<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.secondlife.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Log+Linden</id>
	<title>Second Life Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.secondlife.com/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Log+Linden"/>
	<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/wiki/Special:Contributions/Log_Linden"/>
	<updated>2026-07-28T04:04:17Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.42.1</generator>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=Linden_Lab_Official:User_Groups&amp;diff=1217044</id>
		<title>Linden Lab Official:User Groups</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=Linden_Lab_Official:User_Groups&amp;diff=1217044"/>
		<updated>2024-08-08T22:24:07Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Current Events Nav}}&lt;br /&gt;
== About Second Life User Groups ==&lt;br /&gt;
&lt;br /&gt;
User groups are product or community focused and each one is led by the product manager or community manager. Our goals are to make it easier for you to find the user group, or groups, that you want to participate in and for us to listen more closely to your needs and ideas. The user group program is about opening up more lines of communication. Most user groups are public and include inworld meetings, JIRA sections, and sometimes a Twitter feed, an SL Forum, or an SL email list. It&#039;s up to the user group lead and the core Resident team how they want to communicate with one another. The discussions will be open, direct, and focus more on your needs, new features, and be more forward-looking.&lt;br /&gt;
&lt;br /&gt;
All Residents who join user groups must comply with the new [[Linden_Lab_Official:Community_Participation_Guidelines| Community Participation Guidelines]], in addition to our [http://secondlife.com/corporate/tos.php Terms of Service]. These guidelines ensure that all conversations are constructive, courteous, respectful, and in the spirit of collaboration. &lt;br /&gt;
&lt;br /&gt;
{{KBnote|User groups &#039;&#039;aren&#039;t&#039;&#039; for support help.  Instead, use the  [http://secondlife.com/support Support Portal].}}&lt;br /&gt;
&lt;br /&gt;
== Public User Group Meetings  ==&lt;br /&gt;
&lt;br /&gt;
For information on dates and times of user group meetings, see the user groups meeting schedule. And, each User Group has an individual page where agendas and archives reside. The program is still getting up to speed, so give each User Group leader time to fill in their content. Check back often!&lt;br /&gt;
&lt;br /&gt;
All times listed are [http://www.timeanddate.com/worldclock/city.html?n=224 Pacific Time].&lt;br /&gt;
&lt;br /&gt;
NOTE: By default, the table below is sorted chronologically by day of the week.  To sort alphabetically on any other column, click the icon in the column heading.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;lltable sortable&amp;quot; border=1&lt;br /&gt;
!width=120|User Group&lt;br /&gt;
!width=200|Description&lt;br /&gt;
!width=120|User Group Leader&lt;br /&gt;
!Frequency &lt;br /&gt;
!width=120|Days of Week&lt;br /&gt;
!width=100|Time (PT)&lt;br /&gt;
!Location (SLurl)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Server/Sim/Scripting}}&lt;br /&gt;
| Simulator issues and technology.&lt;br /&gt;
| Simon Linden&lt;br /&gt;
| Weekly&lt;br /&gt;
| Tuesday&lt;br /&gt;
| 12:00-13:00&lt;br /&gt;
| http://maps.secondlife.com/secondlife/Denby/217/45/32 &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Open Development}}&lt;br /&gt;
| Open discussion of SL development, including open source contributions.&lt;br /&gt;
| Vir Linden&lt;br /&gt;
| Bi-Weekly&lt;br /&gt;
| Wednesday&lt;br /&gt;
| 07:00-08:00&lt;br /&gt;
| {{SLurl|region=Hippotropolis|x=209|y=90|z=24|title=Oz&#039;s Raft}} or {{SLurl|region=Hippo Hollow|x=182|y=49|z=44}}&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Content Creation}} &lt;br /&gt;
| Discussion of SL content creation including avatars, animations, and other meshes.&amp;lt;br/&amp;gt;(Supersedes the Bento user group.)&lt;br /&gt;
| Vir Linden&lt;br /&gt;
| Bi-Weekly&lt;br /&gt;
1st, 3rd, and 5th Thursdays&lt;br /&gt;
| Thursday&lt;br /&gt;
| 13:00-14:00&lt;br /&gt;
| {{SLurl|region=Hippotropolis|x=71|y=172|z=30|title=Hippotropolis Campfire Circle}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Concierge &amp;amp; Land}}&lt;br /&gt;
