Fedora Linux Support Community & Resources Center
  #1  
Old 17th November 2006, 07:20 AM
Kai-india Offline
Registered User
 
Join Date: Oct 2006
Location: Auckland, New Zealand
Age: 31
Posts: 9
Question Iptables help for novice.

Hi,

I have a Fedora Core 5 box with two NIC's in it. The services running on it are Squid (port 3128) and SAMBA to provide NTLM authentication for users on a Windows 2003 AD setup. I know all of the platform information has nothing to do with iptables but maybe it will help you understand my problem better.

Ok, now at the moment everything is working fine. Currently iptables is configured to forward all packets destined for eth1 to eth0.

I used the following iptables syntax to get this working (also enabled forwarding in sysctl.conf)

iptables -I FORWARD -i eth1 -o eth0 -j ACCEPT

I also have NAT setup on POSTROUTING on the eth0 interface.

Now I have been told and have read online that transparent proxying and NTLM do not work well together. I am fine with that.

What i want to accomplish is any client machine on the eth1 side that does not have proxy settings entered should not be able to surf the internet. That is, if a client makes a request on port 80 on eth1 then the linux box should drop/reject that request. But if same the client had proxy settings enabled, then the request for a webpage would go through port 3128.

Is this possible?? will this work? I have been experimenting with different iptables rules and no success. I feel this should be simple to accomplish.

Can someone please tell me the exact iptables syntax for dropping all requests for port 80 on eth1. Please remember a forwarding rule is in effect for eth1 to forward to eth0. Any help would be greatly appreciated.
Reply With Quote
  #2  
Old 17th November 2006, 07:22 AM
nick.stumpos's Avatar
nick.stumpos Offline
Registered User
 
Join Date: Feb 2005
Location: Lansing, Mi
Age: 28
Posts: 2,222
I have personally never used it, but firestarter is a gui for iptable, maybe it will make this task easier for you
__________________
As always
Love, Life, Loyalty, Wisdom, Knowledge, And Understanding
FC6: Common Questions answered
Reply With Quote
  #3  
Old 17th November 2006, 07:27 AM
Kai-india Offline
Registered User
 
Join Date: Oct 2006
Location: Auckland, New Zealand
Age: 31
Posts: 9
thanks for that. will try that. I would still like to hear any other suggestions people have too.
Reply With Quote
Reply

Tags
iptables, novice

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
novice asks help robzane Using Fedora 2 21st September 2008 05:50 PM
Novice - Yum and the gui jamien73 Installation and Live Media 1 2nd July 2008 09:29 AM
A novice!!!! Euręka! Fedora Focus 10 27th June 2008 02:43 PM
novice needs help jimmmm Using Fedora 0 26th August 2006 06:08 PM
Total Novice - Intel Pro/100 chuggy Installation and Live Media 22 8th January 2006 04:52 AM


Current GMT-time: 21:33 (Tuesday, 21-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat