On Thursday, May 5, 2022, Marcus MERIGHI <mcmer-open...@tor.at> wrote:

> Hello Stuart, Hello Fabio,
>
> thanks for reading and suggesting!
>
>
> Exactly, though it is going to be relayd that is listening and
> forwarding to the application (or not, in case of geoblocking).
>
> Marcus
>

This way you are only blocking per IP, not Host.
I thought you needed to analyze the "Host: " inside the request before
taking the decision, per this statement:

-----
 I need to block http/s traffic, but only for some Host: header values.
I.e. domain "xyz.abc" should be reachable, domain "klm.opq" not, both
behind the same IP.
------

If https traffic inspection is not necessary, no need to add a reverse
proxy/httpd.





-- 
Atenciosamente,

Fabio Martins

(+5521) 97914-8106 (Signal)
https://www.linkedin.com/in/fabio1337br/

Reply via email to