Hi
I have 3 lan cards in my system(redhat enterprise3.0). I am runing secure squid. which runs perfect when i change the LAN setting to proxy server (192.168.50.1 port 3128). But when i try to do it through iptables it doesnot not. If the changes try to do it it searchs for
/questions/newthread.php?do=newthread&f=3
instead of
http://www.linuxquestions.org/questi...=newthread&f=3
What should i do so that all trafic through this server passes through the squid port.
I am attaching the iptables script.
Sanjib gupta
# more iptables
# Generated by iptables-save v1.2.7a on Mon Apr 30 15:08:01 2007
*nat
:PREROUTING ACCEPT [163:15266]
:POSTROUTING ACCEPT [13:780]
:OUTPUT ACCEPT [13:780]
-A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to 202.141.xxx.27:80
-A PREROUTING -i eth0 -p tcp --dport 443 -j DNAT --to 202.141.xxx.26:443
-A PREROUTING -i eth2 -p tcp --dport 80 -j REDIRECT --to-port 3128
-A POSTROUTING -s 192.168.50.0/24 -o eth0 -j MASQUERADE
-A POSTROUTING -s 202.141.148.24/28 -o eth0 -j MASQUERADE
COMMIT
# Completed on Mon Apr 30 15:08:01 2007
# Generated by iptables-save v1.2.7a on Mon Apr 30 15:08:01 2007
*mangle
:PREROUTING ACCEPT [899:63753]
:INPUT ACCEPT [741:48753]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [683:50009]
:POSTROUTING ACCEPT [683:50009]
COMMIT
# Completed on Mon Apr 30 15:08:01 2007
# Generated by iptables-save v1.2.7a on Mon Apr 30 15:08:01 2007
*filter
:INPUT ACCEPT [741:48753]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [683:50009]
-A INPUT -i lo -j ACCEPT
-A INPUT -i eth0 -s 203.197.xxx.0/28 -d 0/0 -p all -j ACCEPT
-A INPUT -i eth1 -s 202.141.xxx.24/29 -d 0/0 -p all -j ACCEPT
-A INPUT -i eth2 -s 192.168.50.0/24 -d 0/0 -p all -j ACCEPT
-A FORWARD -i eth2 -s 192.168.50.0/24 -d 202.141.xxx.24/29 -p all -j ACCEPT
-A FORWARD -i eth1 -p tcp -s 202.141.xxx.24/255.255.255.240 --dport 80 -j ACCEPT
-A FORWARD -i eth1 -p tcp -s 202.141.xxx.26/255.255.255.255 --dport smtp -j ACCEPT
-A FORWARD -i eth1 -p tcp -s 202.141.xxx.24/255.255.255.240 --dport 53 -j ACCEPT
-A FORWARD -i eth1 -p udp -s 202.141.xxx.24/255.255.255.240 --dport 53 -j ACCEPT
COMMIT
# Completed on Mon Apr 30 15:08:01 2007