From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ruslan Spivak Subject: Re: REDIRECT question Date: Wed, 02 Jul 2003 14:14:20 +0300 Sender: netfilter-admin@lists.netfilter.org Message-ID: <3F02BE8C.7020701@is.lg.ua> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Chris Wilson Cc: netfilter@lists.netfilter.org Chris Wilson wrote: >Hi Ruslan, > > > >>i want make transaparent proxy on localhost and want to disabe access >>after redirecting to port 3128 if destination address in net other then >>193.108.240.0/22. >>Does REDIRECT target send packet to INPUT chain and i should disable >>access in INPUT chain or should i disable access in '-t nat -A >>POSTROUTING' chain? >> >> > >You will not be able to disable access in the POSTROUTING chain, since >after reading the REDIRECT rule, no further rules in that chain are >processed. In any case, it is not recommended to filter in the nat table. >The best place to put your filtering rule is in the INPUT chain. > >Cheers, Chris. > Hello, Chris. I just want to be sure that after redirecting, the packet is going to input chain where i can filter it. (am i right?) Thanks for your reply. Best regards, Ruslan