Re: [SOLVED] Re: Transparent proxy - forwarding does not work



On Tue, Jan 15, 2008 at 03:08:55PM -0200, Eduardo M KALINOWSKI wrote:
Alex Samad wrote:
On Tue, Jan 15, 2008 at 08:11:34AM -0200, Eduardo M KALINOWSKI wrote:

Alex Samad wrote:

[snip]

Well, this solution is far more complicated than what I wanted, so I took a
look at iptables' manpage and discovered that matching can be done based on
the UID that is running the process, so the idea is to let requests made by
user 'proxy' through, and redirect all others to the proxy. This accounts
to the two lines

iptables -t nat -A OUTPUT -p tcp --dport 80 -m owner --uid-owner proxy -j
ACCEPT
iptables -t nat -A OUTPUT -p tcp --dport 80 -j REDIRECT --to-port 3128
I think there is a caveat it only works on non smp boxes !




--
Well, it's hard for a mere man to believe that woman doesn't have equal rights.
-- Dwight D. Eisenhower

Eduardo M KALINOWSKI
ekalin@xxxxxxxxx
http://move.to/hpkb


--
To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a
subject of "unsubscribe". Trouble? Contact listmaster@xxxxxxxxxxxxxxxx



--
"One of the most meaningful things that's happened to me since I've been the governor -- the president -- governor -- president. Oops. Ex-governor. I went to Bethesda Naval Hospital to give a fellow a Purple Heart, and at the same moment I watched him--get a Purple Heart for action in Iraq - and at that same - right after I gave him the Purple Heart, he was sworn in as a citizen of the United States - a Mexican citizen, now a United States citizen."

- George W. Bush
01/09/2004
Washington, DC

Attachment: signature.asc
Description: Digital signature



Relevant Pages

  • Re: "less" or "man" clear-screen issue
    ... exit. ... Which means that I always need to switch between two terminals (or ... remains of the manpage still on screen. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: less, exit but left content on screen
    ... to flip back and forth to see this manually switch to ... This is annoying, e.g., if I'm reading a manpage and want to refer to an example while I type a new command. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx with a subject of "unsubscribe". ...
    (Debian-User)
  • squid sarge x squid etch
    ... night I go to migrar it stops etch, would like to know of the opinion ... of the staff if somebody had problems with squid 2,6 as proxy ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • Re: Cron jobs and root account locked on Lenny
    ... I think that doesn't matter in this regard. ... behave as mentioned in the manpage, which would be clearly a bug. ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
    (Debian-User)
  • RE: RC.conf
    ... Gil Agno Virtucio ... machine that is running nat.. ... To unsubscribe, ...
    (freebsd-questions)