Re: iptables transparent proxy

From: Cameron Kerr (cameron.kerr_at_paradise.net.nz)
Date: 06/11/04


Date: 11 Jun 2004 21:00:35 +1200

Fritz Bayer <fritz-bayer@web.de> wrote:
> Hi,
>
> I'm trying to do something very simple. I would like to forward all of
> my browsers requests to port 8888 on which a proxy server is
> listening.
>
> I have a hardware router (ADSL) on 192.168.1.1 and my linux machine
> (Debian/testing Kernel 2.6.5) has the ip 192.168.1.4.

How is your network structured? For transparent proxying to work ok,
your cache needs to be able to be in a position where it can intercept
all the traffic, or it needs to have all relevant traffic forwarded to
it. Since most ADSL routers don't have the ability to forward port 80 to
a different machine (such a thing is called a Level 4 switch), you would
likely need to configure your network in the following way.

  <Internet> --- <ADSL Router> --- <Linux> --- <Internal network>

This means that you would need to set up your Linux box as a router,
and reconfigure your ADSL router and internal clients appropriately.

Alternatively, you could set your Linux box to act as a bridge instead
of a router, but that is an advanced topic, and I can't off the top of
my head, remember how to do that.

You'll probably find it easier just to configure your browsers to use
the proxy manually, particularly if you want to play with user proxy
authentication later on.

-- 
Cameron Kerr
cameron.kerr@paradise.net.nz : http://nzgeeks.org/cameron/
Empowered by Perl!


Relevant Pages

  • Re: Port forwarding
    ... Many ADSL routers have an inbuilt logger. ... >> - What port numbers are you talking about? ... > Trying to access a web page provided by IIS6 ... >> access the server port under test from the laptop, ...
    (microsoft.public.windows.server.general)
  • Re: Port forwarding
    ... port as suggested but it still didn't work, if I try a telnet to a port ... no firewall set up on the w2k3 server). ... > Many ADSL routers have an inbuilt logger. ... >>> what does your network adapter status panel show? ...
    (microsoft.public.windows.server.general)
  • Re: Dlink DSL504
    ... On 14 Apr 2006, Saviour wrote: ... could just add a hub/switch. ... One firm I've visited has a 24 port unit ... and a second 16 or 24 port switch (they have two ADSL routers, ...
    (uk.telecom.broadband)