| Discussion &amp;amp; education of SL topics such as current known issues and bugs, project viewers and new features, and general Mainland issues. &lt;br /&gt;
| Wendi Linden &amp;amp; Vix Linden&lt;br /&gt;
| Every 4th Wednesday&lt;br /&gt;
| Wednesday&lt;br /&gt;
| 12:00-13:00&lt;br /&gt;
|  [http://maps.secondlife.com/secondlife/Linden%20Estate%20Services4/228/16/28 Linden Estate Services4 228,16,28]&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Web}}&lt;br /&gt;
| Discussion of issues around Web properties such as Marketplace, Profiles, Place Pages, Search, etc.&lt;br /&gt;
| Sntax Linden&lt;br /&gt;
| Monthly&lt;br /&gt;
| Wednesday&lt;br /&gt;
| 14:00&lt;br /&gt;
| http://maps.secondlife.com/secondlife/Denby/73/78/25&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Skill Gaming}}&lt;br /&gt;
| Discussion of anything pertaining to the Skill Gaming Program. How to be part of the SLSG Program, questions about processes, and any known issues or concerns.&lt;br /&gt;
| Corky Linden&lt;br /&gt;
| Every 2nd Tuesday.&lt;br /&gt;
| Tuesday&lt;br /&gt;
| 11:00 - 12:00 &lt;br /&gt;
| http://maps.secondlife.com/secondlife/Havenhurst/92/159/21&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
| {{User Group|Governance}}&lt;br /&gt;
| Discussion of topics relating to safety and security in Second Life. Please note this does not include the discussion of Reports anyone has filed, the outcome of investigations, or potential actions taken on abuse, DMCA or copyright issues.&lt;br /&gt;
| Keira Linden&lt;br /&gt;
| Monthly, Every 2nd Thursday  &lt;br /&gt;
| Thursday&lt;br /&gt;
| 14:00 - 15:00 &lt;br /&gt;
| [http://maps.secondlife.com/secondlife/Linden%20Estate%20Services4/228/16/28 Linden Estate Services4 228,16,28]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[Category:User Groups]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:User Groups]]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=Message_Template&amp;diff=1215442</id>
		<title>Message Template</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=Message_Template&amp;diff=1215442"/>
		<updated>2023-11-22T18:55:38Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: We use git for the message template now. We had updated the URI to the github repository but still claimed it was a mercurial repository.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{OSWikiLearnBox|parent=Protocol}}&lt;br /&gt;
&lt;br /&gt;
The message template describes all of the [[message]]s that Second Life uses to communicate between hosts. All message templates must match a CRC check between hosts, otherwise they will not communicate with each other.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The master message template is stored in a public git repository at:&lt;br /&gt;
https://github.com/secondlife/master-message-template&lt;br /&gt;
&lt;br /&gt;
== See also ==&lt;br /&gt;
* [[Message]]s&lt;br /&gt;
* [[Packet Layout]]&lt;br /&gt;
* [http://lib.openmetaverse.org/template/ Template archive at libopenmetaverse]&lt;br /&gt;
* [https://github.com/cinderblocks/libremetaverse/tree/master/data/ LibreMetaverse (living fork of LibOpenMetaverse)]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=Logging_System_Overview&amp;diff=1208676</id>
		<title>Logging System Overview</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=Logging_System_Overview&amp;diff=1208676"/>
		<updated>2019-08-19T18:30:52Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Fixed typo in example logcontrol.xml that was causing parser error&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This document explains how to use the Second Life logging system in the SL Viewer and Simulator, in executable and runtime configuration.   &lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
Enable all developer functionality by including &amp;quot;&#039;&#039;&#039;llerror.h&#039;&#039;&#039;&amp;quot; (in llcommon).  Configure runtime settings with the log control file, as described in [[#Runtime control|Runtime control]].&lt;br /&gt;
&lt;br /&gt;
To get the maximum utility out of the log system, add the following &lt;br /&gt;
to the private section of your class declaration:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;LOG_CLASS(LLFoo);&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;    &lt;br /&gt;
    class LLFoo&lt;br /&gt;
    {&lt;br /&gt;
        LOG_CLASS(LLFoo);&lt;br /&gt;
    public:&lt;br /&gt;
        ...&lt;br /&gt;
    };&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Output===&lt;br /&gt;
