS
support.
14.9.1
FTP proxy
The FTP proxy allows FTP clients to access FTP servers in a secured way. In
comparison to a firewall policy which allows straight through FTP connections, proxied
connections have several advantages. There's no direct IP connection between the
FTP client and the FTP server. Restricting the accepted FTP sites prevents abuse.
Security is enhanced by validity checks of the transmitted commands and the optional
virusscan of downloads.
By default the FTP proxy will deny access to any server. A list of
accepted target servers has to be defined first. Wildcard entries
which allow access to any server are possible.
SX-GATE's FTP proxy can even operate transparent if you configure the firewall
accordingly. Transparent means that the client will not notice that the requests are
proxied. Furthermore there's no need to change the clients configuration. Change to
"Modules > Firewall > Policies" and select the interface the client is connected to.
Usually this is SX-GATE's LAN interface "eth0". Enable the redirection of connections
to port 21 on tab "Transp. proxy".
In non-transparent mode any FTP client can use the proxy, too. If the FTP client allows
you to configure an FTP proxy, you will have to enter SX-GATE as the proxy server
on port 2121. The notations for the proxy type vary. Select something like "USER