Считаете, что Ubuntu недостаточно дружелюбна к новичкам? Помогите создать новое Руководство для новичков!
0 Пользователей и 1 Гость просматривают эту тему.
Голова идёт кругом от правил.
ip a ; ip r ; sysctl net.ipv4.ip_forward ; sudo iptables-savess -lnpt | grep 3128 ; grep -Ev '^#|^$' /etc/squid/squid.conf
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 16436 qdisc noqueue state UNKNOWN link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00 inet 127.0.0.1/8 scope host lo2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:27:0e:13:99:0e brd ff:ff:ff:ff:ff:ff inet 192.168.0.3/24 brd 192.168.0.255 scope global eth03: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP qlen 1000 link/ether 00:80:48:44:3d:1a brd ff:ff:ff:ff:ff:ff inet 192.168.1.1/24 brd 192.168.1.255 scope global eth14: ppp0: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN qlen 3 link/ppp inet 10.68.207.237 peer 10.64.64.64/32 scope global ppp0
default dev ppp0 scope link 10.64.64.64 dev ppp0 proto kernel scope link src 10.68.207.237 192.168.0.0/24 dev eth0 proto kernel scope link src 192.168.0.3 192.168.1.0/24 dev eth1 proto kernel scope link src 192.168.1.1
net.ipv4.ip_forward = 1
iptables-save: invalid option -- 'l'iptables-save: invalid option -- 'n'iptables-save: invalid option -- 'p'iptables-save: option requires an argument -- 't'Unknown arguments found on commandlineacl manager proto cache_objectacl localhost src 127.0.0.1/32 ::1acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1acl localnet src 192.168.0.0/24 # RFC1918 possible internal networkacl SSL_ports port 443acl Safe_ports port 80 # httpacl Safe_ports port 21 # ftpacl Safe_ports port 443 # httpsacl Safe_ports port 70 # gopheracl Safe_ports port 210 # waisacl Safe_ports port 1025-65535 # unregistered portsacl Safe_ports port 280 # http-mgmtacl Safe_ports port 488 # gss-httpacl Safe_ports port 591 # filemakeracl Safe_ports port 777 # multiling httpacl CONNECT method CONNECThttp_access allow localhosthttp_access deny managerhttp_access deny !Safe_portshttp_access deny CONNECT !SSL_portshttp_access allow localhosthttp_access deny allhttp_port 3128 cache_dir ufs /var/spool/squid3 10240 16 256maximum_object_size 10240 KBaccess_log /var/log/squid3/access.log squidpid_filename /var/run/squid3.pidcache_log /var/log/squid3/cache.logcoredump_dir /var/spool/squid3refresh_pattern \.bz2$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.exe$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.gif$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.gz$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.ico$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.jpg$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.mid$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.mp3$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.pdf$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.swf$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.tar$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.tgz$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.zip$ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://ad\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://ads\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://adv\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://click\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://count\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://counter\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://engine\. 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://img\.readme\.ru 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern http://userpic\.livejournal\.com 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.ru/bf-analyze 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern \.ru/bf-si 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern /advs/ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern /banners/ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern /cgi-bin/iframe/ 43200 100% 43200 override-lastmod override-expire ignore-reload ignore-no-cacherefresh_pattern ^ftp: 1440 20% 10080refresh_pattern ^gopher: 1440 0% 1440refresh_pattern -i (/cgi-bin/|\?) 0 0% 0refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880refresh_pattern . 0 80% 14400visible_hostname UbuntuSquiderr_page_stylesheet /etc/squid3/errorpage.cssreload_into_ims on
sudo iptables-savess -lnpt | grep 3128
[b]sudo iptables-save[/b][code]# Generated by iptables-save v1.4.12 on Sat Jun 8 19:12:45 2013*nat:PREROUTING ACCEPT [633:40109]:INPUT ACCEPT [203:14603]:OUTPUT ACCEPT [178:12097]:POSTROUTING ACCEPT [22:2546]-A POSTROUTING -o ppp0 -j MASQUERADECOMMIT# Completed on Sat Jun 8 19:12:45 2013# Generated by iptables-save v1.4.12 on Sat Jun 8 19:12:45 2013*filter:INPUT ACCEPT [1826:176669]:FORWARD ACCEPT [10310:3939049]:OUTPUT ACCEPT [1662:233712]:fail2ban-ssh - [0:0]-A INPUT -p tcp -m multiport --dports 22 -j fail2ban-ssh-A fail2ban-ssh -j RETURNCOMMIT# Completed on Sat Jun 8 19:12:45 2013
LISTEN 0 128 :::3128 :::*
Код: [Выделить]*mangle:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]-A FORWARD -o <inet_if> -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1300:1500 -j TCPMSS --clamp-mss-to-pmtu-A OUTPUT -o <inet_if> -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1300:1500 -j TCPMSS --clamp-mss-to-pmtuCOMMIT
*mangle:FORWARD ACCEPT [0:0]:OUTPUT ACCEPT [0:0]-A FORWARD -o <inet_if> -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1300:1500 -j TCPMSS --clamp-mss-to-pmtu-A OUTPUT -o <inet_if> -p tcp -m tcp --tcp-flags SYN,RST SYN -m tcpmss --mss 1300:1500 -j TCPMSS --clamp-mss-to-pmtuCOMMIT
OK, вы хотите делать прозрачный или непрозрачный прокси?
Цитата: ArcFi от 08 Июня 2013, 17:21:59OK, вы хотите делать прозрачный или непрозрачный прокси?В данный момент работает как прозрачный сервер
iptables -t nat -A PREROUTING -s 192.168.1.1/24 -i ppp0 -p tcp -m multiport --dport 80,8080 -j REDIRECT --to-ports 3128
! -i ppp0
Страница сгенерирована за 0.035 секунд. Запросов: 25.