The Viewer saves log output to &amp;lt;code&amp;gt;LL_PATH_APP_SETTINGS/logs/SecondLife.log&amp;lt;/code&amp;gt;, where LL_PATH_APP_SETTINGS is:&lt;br /&gt;
* &amp;lt;code&amp;gt;%APPDATA%\SecondLife\&amp;lt;/code&amp;gt; on Windows.&lt;br /&gt;
* &amp;lt;code&amp;gt;$HOME/Library/Application Support/SecondLife/&amp;lt;/code&amp;gt; on MacOS.&lt;br /&gt;
* &amp;lt;code&amp;gt;$HOME/.secondlife/&amp;lt;/code&amp;gt; on Linux.&lt;br /&gt;
&lt;br /&gt;
The server sends log output to &amp;lt;code&amp;gt;/var/log/indra.log&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
== Logging macros ==&lt;br /&gt;
&lt;br /&gt;
To selectively enable or disable log messages at runtime, use log message tag strings (a &amp;quot;broad&amp;quot; scope tag and a &amp;quot;narrow&amp;quot; scope tag).  For an example, see the &#039;&#039;&#039;&amp;lt;key&amp;gt;tags&amp;lt;/key&amp;gt;&#039;&#039;&#039; block in [[#Runtime_control|Runtime control]].  &lt;br /&gt;
&lt;br /&gt;
If you really don&#039;t want to tag a message, pass NULL to the macro.  However, the overhead of logging a message is small.&lt;br /&gt;
&lt;br /&gt;
=== Basic macros ===&lt;br /&gt;
Use the base macros as follows:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;LL_DEBUGS(&amp;quot;BroadScopeTag&amp;quot;) &amp;lt;&amp;lt; &amp;quot;A debug level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;   &lt;br /&gt;
// This is a macro, not a string stream.  The &amp;quot;LL_ENDL&amp;quot; is required.&lt;br /&gt;
LL_INFOS(&amp;quot;BroadScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;An info level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_WARNS(&amp;quot;BroadScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;A warning level log message&amp;quot; &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_ERRS(&amp;quot;BroadScopeTag&amp;quot;)   &amp;lt;&amp;lt; &amp;quot;An error level log message&amp;quot;  &amp;lt;&amp;lt; LL_ENDL;   &lt;br /&gt;
//  LL_ERRS forces a crash of the viewer.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The logging macros behave like iostreams.  You can appended anything to them that can be appended to an iostream.&lt;br /&gt;
&lt;br /&gt;
=== Dual tag macros ===&lt;br /&gt;
&lt;br /&gt;
With dual tag macros, you to bind two string tags to a log message: a &amp;quot;broad&amp;quot; scope tag and a &amp;quot;narrow&amp;quot; scope tag, useful to specify a high granularity and a low granularity tag for a log message.  For example, you could specify &amp;quot;AppInit&amp;quot; and &amp;quot;SystemInfo&amp;quot; tags, where &amp;quot;AppInit&amp;quot; is the broad scope tag for the long application initialization process of which the narrow scope tag &amp;quot;SystemInfo&amp;quot; printing is a small portion.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;LL_DEBUGS2(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;) &amp;lt;&amp;lt; &amp;quot;A debug level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;  &lt;br /&gt;
// NOTE: This is a macro, not a string stream.  The &amp;quot;LL_ENDL&amp;quot; is required.&lt;br /&gt;
LL_INFOS2(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;An info level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_WARNS2(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;A warning level log message&amp;quot; &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_ERRS2(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;)   &amp;lt;&amp;lt; &amp;quot;An error level log message&amp;quot;  &amp;lt;&amp;lt; LL_ENDL;    &lt;br /&gt;
// NOTE: LL_ERRS2 force a crash of the viewer.&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Tag formatting ===&lt;br /&gt;
&lt;br /&gt;
Format macro tags in &amp;quot;camel case&amp;quot;, such as &amp;quot;RenderInit&amp;quot; and &amp;quot;TextureCache&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Tags may not contain whitespace characters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Obsolete macros ===&lt;br /&gt;
&lt;br /&gt;
In the past, the &amp;quot;&#039;&#039;&#039;llerrs&#039;&#039;&#039;&amp;quot;, &amp;quot;&#039;&#039;&#039;llwarns&#039;&#039;&#039;&amp;quot;, &amp;quot;&#039;&#039;&#039;llinfos&#039;&#039;&#039;&amp;quot;, &amp;quot;&#039;&#039;&#039;lldebugs&#039;&#039;&#039;&amp;quot;, and &amp;quot;&#039;&#039;&#039;llendl&#039;&#039;&#039;&amp;quot;  macros were less capable versions of the current system. For a long time, they were allowed, but now they have been replaced with those documented here and removed.&lt;br /&gt;
