Настраиваю iptables на то, чтобы заворачивались http порты на мой прокси, который висит на 192.168.0.1:3128
Содержание iptables.conf
# Generated by iptables-save v1.4.4 on Thu May 19 14:17:09 2011
*mangle
:PREROUTING ACCEPT [208308:63825679]
:INPUT ACCEPT [182317:53139815]
:FORWARD ACCEPT [25987:10685552]
:OUTPUT ACCEPT [287299:329542980]
:POSTROUTING ACCEPT [313424:340250988]
-A FORWARD -p tcp -m tcp --tcp-flags SYN,RST SYN -j TCPMSS --clamp-mss-to-pmtu
# Completed on Thu May 19 14:17:09 2011
# Generated by iptables-save v1.4.4 on Thu May 19 14:17:09 2011
*nat
:PREROUTING ACCEPT [2285:173616]
-A PREROUTING ! -d 192.168.0.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j DNAT --to-destination 192.168.0.1:3128
:OUTPUT ACCEPT [1824:114875]
:POSTROUTING ACCEPT [35:4074]
-A POSTROUTING -o eth0 -j MASQUERADE
COMMIT
# Completed on Thu May 19 14:17:09 2011
# Generated by iptables-save v1.4.4 on Thu May 19 14:17:09 2011
*filter
:INPUT ACCEPT [182317:53139815]
:FORWARD ACCEPT [25987:10685552]
:OUTPUT ACCEPT [287300:329543031]
COMMIT
# Completed on Thu May 19 14:17:09 2011
В 10.10 (на другом компе) все работало, в 11.04 почему-то нет.
P.S.: Если на клиентских тачках в браузере явно указывать прокси, то все работает