/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


>>>>> "CG" == Chris Garrigues <[EMAIL PROTECTED]> writes:


    CG> I've got this line in my ipchains.save:

    CG> -A input -s 10.1.2.0/8 -d default/0 80 -p tcp -j REDIRECT 3128

    CG> It says "if the source address is on my network and the destination
    CG> address is port 80, redirect it to port 3128" (which is where squid
    CG> runs).

    CG> I believe this is documented in multiple places and I suspect that
    CG> the hint that's inserted at the top of every message to this list
    CG> would have also found the answer.

I'm reviving an oooold message thread regarding transparent redirection.  The
intention here is to transparently redirect all outdoing packets destined for
port 80 (www) at any address to port 3128 on a specific internal address.
This would allow me to transparently force all my internal users' browsers to
run their URLs through squid without manually configuring each browser to use
a manual proxy.

Unfortunately, this does not make sense to me and, in any event, I cannot get
this to work.  I want to redirect the outgoing packets that are generated by
my internal network with a destination address of anywhere at port 80.  I
want them redirected from their intended external address and sent to port
3128 on one of my internal addresses.  This will transparently allow squid to
intercept the URLs and do something more intelligent with them.  The
suggestion by Chris seems to be doing the opposite: redirecting input packets
(that is, packets that are inboind to port 80 internally) and sends them to
port 3128 instead.  This is not what I want, is it?

TIA!


-- 
Jake Colman                     

Principia Partners LLC                  Phone: (201) 946-0300
Harborside Financial Center               Fax: (201) 946-0320
902 Plaza II                           Beeper: (800) 928-4640
Jersey City, NJ 07311                  E-mail: [EMAIL PROTECTED]
                                       E-mail: [EMAIL PROTECTED]
                                          web: http://www.ppllc.com

"Every time I think I've idiot-proofed something someone comes up with a
better idiot"

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to