Re: domain-based restrictions

From: Nigel Metheringham <Nigel.Metheringham@dont-contact.us>
Date: Thu, 18 Jul 1996 11:32:45 +0100

} >Nice, but I prefer this way:
} >
} >acl localnet .my.domain.com
} >http_acces allow localnet
} >
} >so sorry it's not supported :(
}
} I think I agree with Alexander about this one, we (as a University) have
} approx. 25 class 'C' nets, so I would have to list a lot of nets, whilst a
} single 'acl domain' could cover all eventualities, even sub-domains.

Can't you aggregate any of these C's?

The problem is that 'acl domain' would require a reverse DNS lookup
on each incoming request, and that can be painful speedwise for
something like squid! I guess it could be coded in in a reasonably
fast method but it would cost for all incoming requests (not just
those in the mentioned domains).

        Nigel.

-- 
[ Nigel.Metheringham@theplanet.net   - Unix Applications Engineer ]
[ *Views expressed here are personal and not supported by PLAnet* ]
[ PLAnet Online : The White House          Tel : +44 113 251 6012 ]
[ Melbourne Street, Leeds LS2 7PS UK.      Fax : +44 113 2345656  ]
Received on Thu Jul 18 1996 - 03:34:17 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:32:36 MST