Answer the question
In order to leave comments, you need to log in
AP Continent + IPTables?
Hello! Who set up a bunch of AP Continent (for access to SUFD) + IPTables a question for you. There was a problem when connecting users to the AP Continent through a proxy server on CentOS 7 with configured squid + iptables. On squid, traffic is wrapped on ports 80 and 443, the rest of the traffic is blocked. For the operation of the AP Continent, the following allowing rules have been created in iptables:
*filter
-A FORWARD -s 82.119.129.210 -d 10.10.11.192/27 -i eth0 -o tun0 -p udp --sport 4433 -j ACCEPT
-A FORWARD -d 82.119.129.210 -s 10.10.11.192/27 -o eth0 -i tun0 -p udp --dport 4433 -j ACCEPT
-A FORWARD -s 82.119.129.210 -d 10.10.12.192/27 -i eth0 -o tun1 -p udp --sport 4433 -j ACCEPT
-A FORWARD -d 82.119.129.210 -s 10.10.12.192/27 -o eth0 -i tun1 -p udp --dport 4433 -j ACCEPT
-A FORWARD -s 82.119.129.210 -d 10.10.13.192/27 -i eth0 -o tun2 -p udp --sport 4433 -j ACCEPT
-A FORWARD -d 82.119.129.210 -s 10.10.13.192/27 -o eth0 -i tun2 -p udp --dport 4433 -j ACCEPT
*nat
-A POSTROUTING -o eth0 -p udp --dport 4433 -d 82.119.129.210 -s 10.10.11.192/27 -j MASQUERADE
-A POSTROUTING -o eth0 -p udp --dport 4433 -d 82.119.129.210 -s 10.10.12.192/27 -j MASQUERADE
-A POSTROUTING -o eth0 -p udp --dport 4433 -d 82.119.129.210 -s 10.10.13.192/27 -j MASQUERADE
Answer the question
In order to leave comments, you need to log in
something I doubt that udp
had nothing to do with it, so the first line of diagnostics:
in the first console
in the second console,
do something that should fly to 82.119.129.210 and located behind tun0,
see what flew to the router in the first
what flew away after in the second, what immediately returned
and again in the first, whether what returned to the right place flew
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question