если да то как перенаправить ВЕСЬ ВЭБ-трафик на порт сквида (3128)
пока не гуглил, но интересно что за зверь "allow ip from me" и как этот "me" назначается?
есть такой сет правил
Код: Выделить всё
server# ipfw list
00010 allow ip from any to me dst-port 53
00020 allow ip from me 53 to any
00100 allow ip from 192.168.0.0/24 to me
00200 allow ip from me to 192.168.0.0/24
00300 allow ip from 192.168.0.2 to 192.168.0.1
00400 allow ip from 192.168.0.1 to 192.168.0.2
00500 allow ip from me to any keep-state
00600 deny icmp from any to any frag
00700 allow icmp from any to any
00800 allow tcp from any to any dst-port 443
00900 allow tcp from any 443 to any
01000 allow tcp from any to any dst-port 22
01100 allow tcp from any 22 to any
01200 allow tcp from any to any dst-port 25,110
01300 allow tcp from any 25,110 to any
01400 allow ip from 192.168.0.0/24 to me
01500 allow ip from me to 192.168.0.0/24
01600 deny ip from any to me dst-port 80
01700 allow ip from 192.168.0.2 to 192.168.0.1
01800 allow ip from 192.168.0.1 to 192.168.0.2
01900 allow ip from me to any keep-state
02000 deny icmp from any to any frag
02100 allow icmp from any to any
02200 allow tcp from any to any dst-port 443
02300 allow tcp from any 443 to any
02400 allow tcp from any to any dst-port 22
02500 allow tcp from any 22 to any
02600 allow tcp from any to any dst-port 25,110
02700 allow tcp from any 25,110 to any
02800 allow udp from any to any dst-port 53
02900 allow udp from any 53 to any
03000 deny ip from any to any
65535 deny ip from any to any