Improve company productivity with a Business Account.Sign Up

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 86
  • Last Modified:

problem in squid between L3-switch and router

I need to config a squid server  between L3-switch and router without change configuration .  L3--->squid--->router
I installed a transparent squid  between the switch and the router in bridge mode, the switch has several vlans that speaks with a route.
All vlans can reach the router so bridging seems ok, but  i cant't see any log in squid's access.log  
my config as follows:
/usr/sbin/brctl addbr br0
/usr/sbin/brctl addif br0 eth0
/usr/sbin/brctl addif br0 eth1
/sbin/ifconfig eth0 0.0.0.0 promisc
/sbin/ifconfig eth1 0.0.0.0 promisc
/sbin/ifconfig br0 192.168.100.5 255.255.255.0 up
route add default gw 192.168.100.1 dev br0
ebtables -t broute -A BROUTING -p IPv4 --ip-protocol 6  --ip-destination-port 80 -j redirect  --redirect-target ACCEPT --log --log-level=info --log-prefix="EBTAB" --log-ip
/sbin/iptables -t nat -A PREROUTING  -i br0 -p tcp --dport 80  -j REDIRECT --to-port 3128

after i did this,no log come and no packets in iptables's nat table
sorry for my bad english
Anyone have a suggestion on how to manage the transparent proxy mode inside the vlans?
0
young liu
Asked:
young liu
  • 3
1 Solution
 
gheistCommented:
I look at your config - are you suer you need a bridge or you mean bonding/ifenslave?
1
 
young liuAuthor Commented:
@gheist
 thank you for your reply.
I really need to do this. my network traffic is so confused with a lot of vlan,acl  and qos policy,use a squid box  by NAT mode  will change the static route and network structure.so  I have to use a bridge  mode. i think this will not change the network structure
do you have any good suggestions
0
 
gheistCommented:
To clear some confusion - bridge is L2, router is L3...
If you read on ebtables manual, you see that only FORWARD table will apply on the bridge.
Probably it is not a good idea to mix ebtables and iptables, either is a full framework on its own. (me never used ebtables)
NAT cannot work without IP address (see respective RFC)
0
 
gheistCommented:
Hope it helped.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

Featured Post

The 14th Annual Expert Award Winners

The results are in! Meet the top members of our 2017 Expert Awards. Congratulations to all who qualified!

  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now