Beefy Boxes and Bandwidth Generously Provided by pair Networks Frank
Clear questions and runnable code
get the best and fastest answer
 
PerlMonks  

Re: verify form submission is from a specific place

by gawatkins (Monsignor)
on Jun 17, 2005 at 13:55 UTC ( #467727=note: print w/ replies, xml ) Need Help??


in reply to verify form submission is from a specific place

xorl,

First of, are their any ports currently open, possibly TCP 80 and/or TCP 443? If they are open you could use LWP::Useragent to access a page on your intranet server. The page on the intranet server would handle the AD testing and return a yes/no answer. You could then parse the output on the DMZ server for confirmation.

If there are not any ports open, you could set up a host to host rule on the firewall (Even though you said you wanted to avoid this), where inbound traffic is only permitted from the DMZ server address to the intranet server address. A rule like this is safer than just opening up the port to any internet host.

Hope this helps.
Greg W


Comment on Re: verify form submission is from a specific place
Re^2: verify form submission is from a specific place
by xorl (Deacon) on Jun 17, 2005 at 14:29 UTC
    No you currently cannot have the webserver request a page from the intranet server. I did suggest something like this. I wasn't shot down exactly, but was told they wanted other options.
      xorl,

      I don't really see much of a way solution, considering your current level of resources. As a very last possible resort you could have the DMZ server email the requests to an account on the Intranet server for processing (which is a whole different security concern), then the intranet server could post the results to a form on the DMZ server. This would REALLY slow the process down, but I believe it to be at least an option if there are not any others.

      Thanks,
      Greg W.

Log In?
Username:
Password:

What's my password?
Create A New User
Node Status?
node history
Node Type: note [id://467727]
help
Chatterbox?
and the web crawler heard nothing...

How do I use this? | Other CB clients
Other Users?
Others chanting in the Monastery: (8)
As of 2014-04-21 09:06 GMT
Sections?
Information?
Find Nodes?
Leftovers?
    Voting Booth?

    April first is:







    Results (492 votes), past polls