Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Linux / Unix Discussion
Home Forums Register Search Today's Posts Mark Forums Read

IPtables Transparent Proxy

Post New ThreadReply
 
Thread Tools Display Modes
  #16  
Old 26-Dec-2007, 11:28 PM
zebulebu's Avatar
zebulebu zebulebu is offline
Lifetime Member
Posts: 1,714
Points: 4099 zebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 pointszebulebu has over 4000 points
Power: 61
None
Join Date: 07 Aug 2006
Location: Croydon - arsehole of the universe
Age: 34
Certifications: A few
WIP: NCDA, VCP
Quote:
Originally Posted by jackd View Post
Ill give you a little background info for a better idea of my setup
The machine is running Ubuntu Server 7.10 squid version is 2.6, everything on my squid setup should be working fine if i set the proxy manually in the clients then everything is fine even https works as it should, but oviously i dont want to setup the clients manually i'd just like it to be transparent.

Heres the nat iptable on my /etc/iptables.up.rules
Code:
*nat
:PREROUTING ACCEPT [0:0]
:OUTPUT ACCEPT [0:0]
:POSTROUTING ACCEPT [0:0]
-A POSTROUTING -j MASQUERADE
#-A PREROUTING -p tcp -m tcp -i eth1 ! --dport 22 -j REDIRECT --to-ports 3128
#-A PREROUTING -p tcp -m tcp -i eth1 ! --dport 443 -j REDIRECT --to-ports 3128
#-A PREROUTING -p tcp -m tcp -i eth1 ! --dport 10000 -j REDIRECT --to-ports 3128
-A PREROUTING -p tcp -m tcp -i eth1 --dport 80 -j REDIRECT --to-ports 3128
-A PREROUTING -p tcp -m tcp -j ACCEPT
You can see the rules that i tried commented out. I cant fit my whole squid config file on here so is accessable via my webserver here
Jack - forgive me for stating the obvious, but are the lines for ports 22,443 and 10000 still commented out in your live config?


¡vamos españa!


My crappy youtube vids
 
Reply With Quote
  #17  
Old 27-Dec-2007, 08:04 AM
jackd's Avatar
jackd jackd is offline
Longterm Member
Posts: 550
Points: 236 jackd has over 100 pointsjackd has over 100 pointsjackd has over 100 points
Power: 12
None
Join Date: 14 Mar 2006
Location: Durham , UK
Age: 13
They are currently because they arent working, ive just commented them out so i dont have to recreate them all again if i need to change something. Sorry about that i was going to put it in my last post but must of forgot sorry. I needed to comment them out because some people still need to use the internet

Jack


Last edited by jackd : 27-Dec-2007 at 08:06 AM.
 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Linux / Unix Discussion


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Standalone box and ISA proxy and yum update zillah Linux / Unix Discussion 3 22-Jan-2007 02:23 PM
Web Proxy Mr.Cheeks Connectivity, Telecommunications & the Internet 1 07-Nov-2006 02:55 PM
Proxy Mr.Cheeks Software 10 03-Nov-2006 10:09 PM
Proxy Server Nelix Connectivity, Telecommunications & the Internet 15 11-Jul-2004 10:35 PM


All times are GMT. The time now is 08:36 PM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages