Author Topic: WLAN / LAN Transparent proxy https  (Read 4280 times)

gpouser

  • Zen Apprentice
  • *
  • Posts: 4
  • Karma: +0/-0
    • View Profile
WLAN / LAN Transparent proxy https
« on: August 06, 2009, 10:46:46 pm »
I have installed a eBox system as
System eBox 1.2

LAN / WLAN                                             eBox                         webAdmin on 333 port

Laptop                                                        eth1                                   eth0          https://192.168.41.77:333

client 192.168.51.25 https  --  LAN -----  ( 192.168.51.1 eth1 Ebox  eth0  192.168.41.77  )   vlan access to internet ASA5510
                                                                Transparent proxy                               


Would this work as bridge mode but with content filtering on 192.168.51.1 interface for connecting WLAN / LAN client’s

When on client on 192.168.51.25 you can get internet access, but if you direct to https web site it fails.

As yet I have not set either interface as Ext, should I enable 192.168.51.1 as Ext even thou its not the way out for internet.

I think the above does not work as NAT can not take place as there are no Ext interfaces, but if I set 192.168.41.77 then there will be no access to the webAdmin on https://192.168.41.77

I think there should be some more documentation (examples)as to setting up transparent proxy with https such as setting NAT and firewall rules.

Found this link to try

http://forum.ebox-platform.com/index.php?topic=1564.0

* Grab the new exceptionsitelist.mas here
* cp exceptionsitelist.mas /usr/share/ebox/stubs/squid/exceptionsitelist.mas
* /etc/init.d/ebox squid restart

This worked for me, once we had our route set on ASA5510 for subnet 192.168.51.0/24 and placed redirect on eth1 for host mail servers in the form ExtIP xxx.xxx.xxx.xxx (mail server)  443   TCP/UDP  IntIP xxx.xxx.xxx.xxx (mail server), neither interfaces was set as external interface in \networking\interface

The system works with Ruckus WireLess system as firewall transparent proxy for external guests





« Last Edit: August 11, 2009, 04:22:01 pm by gpouser »