Re: [help] modern iptables rule for transproxy

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Peter T. Breuer wrote:
I'd be much obliged if somebody could give me a modern iptables
equivalent for this ipchains rule

   ipchains -A input -p tcp -d 0.0.0.0/0 80 -j REDIRECT 8081

My auto-generated FW has this (with suitable replacements):

iptables -t nat -A PREROUTING -i $LOCAL_IFACE -p tcp -s ! $PROXY_BOX --dport 80 -j REDIRECT --to-ports 8081


which is intended to redirect OUTGOING packets with port 80 as
destination to port 8081 on localhost, where I have tproxy sitting
waiting to talk to the LAN web proxy and cache.

The tproxy man page doesn't give anything other than ipfw (freebsd)
or ipfwadm or ipchains (or ipnat, whatever that is) rules, but then it
was written in 2000. Perhaps the man page could be updated, with a
suitable note of thanks, when we know what to put in it!

Thanks in advance!

Peter (ptb@xxxxxxxxxxxxx, ptb@xxxxxxxxxxxxxx)


Amos
--
Please use Squid 2.6STABLE17 or 3.0STABLE1.
There are serious security advisories out on all earlier releases.

-
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux