Linux Netfilter discussions
 help / color / mirror / Atom feed
* Transparent proxy using squid, redirect all ssl/https ... ?
@ 2006-05-22  2:17 Elijah Alcantara
  2006-05-22 11:30 ` Unknown, martijn
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: Elijah Alcantara @ 2006-05-22  2:17 UTC (permalink / raw)
  To: netfilter

Hi,

It seems that implementing transparent squid proxy will cause https &
ssl to not work well on browsers ... and it would be troublesome to
manually setup proxy settings to all browsers within our network.

So I'd like to be able to redirect all other requests like
https/ssl(port 443) or email client's ports to directly access the
internet instead of going through our proxy server.

Here's a little diagram of our network:
http://static.flickr.com/49/149174815_48fa51f1a3_o.png

What I did so far is:
1. Block out all connection request from our router settings except
for our proxy server (adminserver ) only, this will force our users to
use the proxy settings for their other applications.
2. Set all client's pc's to use the new gateway 'adminserver' (our
squid server).
3. Setup transparent proxy for squid. For http requests.

Everything else is working fine so far, except that opening up
ssl-enabled sites (mail.yahoo.com) creates a timeout error and email
clients seems to not work even with proxy settings enabled.

What I need is some sort of iptable rule to grab all port 443
connections and make it connect directly to the internet ... I used
webmin to formulate a rule but that didn't work ... so I thought of
asking for help here, anyone?

Here are my current rules:
-A PREROUTING -p tcp -m tcp -i eth0 --dport 80 -j REDIRECT --to-ports 3128
-A PREROUTING -p tcp -m tcp -i eth0 --dport 443 -j DNAT
--to-destination 192.168.100.3

The first one works, it's for transparent proxy, the other one.. I
have no idea why it's not working =(


Regards,
Elijah A.


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2006-05-23  2:48 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-05-22  2:17 Transparent proxy using squid, redirect all ssl/https ... ? Elijah Alcantara
2006-05-22 11:30 ` Unknown, martijn
     [not found] ` <8963106281166041607@unknownmsgid>
2006-05-22 11:52   ` Elijah Alcantara
2006-05-22 18:26     ` Martijn Lievaart
2006-05-23  2:48       ` Elijah Alcantara
2006-05-22 13:57 ` Boryan Yotov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox