?
Solved

IPTABLE FOR RH - LINUX 9.0

Posted on 2003-12-10
11
Medium Priority
?
368 Views
Last Modified: 2010-03-18
Dear All Support,

I have RedHat Linux 9.0 installed on my Pentium 4 PC. I would like to have it running as a proxy server. Which package is best to utilize for this issue ( IPTABLES or SQUID PROXY? ). If so, How can I do the configuration.

Here is my current Network Infrastructure:

1. RedHat 9.0 Server:
=> Local DNS Server
=> Local Sendmail Server
=> Local Apache Web Server
=> DHCP
=> Samba

+=> ( IPTABLES or SQUID PROXY ) I would like to add this feature to my RH- Server, so that everyone on the network could access to the Internet.  At the moment my network is using a 56K dialup to connect to the internet and receive E-Mails, but very soon we will have a fractional T1 implementing to our LAN.

Could someone please help me to resolve this problem? I deeply appreciate your help.

PS. Right now I will post this question with a 100 expert points, it will be double up once the problem is resolved.

Thank you in advance,
0
Comment
Question by:linxcelent
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
11 Comments
 

Author Comment

by:linxcelent
ID: 9917351
My Goal:

Currently: RedHat Linux 9 --> Dialup --> Proxy Server--> 25 Clients
Wil upgrate to: RedHat Linux 9 --> Fractional T1 --> Proxy Server --> 25 Clients

I am focusing on ( 56K dialup at the moment )
0
 
LVL 4

Expert Comment

by:Jivko
ID: 9918724
SQUID is the best proxy solution for web caching , but if you need other services such as icq , instant messaging , irc , and full functional internet access you need NAT solution - iptables

Regards
0
 

Author Comment

by:linxcelent
ID: 9920028
Let's pick SQUID if it's an ideal web server! How may I approach the configuration process? Do I need to install any additional package beside RH Linux 9?

Please give me some configuration sample.

Thank you the respond.
0
The Ideal Solution for Multi-Display Applications

Check out ATEN’s VS1912 12-Port DP Video Wall Media Player at InfoComm 2017. Kerri describes how easy it is to design creative video walls in asymmetric layouts and schedule detailed playlists ahead of time with its advanced scheduling feature.

 
LVL 4

Expert Comment

by:Jivko
ID: 9920411
SQUID is not a webserver it is proxy server for web caching.
For web server use Apache
0
 

Author Comment

by:linxcelent
ID: 9920601
I apologize about my wording! However I think you know what I mean by webserver:

Server --> Sharing --> internet connection with multiple clients.

I used iptables before but it doesn't help function properly. It takes a lot of time to recognize clients. If thinking about converting to SQUID Proxy. Could you help me with the configuration?

Thank you.
0
 
LVL 4

Expert Comment

by:Jivko
ID: 9920919
Just open th configuration file and go ahead.
There is a explanation for each directive and configuration options

And iptables is not so confusing

if you want to use private range of addresses just run this:

iptables -t nat -I POSTROUTING -s 192.168.0.0/16 -j MASQUERADE

and that is all


0
 

Author Comment

by:linxcelent
ID: 9928621
Here is the problem with my existing NAT iptables:

All the client are logon to the domain before the ( NAT ) server is dialup. When the server is dialup all clients need to restart to refresh their IP addresses. All client doesn't have permission to renew ( ipconfig /renew or release) IP address. It must be done with an administrator account.

Is there any way I can resolve this problem? If so, how do I approach it?

Please help, thank you.
0
 

Author Comment

by:linxcelent
ID: 9943160
Please delete this questiong and refund points - No respond was posted.
0
 
LVL 4

Accepted Solution

by:
Jivko earned 400 total points
ID: 9948137
So what was the question? How to install squid-proxy? Or how to setup NAT with iptables? Or wich is better?

>> " When the server is dialup all clients need to restart " 
What do you mean?

>> "If thinking about converting to SQUID Proxy. Could you help me with the configuration?"

The configuration is very simple.
There is default configuration file called squid.conf.default with explanation of every configuration option - working in most cases.
It is a good idea to read something about Squid:
http://www.squid-cache.org/Doc/FAQ/FAQ-3.html#ss3.2

...and about iptables

http://www.netfilter.org/documentation/HOWTO//NAT-HOWTO.html
http://www.yolinux.com/TUTORIALS/LinuxTutorialIptablesNetworkGateway.html




0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question