Jump to content

Question

Posted

i need to setup proxy

 

 iptables -t nat -A PREROUTING -p tcp --dport 2106 -j DNAT --to-destination xxx.xxx.xxx.xxx:2106
 iptables -t nat -A PREROUTING -p tcp --dport 7777 -j DNAT --to-destination xxx.xxx.xxx.xxx:7777

in the .ini there is only

 

Proxy = 

 

any clue? is my 1st time using this config, im used to set up common way for login

2 answers to this question

Recommended Posts

  • 0
Posted (edited)

It's additional proxy or you just have server behind NAT and need port forwarding?

 

If it's just port forwarding, you don't need anything else than DNAT and enabling IPv4 forwarding

sysctl net.ipv4.ip_forward=1

Also packets from server must go back through the proxy (it must be default gateway for the server)

 

 

If it's real proxy (another server endpoint):

 

http://www.maxcheaters.com/topic/206180-patched-hauth-to-support-multiple-ip-addressesproxies/?hl=hauthd

 

Also you'll have to learn something about policy-based routing because when you have two endpoints, server will still send packets via default gateway - which will be your primary IP address. So if packet comes to l2server via proxy, it must go back to client via the very same proxy - not via default gateway.

 

You should read something about it (google linux policy based routing), this can help you a bit:

 

On router:

 

Mark incoming packets and restore mark for outgoing packets:

 

iptables -t mangle -A PREROUTING -i tun0 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 100 # mark packets from 1st proxy
iptables -t mangle -A PREROUTING -i tun1 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 101 # mark packets from 2nd proxy
iptables -t mangle -A PREROUTING -i tun2 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 102 # mark packets from 3rd proxy
iptables -t mangle -A PREROUTING -i br1 -p tcp -m tcp --sport 7777 -j CONNMARK --restore-mark # restore mark on packets going back
Use policy-based routing based on packet mark:
 
ip rule add fwmark 100 table 100 # if packet is marked as from 1st proxy, use routing table 100
ip route add default via 10.8.0.1 table 100 # routing table 100 - default gateway is 1st proxy internal address
ip rule add fwmark 101 table 101 # if packet is marked as from 2nd proxy, use routing table 101
ip route add default via 10.8.1.1 table 101 # routing table 101 - default gateway is 2nd proxy internal address
ip rule add fwmark 102 table 102 # if packet is marked as from 3rd proxy, use routing table 102
ip route add default via 10.8.2.1 table 102 # routing table 102 - default gateway is 3rd proxy internal address
On proxy:
 
up iptables -t nat -A PREROUTING -m tcp -p tcp --dport 7777 -j DNAT --to-destination 10.8.0.2:7777
Edited by eressea
  • 0
Posted (edited)

 

It's additional proxy or you just have server behind NAT and need port forwarding?

 

If it's just port forwarding, you don't need anything else than DNAT and enabling IPv4 forwarding

sysctl net.ipv4.ip_forward=1

Also packets from server must go back through the proxy (it must be default gateway for the server)

 

 

If it's real proxy (another server endpoint):

 

http://www.maxcheaters.com/topic/206180-patched-hauth-to-support-multiple-ip-addressesproxies/?hl=hauthd

 

Also you'll have to learn something about policy-based routing because when you have two endpoints, server will still send packets via default gateway - which will be your primary IP address. So if packet comes to l2server via proxy, it must go back to client via the very same proxy - not via default gateway.

 

You should read something about it (google linux policy based routing), this can help you a bit:

 

On router:

 

Mark incoming packets and restore mark for outgoing packets:

