Господа, прошу помочь настроить "прозрачность". При указании в браузере прокси-сервера работает на ура, иначе - нет.
Ubuntu Server 7.10 + KDE, Squid v. 2.6.STABLE14
На сервере только один интерфейс eth0 с адресом 192.168.0.106
squid.conf
http_port 192.168.0.106:3128 transparent
root@ubuntu:~# iptables-save
# Generated by iptables-save v1.3.6 on Tue May 20 20:54:16 2008
*mangle
:PREROUTING ACCEPT [16810:5613595]
:INPUT ACCEPT [16810:5613595]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [18254:5769889]
:POSTROUTING ACCEPT [18305:5777418]
COMMIT
# Completed on Tue May 20 20:54:16 2008
# Generated by iptables-save v1.3.6 on Tue May 20 20:54:16 2008
*filter
:INPUT DROP [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT DROP [0:0]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 127.0.0.0/255.0.0.0 -i ! lo -j LOG
-A INPUT -s 127.0.0.0/255.0.0.0 -i ! lo -j DROP
-A INPUT -d 255.255.255.255 -i eth0 -j ACCEPT
-A INPUT -d 192.168.0.106 -i eth0 -j ACCEPT
-A INPUT -d 192.168.0.255 -i eth0 -j ACCEPT
-A INPUT -d 224.0.0.1 -j DROP
-A INPUT -j LOG
-A INPUT -j DROP
-A INPUT -d 127.0.0.1 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i eth0 -p icmp -m icmp --icmp-type 4 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 53 --dport 51024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 53 --dport 1024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 25 --dport 1024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 110 --dport 1024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 143 --dport 1024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --sport 21 --dport 1024:65535 -j ACCEPT
-A INPUT -i eth0 -p tcp -m tcp --dport 1024:65535 -m multiport --sports 80,443 -j ACCEPT
-A INPUT -i eth0 -p udp -m udp --sport 67 --dport 68 -j ACCEPT
-A FORWARD -d 224.0.0.1 -j DROP
-A FORWARD -j LOG
-A FORWARD -j DROP
-A FORWARD -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A OUTPUT -d 255.255.255.255 -o eth0 -j ACCEPT
-A OUTPUT -s 192.168.0.106 -o eth0 -j ACCEPT
-A OUTPUT -s 192.168.0.255 -o eth0 -j ACCEPT
-A OUTPUT -d 224.0.0.1 -j DROP
-A OUTPUT -j LOG
-A OUTPUT -j DROP
-A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -o eth0 -p icmp -m icmp --icmp-type 4 -j ACCEPT
-A OUTPUT -o eth0 -p udp -m udp --sport 1024:65535 --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 53 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 25 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 110 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 143 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 --dport 21 -j ACCEPT
-A OUTPUT -o eth0 -p tcp -m tcp --sport 1024:65535 -m multiport --dports 80,443 -j ACCEPT
-A OUTPUT -o eth0 -p udp -m udp --sport 68 --dport 67 -j ACCEPT
COMMIT
# Completed on Tue May 20 20:54:16 2008
# Generated by iptables-save v1.3.6 on Tue May 20 20:54:16 2008
*nat
:PREROUTING ACCEPT [1768:112225]
:POSTROUTING ACCEPT [790:53855]
:OUTPUT ACCEPT [790:53855]
[b]-A PREROUTING -d ! 192.168.0.0/255.255.255.0 -i eth0 -p tcp -m multiport --dports 80,8080 -j DNAT --to-destination 192.168.0.106:3128[/b]
COMMIT
# Completed on Tue May 20 20:54:16 2008
Заранее признателен )