Displaying 20 results from an estimated 20000 matches similar to: "Squid as a transparent proxy"
2008 Feb 25
3
shorewall 4 installation requirements
Are shorewall-shell and shorewall-common required at
compile time even if one only wishes to use
shorewall-perl (4.0.9)?
____________________________________________________________________________________
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now. http://mobile.yahoo.com/;_ylt=Ahu06i62sR8HDtDypao8Wcj9tAcJ
2005 Feb 25
6
nat problem
Hi All,
I''m using the Mandrake Linux MultiNetwork Firewall which is a web based
interface to the shorewall firewall.
I have an internal ip address of 172.25.38.1 which I am try to nat to a
public address so that the client pc can ftp to the internet
I have add the following in the nat file:
168.10.10.1 eth3 172.25.38.1 No No
And this to rules:
ACCEPT lan:172.25.38.1 wan tcp
2004 Dec 14
5
Dynamic blacklisting
Does anyone know of a script that can act as a
"helper" for Shorewall''s dynamic blacklist
capabilities?
Briefly said, I''d like to know if someone already
wrote a script/program that, e.g., parses log files
(/var/log/messages, etc) and picks up for example all
IP addresses that failed SSH login more than X times
and then executes a command such as
shorewall drop
2005 May 12
2
OpenVPN ifconfig
I''m new to openvpn and maybe I should be asking on
openvpn''s list...
But I read the tutorial:
http://www.shorewall.net/OPENVPN.html#id2452626
and saw the following:
" On System A:
ifconfig 192.168.99.1 192.168.99.2 "
I don''t understand the reason for using these "virual"
IPs.
For instance, I configured openvpn on my peers so that
the IPs on the
2004 Sep 29
10
DNAT + Masq Problem - Yes I read the FAQ I promise
I have a debian woody machine acting as a firewall for a small
network. I am trying to do a simple DNAT to port 80 on the protected
webserver and masquerade all traffic from the protect subnet outbound.
After having read the FAQ and various posts regarding problems with
DNAT I''m afraid I''m no closer to a solution. Based on the output from
"shorewall show nat" I
2008 Oct 08
19
transparent proxy
2007 Aug 30
28
Multi-Isp Masqerade ?
Mike Lander wrote:
> I am building a shorewall box that the last post has the SSH error and
> wanted
> some feedback from the list if possible. At first I thought the two ISP''s
> I
> building this
> for had two T-1''s with FQ ip''s as it. I have the box built for this ready
> to
> go.
> Now I find out that one of the T-1''s is
2008 May 30
2
one-to-one NAT on RFC1918 addresses
In my peculiar setup I need my shorewall router to do
one-to-one NAT with RFC1918 addresses.
The "external" addresses are 10.215.0.0 and the
internal addresses are 192.168.0.0.
I can ping, vnc, http, smb from 10.215.144.48 to
10.215.145.237 which is 192.168.44.237 internally.
>From 192.168.44.237 I can do http, rdp, ping to
10.215.0.0 hosts.
So all seems fine except for the fact
2005 Jan 07
3
masq or static nat
Hello,
> My server is on Mandrake 10.1 off.
> eth0 is WAN with static IP connected 512 DSL
> eth1 is LAN.
I am little confused about NAT.
I have a static IP from ISP
I want to do a NAT on eth0.
What should I use in shorewall masquerading or static nat ?
Thanks
Varun
2006 Feb 17
3
dansguardian+squid masquerading not working
Hello Everyone!
I am using shorewall-3.0.5 on suse linux.
Recently we have implemented dansguardian running on 8080 and squid on
port 3128.
Previously (before dans guardian) masquerading was working fine but
after the implementation of dansguardian masquerading is not working.
My rules file has entry
Previous entry was
ACCEPT loc:192.192.192.3 net
REDIRECT loc 8080 tcp
2004 Aug 25
6
Tricky problem of public proxy server
Hello All,
I have installed Shorewall 2.0.7 and configured , I am using masq to share internet for users.
