Skip to main content

Heyho,

I have a question.

If I install a network proxy and want to secure systems in a different domain/IP address range, does the DNS resolution have to work or do I write everything manually into the host file of the network proxy?

 

How many devices need to be protected? DNS will make management easier if you can setup a separate search domain with a secondary or tertiary DNS address from the protected domain.


How many devices need to be protected? DNS will make management easier if you can setup a separate search domain with a secondary or tertiary DNS address from the protected domain.

Hey Shane,

we will start with 8 Clients.

But we will use the proxy for more/diffrent Customers. This customer is our first test


Hi @Base64 ,

 

I assume you will configure network as follows;

 

Client → Proxy ← Infra

 

That means both the clients and the CS/MAs (Infra) will be initially connecting to the proxy to find their way to each other and the Proxy should only be there expecting the connections.

In that case, both the clients and the Infra machines must be able to reach the proxy, either DNS by or IP.

As far as I am aware the Proxy machine will not need any kind of DNS since it will not be initiating any connections.


Hi @Javier , @Base64 ,

you can also use IP Address instead of hostname for the proxy.

This will remove name resolution completly.

If your network gateway is multihome (internal IP on a different interface as the customer IP), you can also create a backup network configuration between internal infrastructure systems and the proxy.
In that case the Interface Pairs defined will be used to reachout to the proxy and not its registered net hostname.

Using the gateway network topology, will help establish persistent tunnel and routes, to enable communication between infrastructure systems and clients.


Reply