Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

security/stunnel: Option to specify local bind address #4483

Open
3 tasks done
boomer41 opened this issue Jan 19, 2025 · 0 comments
Open
3 tasks done

security/stunnel: Option to specify local bind address #4483

boomer41 opened this issue Jan 19, 2025 · 0 comments

Comments

@boomer41
Copy link

Important notices
Before you add a new report, we ask you kindly to acknowledge the following:

Is your feature request related to a problem? Please describe.
I have several stunnel servers configured proxying to local service. However, those services can be reached through multiple interfaces, depending on what BGP decides.

The source ip is thus determined by the interface stunnel connects to the target service.
This makes the source ip a bit hard to predict/whitelist in other firewalls, as I have to whitelist the IP of every BGP-participating interface.

Describe the solution you'd like
I'd like to be able to configure stunnel's local option per service, letting me enter a specific source IP I'd like to have. Of course, that IP must be configured on the firewall by the admin.

Docs: https://www.stunnel.org/static/stunnel.html

local = HOST
By default, the IP address of the outgoing interface is used as the source for remote connections.
Use this option to bind a static local IP address instead.

Describe alternatives you've considered
Creating a separate VM with only one IP is a bit resource intensive and a bit overkill

Additional context
Add any other context or screenshots about the feature request here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

1 participant