Re: rdr not working for transparent http - 5.4-stable

2005-07-31 Thread Giovanni P. Tirloni
Abu Khaled disse: > On 7/31/05, Giovanni P. Tirloni <[EMAIL PROTECTED]> wrote: >> I think there's something in the code that makes it not work because I >> set ipfw to accept by default on every machine I have. There must be >> something else. >> > > Sounds confusing !!! > > Do you mind providin

Re: rdr not working for transparent http - 5.4-stable

2005-07-30 Thread Abu Khaled
On 7/31/05, Giovanni P. Tirloni <[EMAIL PROTECTED]> wrote: > Abu Khaled wrote: > > On 7/30/05, Giovanni P. Tirloni <[EMAIL PROTECTED]> wrote: > > > >>Giovanni P. Tirloni wrote: > >> > >>>Max Laier wrote: > >>> > >>> > One thing comes to my mind: What does > $sysctl net.inet.ip.forwardin

Re: rdr not working for transparent http - 5.4-stable

2005-07-30 Thread Giovanni P. Tirloni
Abu Khaled wrote: On 7/30/05, Giovanni P. Tirloni <[EMAIL PROTECTED]> wrote: Giovanni P. Tirloni wrote: Max Laier wrote: One thing comes to my mind: What does $sysctl net.inet.ip.forwarding say? # sysctl net.inet.ip.forwarding net.inet.ip.forwarding: 1 I had some tweaks in /etc/sysc

Re: rdr not working for transparent http - 5.4-stable

2005-07-30 Thread Abu Khaled
On 7/30/05, Giovanni P. Tirloni <[EMAIL PROTECTED]> wrote: > Giovanni P. Tirloni wrote: > > Max Laier wrote: > > > >> One thing comes to my mind: What does > >> $sysctl net.inet.ip.forwarding > >> say? > > > > > > # sysctl net.inet.ip.forwarding > > net.inet.ip.forwarding: 1 > > > > I had some

Re: rdr not working for transparent http - 5.4-stable

2005-07-30 Thread Giovanni P. Tirloni
Giovanni P. Tirloni wrote: Max Laier wrote: One thing comes to my mind: What does $sysctl net.inet.ip.forwarding say? # sysctl net.inet.ip.forwarding net.inet.ip.forwarding: 1 I had some tweaks in /etc/sysctl but disabling them didn't help either. #net.inet.ip.check_interface=1 #net.in

Re: rdr not working for transparent http - 5.4-stable

2005-07-28 Thread Max Laier
Okay ... so we have to look more closely ... On Thursday 28 July 2005 14:47, Giovanni P. Tirloni wrote: > I've deployed dozens of gateways with transparent HTTP proxy but this > time it isn't working and I suspect pf is somehow involved in this. > Packets aren't being redirected anywhere. I've d

Re: rdr not working for transparent http - 5.4-stable

2005-07-28 Thread Giovanni P. Tirloni
Max Laier wrote: One thing comes to my mind: What does $sysctl net.inet.ip.forwarding say? # sysctl net.inet.ip.forwarding net.inet.ip.forwarding: 1 I had some tweaks in /etc/sysctl but disabling them didn't help either. #net.inet.ip.check_interface=1 #net.inet.tcp.blackhole=2 #net.inet.u

Re: rdr not working for transparent http - 5.4-stable

2005-07-28 Thread Max Laier
On Thursday 28 July 2005 14:47, Giovanni P. Tirloni wrote: > Hello, > > I've deployed dozens of gateways with transparent HTTP proxy but this > time it isn't working and I suspect pf is somehow involved in this. > Packets aren't being redirected anywhere. I've disabled filtering > totally to debu

rdr not working for transparent http - 5.4-stable

2005-07-28 Thread Giovanni P. Tirloni
Hello, I've deployed dozens of gateways with transparent HTTP proxy but this time it isn't working and I suspect pf is somehow involved in this. Packets aren't being redirected anywhere. I've disabled filtering totally to debug this. I've a rule to redirect every connection attempt to port