Re: Transparent proxy feature?

From: Antony T Curtis <antony.t.curtis_at_ntlworld.com>
Date: Sat, 12 Mar 2005 12:22:09 +0000
On Fri, 2005-03-11 at 14:44 -0800, Julian Elischer wrote:
> responding to myself to add more..
> 
> Julian Elischer wrote:
> > Antal Rutz wrote:
> >
> >> Hi,
> >>
> >> Nowadays I have to use a special firewall software ('zorp') but
> >> unfortunately it only runs on linux. the reason is that only linux
> >> has the feature (transparent proxying) to listen on/send packets 
> >> (sourcing)
> >> from other IP addresses than the machine has. (maybe with an extra kmod)

<snip>

> The proxy software need only do a getsockname() to get the sockaddr to use
> for the forward connection.
> 
> The ipfw rules need to be set so that the outgoing forward connection by 
> the
> proxy is not also captured :-)

Isn't the following option also required?

option IPFIREWALL_FORWARD


-- 
Antony T Curtis, BSc.                   UNIX, Linux, *BSD, Networking
antony.t.curtis_at_ntlworld.com            C++, J2EE, Perl, MySQL, Apache
                                        IT Consultancy.
Received on Sat Mar 12 2005 - 11:22:15 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:38:29 UTC