


is tproxy really needed


check Kernel for TPROXY support

grep TPROXY /boot/config-$(uname -r)

expect result:


check if Kernel TPROXY module is available

ls /lib/modules/$(uname -r)/kernel/net/netfilter | grep TPROXY

expect result:


check if module could be loaded(verbose and dry-run)

sudo modprobe -v -n xt_TPROXY

expect result:

# no error or
insmod /lib/modules/4.15.0-23-generic/kernel/net/netfilter/xt_TPROXY.ko

load module

sudo modprobe -v xt_TPROXY

expect result:

insmod /lib/modules/4.15.0-23-generic/kernel/net/netfilter/xt_TPROXY.ko

check if module is loaded

lsmod | grep -i tproxy

expect result:

xt_TPROXY              17327  0
nf_defrag_ipv6         35104  2 xt_TPROXY,nf_conntrack_ipv6
nf_defrag_ipv4         12729  2 xt_TPROXY,nf_conntrack_ipv4


cd /etc/modules-load.d/
echo "xt_TPROXY" > xt_TPROXY.conf

check for iptables extension ‘tproxy’

iptables -j TPROXY --help 

expect result: ``` … TPROXY target options: –on-port port Redirect connection to port, or the original port if 0 –on-ip ip Optionally redirect to the given IP –tproxy-mark value[/mask] Mark packets with the given value/mask

参考 https://github.com/tinyproxy/tinyproxy/issues/181

The source code for this article can be found here. If you find any errors or have any comments, please click on the link to raise an issue in the corresponding GitHub repo.

© 2024 wanmyj   •  Powered by Soopr   •  Theme  Moonwalk