Re: IPTables transparent configuration

I was looking to send all traffic through Tor. The UDP rule was taken off of the Tor Transparent Configuration documentation. I have Tor DNSPorts and DNSListenAddress set. I realize this was for DNS requests, but I was kinda hoping to pipe everything through. I will look at just dropping all other traffic. 

Thanks for sharing your link to your example config as well!

On Nov 17, 2010, at 12:37 PM, intrigeri wrote:

> Hi,
> Curt Shaffer wrote (17 Nov 2010 12:53:27 GMT) :
>> sudo iptables -t nat -A PREROUTING -p tcp -s -j DNAT --to-destination
>> sudo iptables -t nat -A PREROUTING -p icmp -s -j DNAT --to-destination
>> sudo iptables -t nat -A PREROUTING -p udp -s -j DNAT --to-destination
> Tor is able to transport TCP only.
> If you really want these LAN boxes to *only* access the Internet over
> Tor, you have to forbid them anything other than TCP.
> If I am not mistaken, the rules you are showing us allow any UDP
> traffic to go out (without Tor) unless its destination port is !=53.
> I'm not sure this is really what you want to achieve.
> Feel free to have a look to the firewall we use in T(A)ILS as a source
> of inspiration:
>    http://git.immerda.ch/?p=amnesia.git;a=blob;f=config/chroot_local-includes/etc/firewall.conf
>    http://git.immerda.ch/?p=amnesia.git;a=blob;f=config/chroot_local-includes/etc/firewall6.conf
