Squid-Kit-Transparenter-Proxy

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen

Schaubild

Vorraussetzung

Firewall Regeln für den Transparenten Proxy

Input Regel erweitern (Erstmal nur für das das LAN)

Wir erweitern die Zugriffsrechte aus den lokalen Netzwerk in der INPUT Kette
ct state new iif  $LANDEV    ip saddr $LAN     tcp dport { 22, 3128, 80, 443 }  accept

(nftables REDIRECT)

Tabelle und Kette anlegen
  • nft add table ip nat
  • nft add chain ip nat prerouting '{ type nat hook prerouting priority dstnat; policy accept; }'
HTTP und HTTPS lokal umleiten
  • nft add rule ip nat prerouting tcp dport 80 redirect to :3129
  • nft add rule ip nat prerouting tcp dport 443 redirect to :3130

Änderungen in der /etc/squid/squid.conf

#transparenter Zugriff unverschlüsselt
http_port 3129 intercept
#transparenter Zugriff verschlüsselt wichtig https_port
https_port 3130 ssl-bump intercept cert=/etc/squid/certs/squid_proxyCA.pem generate-host-certificates=on options=NO_SSLv3,NO_TLSv1,NO_TLSv1_1,SINGLE_DH_USE,SINGLE_ECDH_USE
ssl_bump bump all

Restart von Squid

  • systemctl restart squid