Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Reverse Proxy / Layer 7 Security

    Scheduled Pinned Locked Moved Cache/Proxy
    2 Posts 1 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      compucoder
      last edited by

      I have been trying to find a good way with 2.3.2 to implement a reverse proxy with a good layer 7 security setup. We host many SSL web sites for many clients with a lot of different domains. So, I would like a typical SSL offloading config which then proxies to HTTP to the backend web servers.

      I know many packages can do this aspect and I can run SNORT on the firewall for the IDS before the proxy.

      What I can't seem to find is the mod_security style layer 7 security capabilities; at least not in 2.3.2. I think this has to do with nginx being the default web server now and mod_security isn't rock solid on this yet.

      So, what are our options now for implementing a good reverse proxy system with tough l7 security support?

      I really want to do this on pfsense instead of having to forward all web requests to another server behind it; like a ubuntu 16 system running apache+mod_security; seems like a silly double proxy mess to me…

      Thanks for any info on how to do the above using pfsense on 2.3+

      1 Reply Last reply Reply Quote 0
      • C
        compucoder
        last edited by

        Does anyone have a guide or tips on how to install mod_security on PFSense 2.3? Module is gone now and I suspect it is due to the change to nginx; there are builds f mod_security now for nginx so am wondering if anyone has tried using it for a reverse security proxy in latest pfsense?

        Thanks

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.