Re: [squid-users] Transparent Proxy - Ethernet in promiscuous mode?

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Fri, 25 May 2001 11:37:02 +0200

The packets must be ROUTED via the intercepting host. If the host is not
in the direct path (i.e. a router in the path), then you must redirect
the traffic at a close by router.

It is not only the matter of seeing the packet, the packet must also
terminate there.

--
Henrik Nordstrom
Squid Hacker
Anjali Kulkarni wrote:
> 
> Hi,
> I want to set up a transparent proxy on my m/c, on FreeBSD 4.0. I have
> read all the related documents and have one doubt, before I start. Do
> we need to set the ethernet in promiscuous mode to make sure that it
> intercepts all packets that arrive at it's interface? IPFilter rules
> in freeBSD will work in the IP layer ie check for IP address; however,
> unless the ethernet card is in promiscuous mode, or it uses ARP to
> intercept packets not addressed to it's own IP address (by supplying
> its own MAC address during ARP), I dont see how it will work?
> Thanks,
> Anjali
Received on Fri May 25 2001 - 05:37:58 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:00:17 MST