Следите за новостями русскоязычного сообщества Ubuntu в Twitter-ленте @ubuntu_ru_loco
0 Пользователей и 1 Гость просматривают эту тему.
Ну так подставьте свой интерфейс ;-)
вместо ppp0 подставьте свой внешний интерфейс. eth1, как я понимаю...
А первое сообщение в теме вы по каким мотивам не читаете? Прочитайте - там написано как сделать.
iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 -d ! 192.168.111.0/24 -j REDIRECT --to-port 3128
Покажите iptables-save
# Generated by iptables-save v1.3.6 on Wed Mar 19 08:16:42 2008*nat:PREROUTING ACCEPT [11424:1984110]:POSTROUTING ACCEPT [530:34463]:OUTPUT ACCEPT [530:34463][31:1488] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 [0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m tcp --dport 80 -j REDIRECT --to-ports 3128 COMMIT# Completed on Wed Mar 19 08:16:42 2008
1. Почему так много одного и того же правила?2. Почему оно не похоже на правило из первого сообщения?
sudo su
iptables -t nat -A PREROUTING -i eth1 -d ! 192.168.111.0/24 -p tcp -m multiport --dport 80,8080 -j DNAT --to 192.168.111.200:3128
iptables-save -c > /etc/iptables-save
# Generated by iptables-save v1.3.6 on Thu Mar 20 09:00:09 2008*nat:PREROUTING ACCEPT [7:512]:POSTROUTING ACCEPT [0:0]:OUTPUT ACCEPT [0:0][0:0] -A PREROUTING -d ! 192.168.111.0/255.255.255.0 -i eth1 -p tcp -m multiport --dports 80:8080 -j DNAT --to-destination 192.168.111.200:3128 COMMIT# Completed on Thu Mar 20 09:00:09 2008
http_port 192.168.111.200:3128 transparentcache_dir ufs /var/spool/squid 100 16 256acl all src 0.0.0.0/0.0.0.0acl manager proto cache_objectacl localhost src 127.0.0.1/255.255.255.255acl to_localhost dst 127.0.0.0/8acl SSL_ports port 443 # httpsacl SSL_ports port 563 # snewsacl SSL_ports port 873 # rsyncacl Safe_ports port 80 # httpacl Safe_ports port 21 # ftpacl Safe_ports port 443 # httpsacl Safe_ports port 70 # gopheracl Safe_ports port 210 # waisacl Safe_ports port 1025-65535 # unregistered portsacl Safe_ports port 280 # http-mgmtacl Safe_ports port 488 # gss-httpacl Safe_ports port 591 # filemakeracl Safe_ports port 777 # multiling httpacl Safe_ports port 631 # cupsacl Safe_ports port 873 # rsyncacl Safe_ports port 901 # SWATacl purge method PURGEacl CONNECT method CONNECThttp_access allow manager localhosthttp_access deny managerhttp_access allow purge localhosthttp_access deny purgehttp_access deny !Safe_portshttp_access deny CONNECT !SSL_portsacl our_networks src 192.168.111.0/24http_access allow our_networkshttp_access allow localhostvisible_hostname routehttp_access deny all
Страница сгенерирована за 0.033 секунд. Запросов: 25.