/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Jake Colman <[EMAIL PROTECTED]> wrote:
>
> CG> I've got this line in my ipchains.save:
>
> CG> -A input -s 10.1.2.0/8 -d default/0 80 -p tcp -j REDIRECT 3128
>
> CG> It says "if the source address is on my network and the destination
> CG> address is port 80, redirect it to port 3128" (which is where squid
> CG> runs).
>
> I'm reviving an oooold message thread regarding transparent redirection. The
> intention here is to transparently redirect all outdoing packets destined for
> port 80 (www) at any address to port 3128 on a specific internal address.
>
> Unfortunately, this does not make sense to me and, in any event, I
> cannot get this to work.
If you are on a client machine, can you test what happens when you try
to telnet to WWW service? Can you issue a "GET /" command and have it
return something useful?
> The suggestion by Chris seems to be doing the opposite: redirecting
> input packets (that is, packets that are inboind to port 80
> internally) and sends them to port 3128 instead. This is not what I
> want, is it?
Yes, that is what you want. As far as your firewall is concerned, a
request from the web is "incoming", that is, packets are coming "in"
from one of your client machines, and trying to forward "out" to the
Internet. Your input rule stops the packet as it is coming in, and
redirects it to a local process listening on port 3128.
However, standard URL lookups and proxied URL lookups use a different
syntax. By default, I believe Squid will not understand the syntax
difference, unless you tell it to look for transparent-proxied requests.
You will need to read the Squid documentation, as I don't have the
answer for you. But I suggest your problem is probably with squid,
since your ipchains rule looks correct. The only way I can see it fail
is if you have some other rule that generates an "ACCEPT" target before
the "REDIRECT" has a chance to take effect. But I doubt that.
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.