[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: tor privoxy squid

On 11/18/06, gabrix <gabrix@xxxxxxxxxxxxx> wrote:
[my transparent squid proxy isn't working]

try the following:

squid: make sure these elements are in your squid.conf
httpd_accel_port 3128
httpd_accel_host virtual
httpd_accel_with_proxy on
httpd_accel_uses_host_header on
cache_peer      localhost       parent  8118    7       no-query default
header_access Via deny all
header_access From deny all
forwarded_for off

privoxy: note that the cache_peer in squid config refers to SOCKS
proxy in privoxy config.
forward-socks4a         /  .

tor: note that 9050 is the SOCKS proxy port for Tor.

INTF=eth1 # internal network interface
ONTF=eth0 # external default route / public interface
$IPTABLES -A FORWARD -i $INTIF -o $EXTIF -p tcp -m state --state
$IPTABLES -t nat -A PREROUTING -i $INTIF -p tcp --dport 80 -j REDIRECT --to 3128

note that you'll want additional firewall / filter rules, and also
that DNS leaks may be present.  you will have to transparently proxy
DNS via dns-proxy-tor or equivalent to avoid this, and the following
filter rules can be used for transparent DNS proxy:
$IPTABLES -t nat -A PREROUTING -i $INTIF -p udp --dport 53 -j REDIRECT
--to 65533
where 65533 is where dns-proxy-tor is listening.