Re: interface or source ip match using brouting - transparent proxy

Bart De Schuymer <[email protected]> Thu, 20 Apr 2006 18:57:47 +0200
Newsgroups gmane.linux.network.bridge.ebtables.user
Message-ID <[email protected]>
Op wo, 19-04-2006 te 23:47 +0300, schreef Andrius Kazimieras
Kasparavičius:
> I want to redirect web trafic passing through the bridge to the proxy
> server squid running on the bridge.
> 
> so when I want to redirect only trafic coming from LAN i try using "-i
> eth1", but that redirects trafic from eth0 as well, but it shouldnt?
> 
> when I want to redirect trafic coming only from ip range 10.0.0.0/8 I
> use rule --ip-src 10.0.0.0/8, but traffic passing bridge from other
> ips get's caugh as well.
> 
> but it catches only "--ip-destination-port 80". So at least one rule
> works. Why "-i eth1" and "--ip-src 10.0.0.0/8" does not do filtering
> for me?

They should also work. Make sure you start from empty tables. Anyway,
you can do a number of tests by looking at the packet counters and
logging the traffic that matches a specific rule.

cheers,
Bart




-------------------------------------------------------
Using Tomcat but need to do more? Need to support web services, security?
Get stuff done quickly with pre-integrated technology to make your job easier
Download IBM WebSphere Application Server v.1.0.1 based on Apache Geronimo
http://sel.as-us.falkag.net/sel?cmd=lnk&kid0709&bid&3057&dat1642