LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 09-02-2004, 07:40 PM   #1
acompw
LQ Newbie
 
Registered: Aug 2004
Distribution: Shrike & Tettnang
Posts: 18

Rep: Reputation: 0
Question Transparent Proxy Question


I am currently deploying a modified version of Dansguardian (pass through proxy) on my LAN here at camp. I have setup iptables to foward port 80 LAN traffic to DansGuardian. It all works out if I set the workstations gateway to the machine running iptables (as well as DansGuardian and Squid). A client though can easily change the gateway address to the router's ip address and bypass the port 80 routing allowing unfiltered access.

I have setup a DHCP server to give out ip addresses and auto assign the correct gateway (iptables) but there is nothing stopping someone from changing the gateway address.

How can I force all workstations to use the iptables gateway rather than the actual router gateway address. My current setup is that ALL workstations are patched directly into a router hub.

Thanks for reading this essay,
Ben

Last edited by acompw; 09-02-2004 at 07:54 PM.
 
Old 09-03-2004, 09:27 AM   #2
acompw
LQ Newbie
 
Registered: Aug 2004
Distribution: Shrike & Tettnang
Posts: 18

Original Poster
Rep: Reputation: 0
Bump, I really need a reply asap,

thanks
 
Old 09-03-2004, 10:47 AM   #3
UsualTuxpect
Member
 
Registered: Aug 2004
Location: New York
Distribution: --------- Gentoo-2004.2 [2.6.8] Redhat-9 [2.6.6]
Posts: 545

Rep: Reputation: 31
if you change the routing tables of all the clients and dont give them root access , i think your problem would be solved...
 
Old 09-03-2004, 01:27 PM   #4
acompw
LQ Newbie
 
Registered: Aug 2004
Distribution: Shrike & Tettnang
Posts: 18

Original Poster
Rep: Reputation: 0
The clients are using winboxes though

acompw
 
Old 09-03-2004, 02:14 PM   #5
stickman
Senior Member
 
Registered: Sep 2002
Location: Nashville, TN
Posts: 1,552

Rep: Reputation: 53
Filter outbound to port 80 (with the exception of the proxy box) on your router. That way even if they do change the gateway, the traffic just gets dropped.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to transparent proxy depam Linux - Software 3 12-30-2005 12:33 PM
transparent proxy mattsthe2 Linux - Networking 9 10-26-2005 08:44 AM
Transparent Proxy krock923 Linux - Networking 1 04-28-2005 06:43 PM
Transparent Proxy ilnli Linux - Networking 3 10-18-2004 06:01 PM
Transparent Proxy vinhhv Linux - Networking 0 07-23-2003 01:01 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:25 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration