Hi,

i have a network with squid authentication on port 3128 and acl's 
controls. My users only surf with password authentication.

I don't control access port with squid acl. All ports is free by squid.

But,

i need control wich ports each machine can access by iptables. Is it 
possible?

My idea is :

- squid do not control ports, only url_path, urlpath_regex, time, password.

- iptables open and close ports (from internal mchines to internet) for 
data from proxy and other (telnet, irc, ssh and all other)

My question:

- Is it possible.

if yes:

- what chain use?
- a example, plase ;-)

if no:

- what's betther way to do this


Thanks, thanks, thanks.

Ze Luis








Reply via email to