Re: Squid proxy 2.6 with FreeBSD 6.2
- From: "Anwarul Mamun" <mamun@xxxxxxxxxxxxxxxxxxx>
- Date: Wed, 12 Sep 2007 10:50:38 +0600
I am using two different server. One is running under linux and using
iptables from which i want to forward http traffic to the FreeBSD box where
i am running Squid proxy and want to make it run as transparent proxy. The
problem is that the FreeBSD box is not working as a transparent proxy in
this scenario. It seems that the Squid proxy server at FreeBSD box doesn't
see the packet forwarded to it through the linux server.
Any suggestion?
On 9/12/07, Andrew Pantyukhin <infofarmer@xxxxxxxxxxx> wrote:
_______________________________________________
On Tue, Sep 11, 2007 at 05:23:28PM +0600, Anwarul Mamun wrote:
Hi All!hit
I have a linux gateway server (using iptables on this) where my client
first. I want to direct the http traffic to the proxy server based onproxy
FreeBSD ( i mean transparent proxy). I am using FreeBSD 6.2 and Squid
2.6. I have directed the http traffic from my linux gateway server tothe
proxy server on FreeBSD as below. But the transparent proxying does not-j
work. Is there anyone worked with the issues on transparent proxy with
FreeBSD 6.2. who may suggest in this case?
/sbin/iptables -t nat -A PREROUTING -s 192.168.40.0/24 -p tcp --dport 80
DNAT --to 172.16.3.1:80808080
/sbin/iptables -t nat -A PREROUTING -s 192.168.40.0/24 -p tcp --dport
-j DNAT --to 172.16.3.1:8080
Assuming your squid config is right, you should stop modifying
packets (with little knowledge of iptables, I think -j DNAT --to
... does that). If you manage to reroute unmodified packets to
the FreeBSD box, you'll need something like this to set up its
ipfw:
$cmd add 100 fwd 127.0.0.1,3128\
proto tcp src-ip $lan_local not src-ip me not dst-ip me\
dst-port $http_ports
$cmd add 200 allow via lo0
$cmd add 500 deny dst-ip me dst-port 3128 not src-ip $lan_local
freebsd-isp@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-isp
To unsubscribe, send any mail to "freebsd-isp-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: Squid proxy 2.6 with FreeBSD 6.2
- From: Andrew Pantyukhin
- Re: Squid proxy 2.6 with FreeBSD 6.2
- References:
- Squid proxy 2.6 with FreeBSD 6.2
- From: Anwarul Mamun
- Re: Squid proxy 2.6 with FreeBSD 6.2
- From: Andrew Pantyukhin
- Squid proxy 2.6 with FreeBSD 6.2
- Prev by Date: Re: Squid proxy 2.6 with FreeBSD 6.2
- Next by Date: Re: Squid proxy 2.6 with FreeBSD 6.2
- Previous by thread: Re: Squid proxy 2.6 with FreeBSD 6.2
- Next by thread: Re: Squid proxy 2.6 with FreeBSD 6.2
- Index(es):
Relevant Pages
|
|