Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question?
If it is not in the man pages or the how-to's this is the place! |
Notices |
Welcome to LinuxQuestions.org, a friendly and active Linux Community.
You are currently viewing LQ as a guest. By joining our community you will have the ability to post topics, receive our newsletter, use the advanced search, subscribe to threads and access many other special features. Registration is quick, simple and absolutely free. Join our community today!
Note that registered members see fewer ads, and ContentLink is completely disabled once you log in.
Are you new to LinuxQuestions.org? Visit the following links:
Site Howto |
Site FAQ |
Sitemap |
Register Now
If you have any problems with the registration process or your account login, please contact us. If you need to reset your password, click here.
Having a problem logging in? Please visit this page to clear all LQ-related cookies.
Get a virtual cloud desktop with the Linux distro that you want in less than five minutes with Shells! With over 10 pre-installed distros to choose from, the worry-free installation life is here! Whether you are a digital nomad or just looking for flexibility, Shells can put your Linux machine on the device that you want to use.
Exclusive for LQ members, get up to 45% off per month. Click here for more info.
|
 |
11-18-2009, 01:23 PM
|
#1
|
LQ Newbie
Registered: Nov 2009
Distribution: Ubuntu, RedHat
Posts: 5
Rep:
|
n00b Question: use router to direct port 80 and 443 traffic to separate proxy server?
This is probably stupid simple, but I haven't seen anything that jumps out at me. I'm happy for educational links too.
--
Coffee shop has two routed networks. One for staff and internal computers, one for public access. They're routed through an old Red Hat 4.1.2 box. The networks are working fine, but we want to use a different web filter that requires it be used as a proxy.
I would prefer not to push out PAC files to visitors and then provide tech support to support that for customers. Can I use the existing routes to direct all the public access 80 and 443 (I may decide to add others later) to the proxy without having to configure their browsers?
|
|
|
11-18-2009, 01:50 PM
|
#2
|
Moderator
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
|
Hi, welcome to LQ!
You most certainly can (not that I know which proxy you're intending to use).
Search google for "squid transparent proxy" - that should arm you with enough
ideas on how to use iptables to achieve what you're after.
And I hope that RedHat 4.1.2 means something like RedHat Enterprise Linux (RHEL 4.x);
otherwise I'd like to call you criminally insane ;D.
Cheers,
Tink
|
|
|
11-18-2009, 01:57 PM
|
#3
|
LQ Newbie
Registered: Nov 2009
Distribution: Ubuntu, RedHat
Posts: 5
Original Poster
Rep:
|
Quote:
Originally Posted by Tinkster
And I hope that RedHat 4.1.2 means something like RedHat Enterprise Linux (RHEL 4.x);
otherwise I'd like to call you criminally insane ;D.
Cheers,
Tink
|
I hope so too... It doesn't say RHEL anywhere in /proc/version. But the Kernel is 2.6.18 so that at least is sometime this century...
I had ignored the Squid references because we have a commercial web filter, but it didn't occur to me to try to glean the info from there.
Thanks!
|
|
|
11-18-2009, 02:00 PM
|
#4
|
Moderator
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
|
Quote:
Originally Posted by DurocShark
I hope so too... It doesn't say RHEL anywhere in /proc/version. But the Kernel is 2.6.18 so that at least is sometime this century...
|
Have a look at /etc/redhat-release.
Quote:
Originally Posted by DurocShark
I had ignored the Squid references because we have a commercial web filter, but it didn't occur to me to try to glean the info from there.
Thanks!
|
No worries - hope it works ok for you! Out of curiosity:
which commercial product are you using?
Cheers,
Tink
|
|
|
11-18-2009, 02:17 PM
|
#5
|
LQ Newbie
Registered: Nov 2009
Distribution: Ubuntu, RedHat
Posts: 5
Original Poster
Rep:
|
Currently we're using Websense tied to a Juniper firewall. So it's all transparent. But Websense is $$$ so I'm testing a Sophos web appliance right now.
|
|
|
11-18-2009, 02:19 PM
|
#6
|
LQ Newbie
Registered: Nov 2009
Distribution: Ubuntu, RedHat
Posts: 5
Original Poster
Rep:
|
redhat-release returns RHEL 5.2. Hmm... I wonder why /proc/version shows Red Hat 4.1?
|
|
|
11-18-2009, 03:05 PM
|
#7
|
Moderator
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
|
Quote:
Originally Posted by DurocShark
redhat-release returns RHEL 5.2. Hmm... I wonder why /proc/version shows Red Hat 4.1?
|
It doesn't :}
That's the compiler version ;}
Cheers,
Tink
|
|
|
11-18-2009, 03:07 PM
|
#8
|
Moderator
Registered: Apr 2002
Location: earth
Distribution: slackware by choice, others too :} ... android.
Posts: 23,067
|
Quote:
Originally Posted by DurocShark
Currently we're using Websense tied to a Juniper firewall. So it's all transparent. But Websense is $$$ so I'm testing a Sophos web appliance right now.
|
If you want to avoid $$$ you could have a look at the
combination Squid/DansGuardian. Does a reasonably good
job - requires some grunt on the machine if you want to
scan content for viruses, though.
Cheers,
Tink
|
|
|
11-18-2009, 03:16 PM
|
#9
|
Moderator
Registered: Mar 2008
Posts: 22,350
|
Might look at things like untangle and other open sourced devices. Can run them as virtual machines within other systems.
Should be able to use wpad.dat too.
|
|
|
11-19-2009, 06:29 AM
|
#10
|
LQ Newbie
Registered: Nov 2009
Distribution: Ubuntu, RedHat
Posts: 5
Original Poster
Rep:
|
The malware and multi-policy and AD integration are needed, which is why were going commercial.
Websense still doesn't even support NTLMv2, let alone Kerb. NTLMv1 and Lan Manager are disabled on my AD servers.
The battle is between iPrism and Sophos. iPrism pre-sales support was utter crap. Sophos has been great. Plus I use Sophos a/v on the desktops and love it.
As for what the 4.1.2... I did say I was a n00b. 
|
|
|
All times are GMT -5. The time now is 01:54 PM.
|
LinuxQuestions.org is looking for people interested in writing
Editorials, Articles, Reviews, and more. If you'd like to contribute
content, let us know.
|
Latest Threads
LQ News
|
|