Re: Discriminate client requests from transparent proxy requests?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Thank you, but what I want is for our *router* to be able to tell the difference between requests from clients to origin servers (and intercept these) and requests from our transparent proxy to origin servers (and not intercept these). I'm wondering what options there are to do this because our proxy makes "transparent" requests to origin servers, with the same source address as the request from the client.

I think what you're describing instead is how the *proxy* can tell the difference between requests that were intercepted and requests that were explicitly sent to the proxy.

On 18/12/12 05:35 AM, Leonardo Rodrigues wrote:

     How about configuring two ports, one for transparent proxy and
other for your 'normal' proxy? Doing that, you could create ACLs for
matching your normal and transparent ports

     Changing the port on your transparent proxy rule will be absolutely
transparent to your users ...

http_port 12345 transparent
http_port 3128

acl transparent_access myport 12345
acl normal_access myport 3128


     i cant think on any easier way of discriminating normal and
transparent-intercepted traffic ...


Em 18/12/12 05:45, Jack Bates escreveu:
Do you have any advice how to discriminate traffic from clients from
traffic from our transparent proxy?

Our proxy sends requests to origin servers with the same source
address as the request from the client, so we can do per-host traffic
shaping on our router. But consequently I wonder how to discriminate
client requests from proxy requests, and route the former to the
proxy, but not route the latter. What options are there?

--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux