From: Paul Collins Date: Fri, 04 Nov 2005 21:06:13 GMT Subject: Re: [PATCH] v2: proxy-command support for git:// Message-ID: <87ll049l8a.fsf@briny.internal.ondioline.org> In-Reply-To: <7v7jbow8ae.fsf@assigned-by-dhcp.cox.net> Junio C Hamano writes: > Junio C Hamano writes: > >> Paul Collins writes: >> >>> Regarding internal vs. external hosts, the proxy command can simply >>> run netcat locally to internal hosts, so perhaps that is sufficient. >> >> I was hoping this to become a bit more generalized mechanism >> than that; for example using outgoing plug over HTTP Connect or >> telnet proxy using tn-gw-nav. "Run a program and talk to it via stdin/stdout" is as general as it gets, isn't it? ssh+netcat is just what I happen to use. > I realize the above does not really convey my real objection. > > Your "ssh to the proxy/firewall host and run netcat to the > destination" would not work for me to reach the internal hosts > at all (while it would work for external ones), because my > firewall does not know names of our internal hosts (the same for > using tn-gw-nav to cross http or telnet proxy). It doesn't have to be unconditional. For example, one could have: if on_blargco_network; then # internal case "$1" in *.blargco.com) exec nc "$1" "$2" ;; *) exec ssh bastion.blargco.com nc "$1" "$2" ;; esac else # external case "$1" in *.blargco.com) exec ssh bastion.blargco.com nc "$1" "$2" ;; *) exec ssh bastion nc "$1" "$2" ;; esac fi But perhaps I do not really understand your objection. -- Dag vijandelijk luchtschip de huismeester is dood