iptables -t nat -A POSTROUTING -s 192.168.30.0/24 -o enp3s1 -j MASQUERADE
sysctl -w net.ipv4.ip_forward=1
iptables -t nat -A PREROUTING -s 192.168.30.0/24 ! -d 192.168.30.1 -p tcp -m multiport --dport 80,81,82,83,88,8000,8001,8002,8080,8081 -j REDIRECT --to-port 3129
iptables -t nat -D PREROUTING -s 192.168.30.0/24 -p tcp -m multiport --dport 80,81,82,83,88,8000,8001,8002,8080,8081 -j REDIRECT --to-port 3129
RUN curl -o /etc/yum.repos.d/public-yum-ol7.repo https://yum.oracle.com/public-yum-ol7.repo && \
yum-config-manager --enable ol7_developer_nodejs10 ol7_oracle_instantclient && \
yum -y install nodejs oracle-instantclient18.3-basic oracle-instantclient18.3-devel oracle-instantclient18.3-sqlplus && \
rm -rf /var/cache/yum && \
echo /usr/lib/oracle/18.3/client64/lib > /etc/ld.so.conf.d/oracle-instantclient18.3.conf && \
ldconfig
FROM oraclelinux:7-slim
# ENV HTTP_PROXY "PATH"
# ENV HTTPS_PROXY "PATH"
# ENV FTP_PROXY "PATH"
RUN curl -o /etc/yum.repos.d/public-yum-ol7.repo https://yum.oracle.com/public-yum-ol7.repo && \
yum-config-manager --enable ol7_oracle_instantclient && \
yum -y install oracle-instantclient18.3-basic oracle-instantclient18.3-devel oracle-instantclient18.3-sqlplus && \
rm -rf /var/cache/yum && \
echo /usr/lib/oracle/18.3/client64/lib > /etc/ld.so.conf.d/oracle-instantclient18.3.conf && \
ldconfig
ENV PATH=$PATH:/usr/lib/oracle/18.3/client64/bin
FROM node:latest
COPY / ./
EXPOSE 3001
RUN npm rebuild oracledb
CMD ["npm", "start"]
SaveConfig = false
systemctl stop wg-quick@wg0
# transparent configuration ports
http_port 192.168.1.253:10080 intercept
https_port 192.168.1.253:10443 intercept ssl-bump options=ALL:NO_SSLv3:NO_SSLv2 connection-auth=off cert=/etc/squid/squidCA.pem
# тут всякое не относящееся к нашему вопросу
# SSL SSL SSL
sslproxy_cert_error allow all
sslproxy_flags DONT_VERIFY_PEER
acl step1 at_step SslBump1
ssl_bump peek step1
ssl_bump splice all
# ниже снова всякие другие опции, delay_pools и т.п.
➜ ~ docker ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
2e03db4ba018 c8088db441f8 "/sbin/tini -- /entr…" 4 weeks ago Up 7 days 0.0.0.0:8080->8080/tcp jira-test_jira_1
➜ ~ docker inspect 2e03db4ba018 | grep Source
"Source": "/home/dmitryg/tmp/jira-test/jira.config",
"Source": "/var/lib/docker/volumes/jira-test_jiralogs/_data",
"Source": "/home/dmitryg/tmp/jira-test/certs",
"Source": "/var/lib/docker/volumes/jira-test_jiradata/_data",
➜ ~
The routers option specifies a list of IP addresses for routers on the client's subnet. Routers should be listed in order of preference.
это странно, потому что например в третьем правиле, визуально (нет возможности на mktk сейчас попробовать) я не вижу каких либо проблем.
Может перед этими правилами есть какое то , куда трафик уходит и до них просто не доходит уже?