LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie
User Name
Password
Linux - Newbie This Linux forum is for members that are new to Linux.
Just starting out and have a question? If it is not in the man pages or the how-to's this is the place!

Notices


Reply
  Search this Thread
Old 03-05-2013, 09:16 AM   #1
proNick
Member
 
Registered: Apr 2005
Posts: 104

Rep: Reputation: 15
Ubuntu behind proxy, and access only to several IP addresses


On my local network I have to setup Linux Ubuntu boxes, so their users will be able to access only to few (2-3) domains. Also, all of those Linux Ubuntu boxes are behind Proxy.

Tried to configure this using Firestarter, but I did not make it after several hours of attempts.

Most of the time I had two cases - or I was able to access to all of Internet, or wasn't at all (in Firefox I was getting message "The proxy server is refusing connections").

IP address of Proxy server is 192.168.21.155.

What I tried with Firestarter is to define Outbound traffic policy as Restrictive by default => whitelist traffic => Allow connections to host: 192.168.21.155, and several IP addresses I want to give access. But no luck, all of the websites where blocked in this case.

Also, tried to Allow service DNS (port 53), and Http-alt (port 8080) to several IP addresses I want to give access.

But I did not make it.

Also, I removed UFW (Uncomplicated Firewall) with all of it's definition, and on Iptables I have no rule defined.

Can you help me please how to configure firewall in this case?
 
Old 03-05-2013, 09:30 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
when you've applied a rulebase, actually SHOW us the config, you can't possibly describe it. run "iptables -vnL"

If you're using an explicit proxy like you appear to be doing from the FX error, you should ONLY need to permit access to the port on the proxy server (for the web access that is, obviously there are other background default rules for other unrelated things). DNS would be done on the proxy itself, not the client under just about all configurations.

---------- Post added 05-03-13 at 03:30 PM ----------

when you've applied a rulebase, actually SHOW us the config, you can't possibly describe it. run "iptables -vnL"

If you're using an explicit proxy like you appear to be doing from the FX error, you should ONLY need to permit access to the port on the proxy server (for the web access that is, obviously there are other background default rules for other unrelated things). DNS would be done on the proxy itself, not the client under just about all configurations.
 
Old 03-05-2013, 10:21 AM   #3
proNick
Member
 
Registered: Apr 2005
Posts: 104

Original Poster
Rep: Reputation: 15
tnx, but if i give access to proxy's port 8080, i will have access to whole internet, and i need access only to several ip addresses. that's where i have a problem.
 
Old 03-05-2013, 10:47 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
configure the proxy then. That's the point of the proxy. you can't fix that by iptables if they can reach a proxy that's not configured right.
 
Old 03-05-2013, 10:52 AM   #5
proNick
Member
 
Registered: Apr 2005
Posts: 104

Original Poster
Rep: Reputation: 15
i don't have access to proxy configuration (if it is that what you mean). i can setup only linux ubuntu boxes.

and just to mention, that if firewall (in this case firestarter) is closed (disabled), i have full access to internet, so there are no problem in proxy, only problem is with firewall configuration.

Last edited by proNick; 03-05-2013 at 11:06 AM.
 
Old 03-05-2013, 02:22 PM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
so what is the firewall ruleset you're looking at using?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Ubuntu Software Center unable to Access the Web Proxy filter Nabeel Ubuntu 7 12-28-2009 11:13 AM
Squid Proxy Server Leaking Private IP Addresses jreige Linux - Software 1 08-09-2007 03:53 AM
cannot access outside ip addresses 360andy Linux - Newbie 5 11-11-2006 12:08 AM
Can access network, cannot access external addresses -Olly- Linux - Wireless Networking 2 10-08-2006 06:10 AM
how to access IP addresses when grepping ecampos02 Linux - General 1 11-05-2005 02:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Newbie

All times are GMT -5. The time now is 01:51 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration