LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-10-2008, 11:31 AM   #16
jocast
Member
 
Registered: May 2004
Location: Laredo
Distribution: FC3
Posts: 185

Original Poster
Rep: Reputation: 30

here is the log from access.log

1223137925.246 370 192.168.1.1 TCP_MISS/200 840 GET http://tta.aajr.com.mx/aplic/cgi-bin...rverinfo.html? - DIRECT/200.76.37.171 text/html
1223137925.512 190 192.168.1.1 TCP_MISS/200 356 GET http://tta.aajr.com.mx/aplic/cgi-bin/ttaprinter.cgi? - DIRECT/200.76.37.171 text/plain
1223137925.521 2 192.168.1.1 TCP_MISS/503 0 CONNECT tta.aajr.com.mx:3144 - DIRECT/- -
 
Old 11-10-2008, 01:26 PM   #17
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
What is the output of:
Code:
iptables -nvL -t nat
And, what is the error you are seeing on the clients?

Last edited by win32sux; 11-10-2008 at 01:27 PM.
 
Old 11-10-2008, 05:02 PM   #18
jocast
Member
 
Registered: May 2004
Location: Laredo
Distribution: FC3
Posts: 185

Original Poster
Rep: Reputation: 30
this is the iptables output
Chain PREROUTING (policy ACCEPT 856K packets, 78M bytes)
pkts bytes target prot opt in out source destination
2834 136K DNAT tcp -- eth1 * !192.168.1.1 0.0.0.0/0 tcp dpt:80 to:192.168.1.1:3128

Chain POSTROUTING (policy ACCEPT 957K packets, 84M bytes)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 SNAT all -- * eth1 192.168.1.0 192.168.1.1 to:192.168.1.1

and the error is

The HTTP proxy 192.168.1.1:8080 failed to connect to the server tta.aajr.com.mx:3144
The following response was returned:
HTTP/1.0 503 Service Unavailable
 
Old 11-11-2008, 06:16 AM   #19
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Quote:
Originally Posted by jocast View Post
this is the iptables output
Chain PREROUTING (policy ACCEPT 856K packets, 78M bytes)
pkts bytes target prot opt in out source destination
2834 136K DNAT tcp -- eth1 * !192.168.1.1 0.0.0.0/0 tcp dpt:80 to:192.168.1.1:3128

Chain POSTROUTING (policy ACCEPT 957K packets, 84M bytes)
pkts bytes target prot opt in out source destination
0 0 MASQUERADE all -- * eth0 0.0.0.0/0 0.0.0.0/0
0 0 SNAT all -- * eth1 192.168.1.0 192.168.1.1 to:192.168.1.1

and the error is

The HTTP proxy 192.168.1.1:8080 failed to connect to the server tta.aajr.com.mx:3144
The following response was returned:
HTTP/1.0 503 Service Unavailable
Why port 8080 instead of 3128?

Also, is this the same box which Squid is running on? I ask because of the use of DNAT instead of REDIRECT.
 
Old 11-11-2008, 10:10 AM   #20
jocast
Member
 
Registered: May 2004
Location: Laredo
Distribution: FC3
Posts: 185

Original Poster
Rep: Reputation: 30
I use dansguardian along with squid. If i change the proxy to 3128 it gives me this message in access log

1223219384.659 122 192.168.1.174 TCP_MISS/503 2303 GET http://tta.aajr.com.mx/aplic/cgi-bin...rverinfo.html? - DIRECT/tta.aajr.com.mx text/html

and the tarantella gives me the same error with port 3128
 
Old 11-11-2008, 10:55 AM   #21
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
I had forgotten about DG. What Tarantella version are you using? According to their FAQ, you need at least version 3.1 in order to use a proxy. Not sure what else to tell you, at this point I'm not even sure Squid is the problem here. I would suggest you take a step back and start troubleshooting by trying with a direct connection, then trying with a SNAT connection, then adding Squid (non-transparent), then adding Squid (transparent) then DansGuardian. As soon as you hit a step where the functionality breaks, then you know where to focus your energy. I'm sorry I can't be of any more use to you at this moment.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Squid and Dansguardian gautamnarayan Linux - Enterprise 2 11-11-2008 01:56 PM
Dansguardian + Squid SBN Linux - Server 2 07-12-2007 07:16 AM
Dansguardian and Squid yeeha! Linux - Networking 4 08-21-2006 01:22 AM
dansguardian + squid shafey Linux - Security 2 12-31-2005 11:42 AM
Dansguardian/Squid HELP! Prizam Linux - Software 3 09-23-2005 06:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:14 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration