/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Thank you for your response John but I think I
not expressed very well.

The logging I'm talking about is the logging
at application level that squid does, not the IP chains
logging.

What I can not see is why changing the IP chains rules
in the kernel (rather low level) can affect something that is more high
level as the update of a log file.

I had the theory that the even when I uncommented the Squid+JunkBuster
section of the TrinityOS script to activate it maybe the HTTP traffic is not
being redirected through Squid.

But I compared the set of 3 ipchains filters for the input chain David put
in these section with the 3 ipchain rules in the  Bastille firewall script
and are equal.

echo "Optional parameter: SQUID transparent proxy"
/sbin/ipchains -A input -j ACCEPT -i $LOOPBACKIF -p tcp -d $LOOPBACKIP/32
www
/sbin/ipchains -A input -j ACCEPT -i $INTIF -p tcp -s $INTLAN -d $INTIP/32
www
/sbin/ipchains -A input -j REDIRECT 3128 -i $INTIF -p tcp -s $INTLAN -d
$BROADCAST/0 www $LOGGING

So maybe, knowing TrinityOS is the tighter ruleset, my new theory is
TrinityOS is missing some other ipchains line/s somewhere
1)To permit the redirection to occur
or
2) To permit that some internal Squid use of networking to    handle the
logging process occur

although 2) seems very improbable to me.

I posted this to see if somebody with this TrinityOS + Squid setup that I
thinks is very commonly deployed had the same problem and if so we can try
so solve here.

I apologixe for my english and thanks again John.

------Original Message------
From: John Hardy <[EMAIL PROTECTED]>
To: "'Ramiro Morales'" <[EMAIL PROTECTED]>
Sent: April 27, 2000 12:13:42 AM GMT
Subject: RE: [Masq]  TrinityOS + Squid


/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I don't have the answer for you, but you really need to know what the
script is doing.  I would suggest that as the top priority.  I might create
a rule set for you which allows everything.  And you may not know.  It
sounds like David's isn't using the -l (log) parameter.  You might want to
ask him directly.  Here is his email
[EMAIL PROTECTED]


-----Original Message-----
From:   Ramiro Morales [SMTP:[EMAIL PROTECTED]]
Sent:   Wednesday, April 26, 2000 2:18 PM
To:     [EMAIL PROTECTED]
Subject:        [Masq]  TrinityOS + Squid

/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


I have set up a fiewall + masquerading to
give Internet access to a LAN.

I installes also Squid in transparent proxy mode to do
some caching and permit control of Web usage.

I was first using the firewall script that came with the Bastille hardening
script (www.bastille-linux-org).

I switched later Ranch's TrinityOS script. And after that
Squid stoped to log the HTTP access from the LAN PCs

thi log is access.log and in RedHat is (if Squid is installed fromt RH's
RPMs) in /var/log/squid/

Did somabody noted the same behavior ?

Any hint of how can I resolve it?

If y go back to the Bastille script, the logging comes back

TIA

--
Ramiro

______________________________________________
FREE Personalized Email at Mail.com
Sign up at http://www.mail.com/?sr=signup

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS
INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

______________________________________________
FREE Personalized Email at Mail.com
Sign up at http://www.mail.com/?sr=signup

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to