Re: [squid-users] Problem with HTTP redirection and IPTABLES?

From: Eliezer Croitoru <eliezer_at_ngtech.co.il>
Date: Fri, 04 Jul 2014 05:29:05 +0300

On 07/04/2014 01:31 AM, Mark jensen wrote:
> I'm using centos 6.5 Linux distro
>
You do understand That you enforce the rules of a nat on a PREROUTING
table and not on an OUTPUT one...

Take a look at the example in the man pages:
http://ipset.netfilter.org/iptables-extensions.man.html

iptables -t nat -A PREROUTING -p tcp --dport 80 -m cpu --cpu 0 -j
REDIRECT --to-port 8080

iptables -t nat -A PREROUTING -p tcp --dport 80 -m cpu --cpu 1 -j
REDIRECT --to-port 8081

You cannot use a DNAT from the OUTPUT table which is a local table that
is not related to traffic that comes outside of the machine.

All The Bests,
Eliezer
Received on Fri Jul 04 2014 - 02:31:29 MDT

This archive was generated by hypermail 2.2.0 : Fri Jul 04 2014 - 12:00:05 MDT