Squid proxy Ga bisa Konek

Diskusi tentang Ubuntu Server baik webserver, database server, samba server dan service lainnya serta jaringan menggunakan Sistem Operasi Ubuntu.
User avatar
golann
Posts: 42
Joined: 21 Aug 2013, 10:05

Squid proxy Ga bisa Konek

Postby golann » 04 Nov 2013, 21:51

Mohon bantuannya semua Proxy saya ga bisa konek internet.

saya lagi penelitian di Lab.

topologi:

internet - - - - | squid proxy | ----- | switch | ----- client

squid dengan 2 interface:

eth0 ( ke internet kampus)
eth1 ( ke LAN yang di LAB)

gedit /etc/network/interfaces

auto eth0 inet dhcp

auto eth1 inet static
address 192.168.1.1
netmask 255.255.255.0
broadcast 192.168.1.255

konfigurasi nat nya:

ip tables -t nat -A PREROUTING -s 192.168.1.0/24 -p tcp dport 80 -j ACCEPT

ip tables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to -port 3128

aktifkan ip forward : net.ipv4.ip_forward = 1

squid.conf sudah saya compile dan tidak ada eror.
tapi kenapa dari klient tidak bisa konek ke internet. ping ke gateway juga (10.100.204.1) tidak konek. Mohon bantuan dan sarannya. atau mungkin ada konfigurasi saya yang kurang atau salah. terima kasih.
User avatar
Mas_budiMan
Posts: 57
Joined: 12 Aug 2013, 18:48
Location: jambi, indonesia
Contact:

Re: Squid proxy Ga bisa Konek

Postby Mas_budiMan » 07 Nov 2013, 14:42

gan scrip squidnya mn
coba di gelar dsnini
biar para suhu bisa bntu
User avatar
riophone
Posts: 34
Joined: 21 Mar 2013, 21:40
Location: Medan, Indonesia

Re: Squid proxy Ga bisa Konek

Postby riophone » 07 Nov 2013, 17:43

Sepertinya dibuat Router Gateway + Proxy ya mas?
coba iptables buat seperti ini dulu mas, kalau jalan tinggal tambahkan di rc.locals

iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
User avatar
q_p
Posts: 3109
Joined: 14 Oct 2012, 13:01
Contact:

Re: Squid proxy Ga bisa Konek

Postby q_p » 07 Nov 2013, 22:26

Sebetulnya banyak contoh2-nya di Google. Salah satunya ini =
[font:Courier New][size:8pt]
#!/bin/sh
# ------------------------------------------------------------------------------------
# See URL: http://www.cyberciti.biz/tips/linux-set ... howto.html
# (c) 2006, nixCraft under GNU/GPL v2.0+
# -------------------------------------------------------------------------------------
# squid server IP
SQUID_SERVER="192.168.1.1"
# Interface connected to Internet
INTERNET="eth0"
# Interface connected to LAN
LAN_IN="eth1"
# Squid port
SQUID_PORT="3128"

# DO NOT MODIFY BELOW
# Clean old firewall
iptables -F
iptables -X
iptables -t nat -F
iptables -t nat -X
iptables -t mangle -F
iptables -t mangle -X
# Load IPTABLES modules for NAT and IP conntrack support
modprobe ip_conntrack
modprobe ip_conntrack_ftp
# For win xp ftp client
#modprobe ip_nat_ftp
echo 1 > /proc/sys/net/ipv4/ip_forward
# Setting default filter policy
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
# Unlimited access to loop back
iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT
# Allow UDP, DNS and Passive FTP
iptables -A INPUT -i $INTERNET -m state --state ESTABLISHED,RELATED -j ACCEPT
# set this system as a router for Rest of LAN
iptables --table nat --append POSTROUTING --out-interface $INTERNET -j MASQUERADE
iptables --append FORWARD --in-interface $LAN_IN -j ACCEPT
# unlimited access to LAN
iptables -A INPUT -i $LAN_IN -j ACCEPT
iptables -A OUTPUT -o $LAN_IN -j ACCEPT
# DNAT port 80 request comming from LAN systems to squid 3128 ($SQUID_PORT) aka transparent proxy
iptables -t nat -A PREROUTING -i $LAN_IN -p tcp --dport 80 -j DNAT --to $SQUID_SERVER:$SQUID_PORT
# if it is same system
iptables -t nat -A PREROUTING -i $INTERNET -p tcp --dport 80 -j REDIRECT --to-port $SQUID_PORT
# DROP everything and Log it
iptables -A INPUT -j LOG
iptables -A INPUT -j DROP
[/size][/font]
User avatar
golann
Posts: 42
Joined: 21 Aug 2013, 10:05

Re: Squid proxy Ga bisa Konek

Postby golann » 11 Nov 2013, 12:18

@mas q_p:

Kalo Eth0 nya DHCP itu ga masalah kan mas??

interface dari internet kampus ke lab.

Return to “Ubuntu Server”

Who is online

Users browsing this forum: No registered users and 1 guest