Dear good lords and ladies,
thank you for being this amazing community where you are helping everywhere you can! I learned so much from you - but I cannot set up a squid forward proxiy (classic one) with two network interfaces plugged in my RPi with each of them only proxying traffic when a specific port is used. After reading and trying for weeks I have now surrendered and am searching for help.
What I am trying to achieve
From my laptop I want to access the internet connection of multiple ethernet-devices which are connected to my RPi. Ideally I want to use multiple ports (of my RPi) and with every specific port squid should proxy the requests to a specified network interface. If I connect to the proxy "RPi:3128" it proxies the requests through eth1 and if I connect to the proxy "RPi:3129" it proxies the requests through eth2.
What I am working with
I am working on a Raspberry Pi 3B+ with Raspbian GNU/Linux 10 (buster) and Squid Version 4.6 ("squid -v" is saying that).
My network adapters are two SIM Dongles:
- Eth1 192.168.0.100 Huawei E3372h (hilink version)
- Eth2 192.168.0.101 ZTE MF667
What is my problem
Now when I am trying to connect to my RPi on port 3128 from my network (from my laptop) the proxy works fine. I get the public IP Address (IPv4 and IPv6) of my eth1 (192.168.0.100 Ethernet device). But: When I am trying to connect via 3129 I get the IP address of my eth1 (192.168.0.100 Ethernet device) instead of the eth2 (192.168.0.101). So I cannot access eth2.
What have I checked
Curl requests for IPs are working for both of them without any hassle on my RPi and I am getting two different IP-Addresses. With ifconfig I am giving them their local IP Address.
Netstat -plant says that squid is listening.
What have I unsuccessfully tried
I tried this: Squid - Listen on multiple ports and forward to different proxy but it seems not to be the completely right direction.
Tried to assign a definitive tcp_outgoing_address for the port (full squid.conf at the end): http_port 3129 acl port_name localport 3129 tcp_outgoing_address 192.168.0.101 port_name #tcp_outgoing_address fe62::d11e:6206:e32:f82b port_name (ipv6 is changed - I copied it from ifconfig output and the eth2) But it doesn't seem to work, I cannot get a connection to eth2.
And tbh I am fairly new to the RPi/Squid/Proxying thus I would really appreciate your help with this. Thanks in advance!
Squid.conf and netstat -plant
My squid.conf looks like this and is (a little bit adapted) from: https://github.com/serverok/squid-proxy-installer/blob/master/squid.conf
http_port 3128
cache deny all
hierarchy_stoplist cgi-bin ?
access_log none
cache_store_log none
cache_log /dev/null
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
http_port 3129
acl port_name localport 3129
tcp_outgoing_address 192.168.0.101 port_name
#tcp_outgoing_address fe62::d11e:6206:e32:f82b port_name
#http_access 192.168.0.100 deny port_name
acl localhost src 127.0.0.1/32 ::1
#acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1
acl SSL_ports port 1-65535
acl Safe_ports port 1-65535
acl CONNECT method CONNECT
acl siteblacklist dstdomain "/etc/squid/blacklist.acl"
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access deny siteblacklist
auth_param basic program /usr/lib/squid3/basic_ncsa_auth /etc/squid/passwd
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
acl password proxy_auth REQUIRED
http_access allow localhost
http_access allow password
http_access deny all
forwarded_for off
request_header_access Allow allow all
request_header_access Authorization allow all
request_header_access WWW-Authenticate allow all
request_header_access Proxy-Authorization allow all
request_header_access Proxy-Authenticate allow all
request_header_access Cache-Control allow all
request_header_access Content-Encoding allow all
request_header_access Content-Length allow all
request_header_access Content-Type allow all
request_header_access Date allow all
request_header_access Expires allow all
request_header_access Host allow all
request_header_access If-Modified-Since allow all
request_header_access Last-Modified allow all
request_header_access Location allow all
request_header_access Pragma allow all
request_header_access Accept allow all
request_header_access Accept-Charset allow all
request_header_access Accept-Encoding allow all
request_header_access Accept-Language allow all
request_header_access Content-Language allow all
request_header_access Mime-Version allow all
request_header_access Retry-After allow all
request_header_access Title allow all
request_header_access Connection allow all
request_header_access Proxy-Connection allow all
request_header_access User-Agent allow all
request_header_access Cookie allow all
request_header_access All deny all
Netstat -plant says that 3128 and 3129 is listened by squid:
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
tcp 0 0 127.0.0.1:631 0.0.0.0:* LISTEN 389/cupsd
tcp6 0 0 ::1:631 :::* LISTEN 389/cupsd
tcp6 0 0 :::3128 :::* LISTEN 564/(squid-1)
tcp6 0 0 :::3129 :::* LISTEN 564/(squid-1)