 

iptables -t mangle -A PREROUTING -i tun0 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 100 # mark packets from 1st proxy
iptables -t mangle -A PREROUTING -i tun1 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 101 # mark packets from 2nd proxy
iptables -t mangle -A PREROUTING -i tun2 -p tcp -m tcp --dport 7777 -j CONNMARK --set-mark 102 # mark packets from 3rd proxy
iptables -t mangle -A PREROUTING -i br1 -p tcp -m tcp --sport 7777 -j CONNMARK --restore-mark # restore mark on packets going back
Use policy-based routing based on packet mark:
 
ip rule add fwmark 100 table 100 # if packet is marked as from 1st proxy, use routing table 100
ip route add default via 10.8.0.1 table 100 # routing table 100 - default gateway is 1st proxy internal address
ip rule add fwmark 101 table 101 # if packet is marked as from 2nd proxy, use routing table 101
ip route add default via 10.8.1.1 table 101 # routing table 101 - default gateway is 2nd proxy internal address
ip rule add fwmark 102 table 102 # if packet is marked as from 3rd proxy, use routing table 102
ip route add default via 10.8.2.1 table 102 # routing table 102 - default gateway is 3rd proxy internal address
On proxy:
 
up iptables -t nat -A PREROUTING -m tcp -p tcp --dport 7777 -j DNAT --to-destination 10.8.0.2:7777

 

yes atm im behind 2 routers and i want to set also few login gateways for better ping from different locations

by now i must fwd ports on router 1 and router 2

in comming weeks i will add the other thing when i get direct conection to wan ip

Edited by etherian

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Answer this question...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



  • Posts

    • My official facebook profile!: https://www.facebook.com/spectrumL2 Specifications: Revamped L2JACIS revision FROM the core Private project!!! Revision that has been receiving corrections for over 3 years!!! Events already installed in the revision: TVT CTF KTB PARTY FARM SPOIL EVENT CRAZY RATES TOURNAMENT TIME ZONE (INSTANCE) All working correctly!!! SIEGE ESSENTIAL FEATURES: Walls fix Gates fix Flags fix 100% functional: OLYMPIADS: Implemented settings Hero receives enchanted Weapons with equal status PvP Weapons Optional /true/false Hero can acquire all Hero Weapons Optional true/false OTHER IMPLEMENTATIONS: Teleport fixed (directly to Giran) Teleport effect classic Vip skins vip collor name Pack NPCs with effect already configured BOSES already configured Mobs already configured CLASS BALANCE SPECIAL SYSTEM We have a SPECIAL system developed for Class Balance with only 1 digit in XML %tage of configurable debuffs Player limitation system in BOSES or PvP zones BS blocking system in FLEG zones or events Among others dozens of improvements made in the review... price: 390 USD !  OBS: WE CAN CHANGE THE BANNER AND NAME OF THE SERVICE TO THE ONE OF YOUR PREFERENCE BUT THE SETTINGS MUST BE KEPT ANY CHANGES REQUIRE ADDITION        
    • Server is Online – 1,000+ Active Players! We’re excited to announce the addition of a Europe Proxy to improve connectivity for our EU players! Clans can now benefit from VIP Access to help you catch up faster. 🎯 If you're a clan leader with at least 9 active members, join our Discord and open a ticket to claim your VIP rewards!  
    • The Telegram team is rolling out a new batch of Stars-only gifts you’ll be able to mint as NFTs. Don’t miss your chance to join the next Telegram trend and earn from it! Buy Telegram Stars cheap and KYC-free 1 Star from $0.0149 (min. 50 Stars, bulk discounts available) Promo code STARS5 — 5 % off Pay any way you like: bank cards · crypto · other popular methods How to purchase: ➡Online Store — Click ➡ Telegram bot — Click Other services: ➡ SMM panel — Click Regular buyers get extra discounts and promo codes. Support: ➡ Telegram: https://t.me/solomon_bog ➡ Telegram channel: https://t.me/accsforyou_shop ➡ Discord: https://discord.gg/y9AStFFsrh ➡ WhatsApp: https://wa.me/79051904467 ➡ Email: solomonbog@socnet.store Use these contacts to discuss wholesale orders, partnerships (current list: https://socnet.bgng.io/partners) or to become a supplier. SocNet — your shop for digital goods and premium subscriptions
  • Topics

×
×
  • Create New...

AdBlock Extension Detected!

Our website is made possible by displaying online advertisements to our members.

Please disable AdBlock browser extension first, to be able to use our community.

I've Disabled AdBlock