FirewallWizards
[Top] [All Lists]

Re: [fw-wiz] Bridge with transparent proxy

To: "'Firewall Wizards Security Mailing List'" <firewall-wizards@listserv.cybertrust.com>
Subject: Re: [fw-wiz] Bridge with transparent proxy
From: "Mathew Want" <mathew.want@ac3.com.au>
Date: Thu, 17 May 2007 09:55:51 +1000
Delivered-to: sp-com-lists@consult.net
Delivered-to: fwwizards-list2@consult.net
Delivered-to: firewall-wizards@listserv.cybertrust.com
In-reply-to: <464AFC2A.9000002@br10.com.br>
List-archive: <https://listserv.icsalabs.com/pipermail/firewall-wizards>
List-help: <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=help>
List-id: Firewall Wizards Security Mailing List <firewall-wizards.listserv.icsalabs.com>
List-post: <mailto:firewall-wizards@listserv.icsalabs.com>
List-subscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=subscribe>
List-unsubscribe: <https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards>, <mailto:firewall-wizards-request@listserv.icsalabs.com?subject=unsubscribe>
References: <464AFC2A.9000002@br10.com.br>
Reply-to: Firewall Wizards Security Mailing List <firewall-wizards@listserv.icsalabs.com>
Sender: firewall-wizards-bounces@listserv.icsalabs.com
Thread-index: AceXzVfF9sAWzZapQ7+GpeGr//mZ+AAR1vag
Jorge,

I think the issue may be here.

> iptables -t nat -A PREROUTING -i br0 -p tcp --dport 80 \
> - -j REDIRECT --to-port 3128

I am not certain but I think that you do not want to NAT here as the proxy
will already put the external address on the packet when it issues the proxy
connection. It may be getting confused as you are trying to NAT the packet
to the external address of the box before handing the packet to SQUID.

Just my AU$0.02.

--
Regards,
Mathew Want

_______________________________________________
firewall-wizards mailing list
firewall-wizards@listserv.icsalabs.com
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards

<Prev in Thread] Current Thread [Next in Thread>