Re: Proxy Filter iptable Settings

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 04/27/2011 07:11 PM, Mike Hendrie wrote:
Squid box 172.20.0.3
All workstations gateway are 172.20.0.3
All workstations proxy settings are 172.30.0.3:8080

The proxy settings are working fine for blocking content, however, I

Does it mean that the proxy server gives restricted access to the Internet for the machines behind it? Can they access the sites like google.com (or whatever sites allowed)?

am having the following issues:

The school's web server is hosted locally. When the workstations try
to access the site via the public domain name, it fails.

If the answer is 'yes' to the above questions, your machines should be able to access the school website as well, through the public IP.

Please ensure that the machines in the LAN are not bypassing the proxy for your school website. Because, we tend to bypass proxy for the school website (in the browser settings), as it is hosted internally (on your LAN, probably on the same machine where squid is running).

Bypassing proxy works, if the Domain Name of your school website is resolved into the local address. But, in your case, the Domain Name is getting resolved into the public address. So, it should ideally go through the proxy server.

Also check, is there any existing iptables rule which is dropping packet from your proxy server to your webserver (even if they are on the same machine), unintentionally.


Regards,
Vignesh
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux