HTTP Anti-Virus Proxy
http://havp.hege.li/forum/

tproxy support (ip spoofing)
http://havp.hege.li/forum/viewtopic.php?f=3&t=413
Page 1 of 1

Author:  rex_dev [ 23 Feb 2009 14:36 ]
Post subject:  tproxy support (ip spoofing)

Hello,

I would like to know if HAVP support tproxy (IP spoofing) or something similar to it.

I want to create an anti virus scanning server but that it will be totally transparent to the client, which means that the server will go with the client IP to the internet and not with the server IP, the same thing that tproxy does when its spoof the client IP.
I manage to do so with squid like showen here - http://wiki.squid-cache.org/ConfigExamples/FullyTransparentWithTPROXY but have a huge problem with connecting it into one of the anti virus programs and that the spoofing won't be broken, the only method i found is icap and that is no longer support or develop.
Does HAVP has this feature or something similar to it?

Thanx,
Eran.

Author:  karesmakro [ 23 Feb 2009 14:51 ]
Post subject:  Re: tproxy support (ip spoofing)

Hi rex_dev and welcome in HAVP forum!

Quote:
Does HAVP has this feature or something similar to it?


Yes, you can do this with options:
Code:
FORWARDED_IP
and
Code:
X_FORWARDED_FOR


greetings

Author:  rex_dev [ 23 Feb 2009 15:12 ]
Post subject:  Re: tproxy support (ip spoofing)

karesmakro wrote:
Hi rex_dev and welcome in HAVP forum!

Thanx, :)

karesmakro wrote:
Yes, you can do this with options:
Code:
FORWARDED_IP
and
Code:
X_FORWARDED_FOR


greetings


Thanx for the quick replay but i tried this options and they didn't work for spoofing feature.
I use tproxy kernel that allows to bind a non_local_ip address and also iptables tproxy patched for mangle redirection.
The issue is that when i setup squid patched with tproxy, everything is fine because the squid generate the request with the client ip when it fetch the url.
When i use HAVP it didn't work because what i see that he does is to fetch the url with the server IP and only does X_forwarding for the client ip, it doesn't Spoof the client IP.

Do you know if HAVP fully support the tproxy feature?

Author:  hege [ 23 Feb 2009 16:42 ]
Post subject:  Re: tproxy support (ip spoofing)

It is not possible until HAVP can be used with ICAP..

Author:  rex_dev [ 24 Feb 2009 10:17 ]
Post subject:  Re: tproxy support (ip spoofing)

hege wrote:
It is not possible until HAVP can be used with ICAP..


Ok, thanx for the replay.
When will be a version that will support ICAP?

Author:  hege [ 24 Feb 2009 10:51 ]
Post subject:  Re: tproxy support (ip spoofing)

When someone has time to code it..

Then again, Squid 3.x with ICAP support is not that stable yet either..

Page 1 of 1 All times are UTC + 2 hours [ DST ]
Powered by phpBB® Forum Software © phpBB Group
https://www.phpbb.com/