All of lore.kernel.org
 help / color / mirror / Atom feed
From: Robert Vangel <vangelr@rfgt.net>
To: netfilter@lists.netfilter.org
Subject: Re: Rules for squid via ssh tunnel
Date: Mon, 01 Aug 2005 10:16:34 +0800	[thread overview]
Message-ID: <42ED8602.5060807@rfgt.net> (raw)
In-Reply-To: <42EAE51A.3080400@ieee.org>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Gus Collins wrote:
> I believe this is suppose to be easily done, but I sure can't seem to
> make it work.  Here's my setup.
> 
> I setup a squid proxy on my firewall machine to allow http traffic from
> my wlan to be encrypted through a ssh tunnel (i.e., ssh -L
> 3128:squid_server:3128 ...).  Worked great until I added iptables to
> that setup.
> 
> My question is: what rules do I need on the server to allow my local
> wlan to access the web via the proxy running on the firewall?

You shouldn't need any rules to do with the port squid is running on. To
the firewall on the interface you are connecting through, it's all
looking like port 22.

The box you are ssh'ing to, is this the same box that squid is running on?

If so, try `ssh -L 3128:localhost:3128 [...]' (as long as squid is
listening on localhost).
> 
> I tried the rule below w/o success:
> 
> iptables -A INPUT -p tcp --dport 3128 -m state --state
> NEW,ESTABLISHED,RELATED

What did you join it to?

> 
> On the client, I have the default output policy of accept, so it should
> be ok?

Yes, but if you have still added any rules they will obviously override
the default policy.

> 
> Any help greatly appreciated!
> 
> Gus Collins
> 
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQFC7YYCV63eDkW7v4cRAnDyAJ0bg8/jiRmDUuQ2lTPKYx1BEp/aHwCfYmK+
Ne+lhWEkMVBG6Ceh5qEXX20=
=/Ad7
-----END PGP SIGNATURE-----


      reply	other threads:[~2005-08-01  2:16 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-07-30  2:25 Rules for squid via ssh tunnel Gus Collins
2005-08-01  2:16 ` Robert Vangel [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=42ED8602.5060807@rfgt.net \
    --to=vangelr@rfgt.net \
    --cc=netfilter@lists.netfilter.org \
    --cc=rob@zilla.id.au \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.