From mboxrd@z Thu Jan 1 00:00:00 1970 From: Stanislav Nedelchev Date: Thu, 18 Aug 2005 12:45:27 +0000 Subject: [LARTC] Two internet lines and squid problem. Message-Id: <485817760508180545204aff01@mail.gmail.com> List-Id: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit To: lartc@vger.kernel.org I have 2 internet connections and i;m trying to use squid as transparent proxy but every time squid is using first internet line but i want to use second internet line . i have this settings and without squid it's working i have default route on the first internet connection. iptables -t nat -I POSTROUTING -o eth2 -p tcp --dport 80 -s 192.168.0.0/24 -d ! 192.168.0.0/16 -j SNAT --to 217.10.248.135 /sbin/ip route add default via 217.10.248.135 dev eth2 table natips /sbin/ip rule add fwmark 66 table natips iptables -t mangle -I PREROUTING -i eth1 -p tcp --dport 80 -j MARK --set-mark 66 iptables -t mangle -A FORWARD -i eth1 -p tcp --dport 80 -j MARK --set-mark 66 I try to solve the problem moving squid to onother computer and i add additional rules like /sbin/ip route add default via 217.10.248.135 dev eth2 table natips /sbin/ip route add default via 192.168.0.11 dev eth1 table squid /sbin/ip route flush cache /sbin/ip rule add fwmark 67 table squid /sbin/ip rule add fwmark 66 table natips iptables -t mangle -I PREROUTING -i eth1 -p tcp -s 192.168.0.11 --dport 80 -j MARK --set-mark 66 iptables -t mangle -I PREROUTING -i eth1 -p tcp -d ! 192.168.0.11 --dport 80 -j MARK --set-mark 67 iptables -t mangle -A FOWARD -i eth1 -s 192.168.0.11 -p tcp --dport 80 -j MARK --set-mark 66 iptables -t mangle -A FORWARD -i eth1 -p tcp -s ! 192.168.0.11 --dport 80 -j MARK --set-mark 67 iptables -t nat -I POSTROUTING -o eth2 -p tcp --dport 80 -s 192.168.0.0/24 -d ! 192.168.0.0/16 -j SNAT --to 217.10.248.135 in this case web traffic is working but pages that uses SSL like gmail.com is not working can anybody help me to use squid like transparent proxy with 2 internet connection and to use second one. Thank in advance. _______________________________________________ LARTC mailing list LARTC@mailman.ds9a.nl http://mailman.ds9a.nl/cgi-bin/mailman/listinfo/lartc