Tema: Re: Klausimas del Squid
Autorius: bash
Data: 2008-07-08 20:27:20
Kazka tu cia nusisnekejai...

Padaryk kaip sakiau:

Squid konfige padarai:
http_port 3128 transparent

Prie visu savo taisykliu pridedi:
iptables -t nat -A PREROUTING -i eth1 -d ! <tavo servo ip> -p tcp --dport
80 -j REDIRECT --to  port 3128

Viskas turetu eit.

"Nerijus" <a@a.a> wrote in message news:g506bl$qhf$1@trimpas.omnitel.net...
> Ziuriu dvi nuomones cia :)
> Bet ar kartais neturetu Squid'as ir siaip matyti visa trafica kai 
> squid.conf padarai "http_port 3128 transparent"?
>
> iptables -F
> iptables -P INPUT DROP
> iptables -P FORWARD ACCEPT
> iptables -P OUTPUT ACCEPT
> iptables -A INPUT -i lo -j ACCEPT
> #
> iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
> iptables -A INPUT -s 127.0.0.1 -j ACCEPT
> iptables -A INPUT -i eth1 -s 192.168.100.0/24 -j ACCEPT
> iptables -A INPUT -p icmp --icmp-type 8 -s 0/0 -d $WAN_IP -m state --state 
> NEW,ESTABLISHED,RELATED -j ACCEPT
> iptables -t nat -A POSTROUTING -o eth0 -j SNAT --to $WAN_IP
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 3306 -j 
> DNAT --to-destination 192.168.100.250
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5500 -j 
> DNAT --to-destination 192.168.100.95:5500
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5600 -j 
> DNAT --to-destination 192.168.100.93:5500
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5700 -j 
> DNAT --to-destination 192.168.100.51:5500
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 5701 -j 
> DNAT --to-destination 192.168.100.51:5500
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30022 -j 
> DNAT --to-destination 192.168.100.50:22
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30040 -j 
> DNAT --to-destination 192.168.100.250:3389
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 30041 -j 
> DNAT --to-destination 192.168.100.30:30041
>
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 8181 -j 
> DNAT --to-destination 192.168.100.50
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 6881 -j 
> DNAT --to-destination 192.168.100.50
> iptables -t nat -A PREROUTING --dst $WAN_IP -p tcp --dport 4444 -j 
> DNAT --to-destination 192.168.100.50
>
> iptables -A INPUT -i eth0 -p tcp --dport 20 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 21 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 22 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 80 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 1701 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 1723 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 3306 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 5600 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 5901 -j ACCEPT
> iptables -A INPUT -i eth0 -p udp --dport 5901 -j ACCEPT
> iptables -A INPUT -i eth0 -p tcp --dport 5900 -j ACCEPT
> iptables -A INPUT -i eth0 -p udp --dport 5900 -j ACCEPT
>
> #FTP Passive mode
> iptables -A INPUT -i eth0 -p tcp --dport 49152:65534 -j ACCEPT