Technical data

4. Packages
4.17.3. OPT_SS5 - Ein Socks4/5 Proxy
For some programs a Socks proxy may be needed. SS5 provides this functionality.
http://ss5.sourceforge.net/
SS5_LISTEN_N
SS5_LISTEN_x Specify IP addresses or symbolic names including portnumber of the inter-
face here on which SS5 should listen to clients. It is a good idea to specify only trusted
interfaces because all clients have full access to SS5 (and its activated configuration edi-
tor). Normally setting IP_NET_1_IPADDR:8050 makes most sense.
SS5 will listen to the addresses set here offering its services. The default port is 8050.
This setting has to be used in the configuration of your programs.
Define your fli4l name (see HOSTNAME in base.txt) or its IP (i.e. 192.168.6.1) as a proxy
in your client. With the port number set here all data necessary to configure programs
for using SS5 is provided.
SS5_ALLOW_N Sets the number of list entries.
SS5_ALLOW_x List of nets and/or IP addresses for which the packet filter has to be opened.
Default: IP_NET_1.
4.17.4. OPT_TRANSPROXY (EXPERIMENTAL) - Transparent HTTP Proxy
Transproxy is a „transparent” Proxy - a program that catches all HTTP requests going through
the fli4l router and redirects them to a normal HTTP proxy i.e. Privoxy. To achieve this the
packet filters has to redirect HTTP queries that should go to the Internet to Transproxy which
will then redirect them to another HTTP proxy. It uses iptables’s „REDIRECT” function to
accomplish this:
PF_PREROUTING_1='tmpl:http IP_NET_1 REDIRECT:8081'
This rule would redirect all HTTP packets from the first defined net (internal LAN normally)
to Transproxy on port 8081.
TRANSPROXY_LISTEN_N
TRANSPROXY_LISTEN_x Specify IP addresses or symbolic names including portnumber
of the interface here on which Transproxy should listen to clients. All interfaces have to
be specified here that should redirect their packets to Transproxy by the packet filter.
With the default setting any:8081 Transproxy listens on all interfaces.
TRANSPROXY_TARGET_IP
TRANSPROXY_TARGET_PORT With this options it is set to which service incoming
HTTP queries should be redirected. This can be a standard HTTP proxy (Squid, Privoxy,
Apache, a.s.o.) on a random PC (or fli4l itself). Please ensure that this proxy is not
in the range of the HTTP queries redirected by the packet filter. This would cause an
infinite loop otherwise.
191