I have problem of perticular sites . I blocked site IP address. and succeeded but i have problem of Public proxy addresses , some user use anonymous proxy Ip and get thru it and use blocked sites.
I blocked Public proxy adresses but it lot of them( I mean more than one public proxy
2004 Nov 16
4
Block Windows Messenger
Hi,
I''m trying to block Windows Messenger by Shorewall 1.4.10b, but I]m don“t have success.
If the rules below, all access are blocked
/etc/shorewall/rules
# Windows Messenger Rules
REJECT:info loc net tcp 1863
REJECT:info fw net tcp 1863
But if use the rules below, any access are allowed, why ????
/etc/shorewall/rules
# Windows
2009 Aug 29
2
ipv6
Hello,
I''m reading this guide on ipv6 (really just getting my "feet wet"):
http://www.shorewall.net/6to4.htm
In the section "Configuring IPv6 using my script" I can read that the IPv6 interfaces are:
INTERFACES="eth2 eth4"
and that correlates fine with the first diagram/figure.
However, further down I read "You will notice that sit1, eth0 and eth2
2006 Oct 13
3
Re: Tc rules Help with multiISP+ squid& squidguard...
>If you
>
>a) Have the correct REDIRECT rule (which you do); and
>b) Are accepting $FW->Net HTTP traffic (which you are -- at least with
your
>policy); and
>c) DNS works from your firewall (I assume it does since you are wide
open >from $FW->Net); then
>The problem is in your Squid configuration (this is true in %90 of the
>reports on this list where Squid
2005 Jan 30
20
FTP Transparent Proxy from Local To Net Through DMZ
Dear All,
Linux Kernel 2.4.20-8
Running Shorewall 2.2.0
ip addr show
1: lo: <LOOPBACK,UP> mtu 16436 qdisc noqueue
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 brd 127.255.255.255 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP> mtu 1500 qdisc pfifo_fast qlen 100
link/ether 00:48:54:53:82:45 brd ff:ff:ff:ff:ff:ff
inet 62.68.254.178/28 brd
2005 Mar 18
4
Using squid transparent proxy and shorewall
Hello !
I have installed and configured squid(last version) transparent proxy and i am using shorewall(last version) as a firewall. I have redirected all of my local network''s http requests to the squid port(3128). But, from my local net i cannot ping a remote machine on the internet using his hostname like google.com. I could do it only when i use a ip address. All of computers in the
2004 Nov 05
6
A distro around Shorewall
Hi all,
Currently at work we use a commercial product called "Gnatbox", which, I
believe, is a BSD derivative running on a floppy disk. They have a pretty
UI and all, but I''d feel much safer/happier with a GNU/Linux box and
Shorewall doing the same thing.
In fact, I''m doing something very close to this at home using Openwrt and
Shorewall on my WRT54G router, but I
2009 Apr 29
5
Shorewall Settings to view internal websites
We are trying to configure shorewall as follows:
1. We have shorewall running at gateway (172.16.1.1) with NAT.
2. We have a number of web servers (172.16.1.x/24). These web servers are
accessed through port forwarding at the gateway (172.16.1.1) and websites
are visible through virtual hosting through a web re-director.
3. Presently the proxy server runs in a transparent mode, i.e., all web
2002 Oct 18
2
WAN setup over frame relay 7 locations
Hi - I have shorewall-1.3.8-1 on a RH 7.3 machine that acts as a firewall
for my network. It was running the other day just fine, but today I have
problems getting to the firewall. It is a frame-relay network with Cisco
routers. Everything is 192.168.x.x / 24. I can''t ping the firewall from
the WAN, but can from the main LAN. Sounds like a routing issue to me, but
it was working for
2004 Aug 20
11
Cannot ping an address on the internet !
I have allowed ALL of the local users to ping the internet but they
currently get the following error and cannot access the internet !
I know it is something I have done wrong (I think it is a routing problem
but just cannot find out what)
The error is:-
Reply from 212.219.13.74: destination host unreachable.
My eth1 is 10.0.0.1 and the users can ping that OK
My eth0 is 212.219.13.74 (connected