News: This forum is now permanently frozen.
Pages: [1]
Topic: opti 1 make default traffic go thru proxy  (Read 1367 times)
« on: December 09, 2009, 05:24:57 »
adrianp918
Guest

Is there a way to make monowall  force all traffic that flows thru it to go thru a proxy filter,

reason being is that i allow some people to get on my network and i want all there traffic to go thru the proxy server

is this poss?
« Reply #1 on: December 09, 2009, 22:55:04 »
f41thr *
Posts: 28

Is there a way to make monowall  force all traffic that flows thru it to go thru a proxy filter,

reason being is that i allow some people to get on my network and i want all there traffic to go thru the proxy server

is this poss?

For sure, but could you please so kind an provide your configuration and more detailed requirement.

How do you plan to seperate guest clients from internal (allowed) clients.
How man clients we are talking about.

Example:
Allowed clients between x.x.x.2 -> x.x.x.126 (Have to be configured with either fixed IP adresses or make reservation for them on the DHCP page for you LAN.
Configure the DHCP Range for the guest clients x.x.x.127 - x.x.x.254   

An other alternative is to use a secondary IP Range on your interface, one for your internal clients with fixed DHCP or fixed adresses and a free range on the second IP range.
The you have to establish a differnt rule set

Make a ruleset wich block all traffic from x.x.x.127 - x.x.x.254 to the Internet
Put a proxy server on an IP in x.x.x.2 -> x.x.x.126
Allow traffic from x.x.x.127 - x.x.x.254 to the proxy server port 8080, the DNS server x.x.x.1, the DHCP Server on x.x.x.1

Configure the guest clients to make use of your proxyserver.

Be aware this is not the best approach and not tested by myself yet.

But it may give you an idea how it could work.

A better way is to use different LAN's for internal (LAN1) and external clients (LAN2 = OPT Interface), put a proxy server in a DMZ, etc...
Best is a dual homed proxy server, then you need two firewalls(m0n0walls).

Everything is possible with M0n0wall. 

F41THR

 
Pages: [1]
 
 
Powered by SMF 1.1.20 | SMF © 2013, Simple Machines