Linux Netfilter discussions
 help / color / mirror / Atom feed
* outbound policy for tcp 80
@ 2005-11-19 22:39 P theodorou
  2005-11-20  3:38 ` outbound policy for tcp 80 (nfcan: addressed to exclusive sender for this address) Jim Laurino
  0 siblings, 1 reply; 2+ messages in thread
From: P theodorou @ 2005-11-19 22:39 UTC (permalink / raw)
  To: netfilter

I have restricted all the connections apart from port 53, 443 and 80 on the 
forward chain. My computer uses eth1 with eth0 beeing the firewall computer.

Unfortunately when testing the outbound performance of the firewall with 
leak testers etc.. (little applications on the web) i discover that they use 
port 80 to transmit info to remote hosts. Fine and logical . How can i avoid 
this using iptables rules. I do need though Internet access.


Regards




^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: outbound policy for tcp 80 (nfcan: addressed to exclusive sender for this address)
  2005-11-19 22:39 outbound policy for tcp 80 P theodorou
@ 2005-11-20  3:38 ` Jim Laurino
  0 siblings, 0 replies; 2+ messages in thread
From: Jim Laurino @ 2005-11-20  3:38 UTC (permalink / raw)
  To: netfilter

On 2005.11.19 17:39, P theodorou - props666999@hotmail.com wrote:
> I have restricted all the connections apart from port 53, 443 and 80 on the  
> forward chain. My computer uses eth1 with eth0 beeing the firewall computer.
> 
> Unfortunately when testing the outbound performance of the firewall with  
> leak testers etc.. (little applications on the web) i discover that they use  
> port 80 to transmit info to remote hosts. Fine and logical . How can i avoid  
> this using iptables rules. I do need though Internet access.

As far as I know, you can NOT do what you want with iptables rules.
The usual approach to what you want to do is to use a proxy server.

http://www.squid-cache.org/

-- 
Jim Laurino
nfcan.x.jimlaur@dfgh.net
Please reply to the list.
Only mail from the listserver reaches this address.


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2005-11-20  3:38 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-11-19 22:39 outbound policy for tcp 80 P theodorou
2005-11-20  3:38 ` outbound policy for tcp 80 (nfcan: addressed to exclusive sender for this address) Jim Laurino

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox