This past week, during a transition between internet accounts from the same provider ( gotta love monopolies! ), I setup a rasberrypi b+ as a temporary router using a 4g cellular hotspot as our primary internet connection.
The maximum data plan available through t-mobile provided only 21GB of data for $120 a month. At 4g LTE speeds, ~50Mbps, you can burn through 21GB in just about an hour.
Clearly, we needed to figure out ways to conserve bandwidth, particularly for an office of 6-8 people all sharing the same connection.
Enter Privoxy, Polipo, Dnsmasq, and some iptables magic.
So, first off, I’m assuming you’ve got the latest Raspbian installed. This was built on the 2014-12-24 release.
So, lets add the usb0 network interface and set it to get an ip address via DHCP.
/etc/network/interfaces
|
1 2 3 4 5 |
allow-hotplug usb0 iface usb0 inet dhcp # this should save your iptables rules across reboots pre-up iptables-restore < /etc/iptables.rules post-down iptables-save > /etc/iptables.rules |
Next, lets go get all the software we’ll need to get this done:
|
1 |
sudo apt-get install -y dnsmasq privoxy polipo avahi-daemon |
Avahi is just because I don’t like to type IP addresses…
Next up is /etc/dnsmasq.conf for providing dhcp service for our network:
|
1 2 3 4 5 6 7 8 |
# add this: dhcp-range=192.168.2.10,192.168.2.160,12h # router is this pi here. dhcp-option=3,192.168.2.1 # and a beefy cache for good measure cache-size=15000 |
Then Privoxy
|
1 2 3 4 5 6 7 8 |
# localhost only, but can be handy to set to 0.0.0.0 for debugging listen-address 127.0.01:8118 # this is important: forward requests to polipo forward / localhost:8123 # this lets you use iptables to set intercepted requests to privoxy accept-intercepted-requests 1 |
Next, we’ve got polipo, our lightweight caching proxy: /etc/polipo/config
|
1 2 3 4 5 6 7 8 |
# can be useful to set to 0.0.0.0 as well for debugging proxyAddress = "127.0.0.1" allowedClients = 127.0.0.1, 192.168.2.0/24,192.168.2.1 proxyName = "piCachingProxy" # for speed, using our handy caching proxy dnsmasq on the Pi! dnsNameServer=192.168.2.1 |
I’d reboot at this moment, to make sure everything comes up roses, plug in your android phone or hotspot setup to do USB tethering.
Then, finally, the iptables rules that do that magic:
|
1 2 3 4 5 6 7 8 9 10 11 12 |
iptables --flush # remove all previous rules iptables --table nat --flush # remove all previous nat tables iptables --delete-chain # remove all chains iptables --table nat --delete-chain # remove chains for nat tables # before we try to route port 80 from eth0, send it to privoxy iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 80 -j DNAT --to 127.0.0.1:8118 # let all traffic owned by the proxy user (polipo) leave iptables -t nat -A OUTPUT -p tcp --dport 80 -m owner --uid-owner proxy -j ACCEPT # use NAT and send all traffic out through usb0, our tethered android phone. iptables --table nat --append POSTROUTING --out-interface usb0 -j MASQUERADE |
Now, you should have your ethernet port serving up IP addresses to your lan, routing all traffic through privoxy and polipo to cache, and serving dns requests locally to your caching dns proxy.
Nota Bene: Should work with iPhones, but you’ll need to install some extra tools and configuration.
Home