Re: [squid-users] Transparent proxy issues...

From: Jon Newman <jnewman@dont-contact.us>
Date: Wed, 13 Apr 2005 20:36:22 -0500 (CDT)

Every time I put the redirect in, I can see the requests for the pages in
the dansguardian logs, but the transfer does not work/take place. Anyone
have any ideas as to why this might occur? It's as though it makes the
initial connection but does not allow the client to recieve any data?

Thanks.

Jon

> On Tue, 12 Apr 2005, Jon Newman wrote:
>
>> Using DNAT, via this command, still nets the same result:
>> iptables -t nat -A PREROUTING -p tcp -s x.x.x.x/32 --dport 80 -j DNAT
>> --to
>> 216.90.3.137:8080
>
> As I said it is equivalent. REDIRECT only saves you from entering the IP
> (automatic).
>
>> Any other ideas? I can't believe this is so difficult, this should be
>> simple and straight foreward...there must be something stupid I am
>> missing...PLEASE, anyone willing to point out my idiocy?
>
> Never ever had netfilter NAT fail on me.
>
> But if your intercepting router is running in "lollipop" mode (just one
> interface, next hop router on same interface as client station) then you
> may need disabling ICMP redirects.
>
> Regards
> Henrik
>

-- 
Jon Newman (jnewman@oplink.net)
Systems Administrator/Software Engineer
The Optimal Link (http://www.oplink.net)
Received on Wed Apr 13 2005 - 19:25:57 MDT

This archive was generated by hypermail pre-2.1.9 : Sun May 01 2005 - 12:00:03 MDT