{"id":184,"date":"2009-04-23T15:59:31","date_gmt":"2009-04-23T10:29:31","guid":{"rendered":"https:\/\/www.qadit.com\/blog\/?p=184"},"modified":"2009-04-23T16:13:43","modified_gmt":"2009-04-23T10:43:43","slug":"basics-of-a-proxy-server-and-means-to-secure-it","status":"publish","type":"post","link":"https:\/\/qadit.com\/blog\/basics-of-a-proxy-server-and-means-to-secure-it\/","title":{"rendered":"Basics of a proxy server and means to secure it"},"content":{"rendered":"<p style=\"text-align: justify;\">A proxy server is a server that acts as a gateway between a client computer and a larger network like the internet.\u00a0 This can be better understood through an illustration of daily life usage of proxy server. We are familiar with configuring proxy settings in the \u2018Network Settings\u2019 tab of our web browsers. We use a proxy in this case. A proxy server receives a web page request from the local internal user. The proxy server then acts as a client on behalf of the user, uses its own IP address to request the page from the server out on the internet. When the page is returned by the internet server, the proxy server relates it to the original request and forwards it on to the local internal user.<!--more--><\/p>\n<p style=\"text-align: justify;\"><em><strong>Purpose of a proxy<\/strong><\/em><\/p>\n<p style=\"text-align: justify;\">\n<p><em>1. Hiding the local machines from the external network<\/em><br \/>\nA proxy server works by intercepting connections between sender and receiver. All incoming data enters through one port and is forwarded to the rest of the network via another port. A proxy server uses a network addressing scheme to present one organization-wide IP address to the Internet. By blocking direct access between two networks, proxy servers make it much more difficult for hackers to get internal addresses and details of a private network.<\/p>\n<p style=\"text-align: justify;\"><em>2. Caching<\/em><br \/>\nProxies may also cache web pages. Each time an internal user requests a URL from outside, a temporary copy is stored locally. The next time an internal user requests the same URL, the proxy can serve the local copy instead of retrieving the original across the network, improving performance.<\/p>\n<p style=\"text-align: justify;\"><em>3. Filtering<\/em><br \/>\nA proxy server is designed to understand, and act on the data that&#8217;s going across it. For example a company&#8217;s web proxy server can be configured to restrict access to certain sites is blocked.<\/p>\n<p style=\"text-align: justify;\"><em>4. Activity monitoring<\/em><br \/>\nA proxy can also do logging. It might track the surfing activities of employees or scan the returned web pages for viruses.<\/p>\n<p style=\"text-align: justify;\"><em>5. Sharing Internet Connection<\/em><br \/>\nProxy software may be run on the machine with the internet connection. Other machines may be configured to use the proxy server.<\/p>\n<p style=\"text-align: justify;\"><span style=\"color: #000000;\"><em><strong>How to secure a proxy?<\/strong><\/em><\/span><\/p>\n<p style=\"text-align: justify;\"><em>1. Enable only essential proxy services<\/em><br \/>\nUnless you have fairly sophisticated needs you probably won&#8217;t need to enable anything beyond the following services:<br \/>\n\u2022\u00a0\u00a0\u00a0 HTTP or WWW service \u2013 For web browsing<br \/>\n\u2022\u00a0\u00a0\u00a0 POP3 Proxy service &#8211; For incoming email.<br \/>\n\u2022\u00a0\u00a0\u00a0 SMTP mapping service &#8211; For outgoing email.<\/p>\n<p style=\"text-align: justify;\">Installation of the following services is not recommended unless they are essential for your IT operations:<br \/>\n\u2022\u00a0\u00a0\u00a0 FTP Proxy service &#8211; Needed if you run an FTP server to transfer files between your computer and Web site, or maybe if you are using some FTP client programs.(You don&#8217;t need to enable this service to FTP files to your computer if you are using your Web browser). If you do enable this service, don&#8217;t allow\u00a0 anonymous FTP unless you really need to.<br \/>\n\u2022\u00a0\u00a0\u00a0 Telnet Proxy service &#8211; allows connection to another computer to run programs and access files. If you do enable this service, require anyone Telneting into your\u00a0 computer to have their own password.<br \/>\n\u2022\u00a0\u00a0\u00a0 DNS service &#8211; Needed only if you want to run a DNS server on your LAN.<br \/>\n\u2022\u00a0\u00a0\u00a0 DHCP service &#8211; This service automatically assigns IP addresses to machines on your network.<\/p>\n<p style=\"text-align: justify;\"><em>2.\u00a0\u00a0 Access Control<\/em><br \/>\nAllow service to requests from computers that are on the local (like 192.168.0.*) subnet. If you don&#8217;t secure your site, unknown users will be able to access your proxy server for HTTP\/WWW service.\u00a0 Although you might not think this level of service would be harmful, Javascript, Java applets, multimedia files etc. can be transferred using the HTTP protocol.\u00a0 Even if this does no harm, do you really want your proxy server to be serving users you don&#8217;t even know, coming from who knows where? Another access control recommendation will be to shut off the proxy server when not in use.<\/p>\n<p style=\"text-align: justify;\"><em>3.\u00a0\u00a0 Logging<\/em><br \/>\nMost proxy server software come with logging feature. If you have properly secured your site, then when you read the logs you should see service requests only from IP addresses or computer names that are in your network.\u00a0 If you see entries from any other addresses, then unknown people are accessing your proxy server.\u00a0 You should shut off the offending service or just shut down proxy server until you can correct the problem. If you enable more services, it&#8217;s a good idea to check the logs occasionally to make sure no unauthorized people are accessing your system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A proxy server is a server that acts as a gateway between a client computer and a larger network like the internet.\u00a0 This can be better understood through an illustration of daily life usage of proxy server. We are familiar with configuring proxy settings in the \u2018Network Settings\u2019 tab of our web browsers. We use &hellip; <\/p>\n<p class=\"link-more\"><a href=\"https:\/\/qadit.com\/blog\/basics-of-a-proxy-server-and-means-to-secure-it\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Basics of a proxy server and means to secure it&#8221;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false},"version":2}},"categories":[13],"tags":[48],"class_list":["post-184","post","type-post","status-publish","format-standard","hentry","category-network","tag-proxy-server"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9AH7Q-2Y","_links":{"self":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/comments?post=184"}],"version-history":[{"count":0,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/posts\/184\/revisions"}],"wp:attachment":[{"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/media?parent=184"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/categories?post=184"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/qadit.com\/blog\/wp-json\/wp\/v2\/tags?post=184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}