&lt;br /&gt;
== Logging a repeating message only once ==&lt;br /&gt;
&lt;br /&gt;
Sometimes log messages will get triggered repeatedly, filling the log file with the same exact message string over and over.  To avoid cases like this, use the &amp;quot;ONCE&amp;quot; macros &lt;br /&gt;
These macros print the message the first time, prepending &amp;quot;ONCE: &amp;quot; to the message string.  Subsequently, when it is triggered &#039;&#039;&#039;with the same message&#039;&#039;&#039; it will print only the 10th, 50th, or every 100th time thereafter.  Then, it updates you by prepending &amp;quot;ONCE (Nth time seen): &amp;quot; to the log message, where N is the number of times it has been seen.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note:&#039;&#039;&#039; This works on unique final log messages, so log messages that depend on one or more variables have the final output treated as different messages if any part of the string changes.  Thus, you should not use ONCE macros for log messages that will print many times but with different messages, as this would be slightly slower and would slowly fill up a std::map with memory occupying junk.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;LL_DEBUGS_ONCE(&amp;quot;BroadScopeTag&amp;quot;) &amp;lt;&amp;lt; &amp;quot;A debug level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;   &lt;br /&gt;
// NOTE: This is a macro, not a string stream.  The &amp;quot;LL_ENDL&amp;quot; is required.&lt;br /&gt;
LL_INFOS_ONCE(&amp;quot;BroadScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;An info level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_WARNS_ONCE(&amp;quot;BroadScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;A warning level log message&amp;quot; &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
&lt;br /&gt;
LL_DEBUGS2_ONCE(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;) &amp;lt;&amp;lt; &amp;quot;A debug level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;   &lt;br /&gt;
// NOTE: This is a macro, not a string stream.  The &amp;quot;LL_ENDL&amp;quot; is required.&lt;br /&gt;
LL_INFOS2_ONCE(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;An info level log message&amp;quot;   &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
LL_WARNS2_ONCE(&amp;quot;BroadScopeTag&amp;quot;, &amp;quot;NarrowScopeTag&amp;quot;)  &amp;lt;&amp;lt; &amp;quot;A warning level log message&amp;quot; &amp;lt;&amp;lt; LL_ENDL;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For example, the following log message:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;LL_WARNS_ONCE(&amp;quot;Drawable&amp;quot;) &amp;lt;&amp;lt; &amp;quot;Drawable becomes static with active parent!&amp;quot; &amp;lt;&amp;lt; LL_ENDL;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Will print the following messages to &amp;lt;code&amp;gt;SecondLife.log&amp;lt;/code&amp;gt; if it kept getting called repeatedly:&lt;br /&gt;
&lt;br /&gt;
    WARNING: LLDrawable::makeStatic: ONCE: Drawable becomes static with active parent! &lt;br /&gt;
    WARNING: LLDrawable::makeStatic: ONCE (10th time seen): Drawable becomes static with active parent! &lt;br /&gt;
    WARNING: LLDrawable::makeStatic: ONCE (50th time seen): Drawable becomes static with active parent! &lt;br /&gt;
    WARNING: LLDrawable::makeStatic: ONCE (100th time seen): Drawable becomes static with active parent! &lt;br /&gt;
    WARNING: LLDrawable::makeStatic: ONCE (200th time seen): Drawable becomes static with active parent! &lt;br /&gt;
    ...&lt;br /&gt;
&lt;br /&gt;
== Runtime control ==&lt;br /&gt;
&lt;br /&gt;
Configuration runtime settings with the &#039;&#039;log control file&#039;&#039;, an XML file that the application loads immediately &lt;br /&gt;
after initialization.  First, it tries to load &amp;lt;code&amp;gt;logcontrol-dev.xml&amp;lt;/code&amp;gt;.  If that file doesn&#039;t exist, then it loads &amp;lt;code&amp;gt;logcontrol.xml&amp;lt;/code&amp;gt; instead.  The application checks the file for changes every couple of seconds and reloads it if necessary.  &lt;br /&gt;
&lt;br /&gt;
Put the &amp;lt;code&amp;gt;logcontrol-dev.xml&amp;lt;/code&amp;gt; file into your user settings directory &#039;&#039;&#039;before launching the viewer&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
=== Sample Control File ===&lt;br /&gt;
&lt;br /&gt;
The following is a sample &amp;lt;code&amp;gt;logcontrol.xml&amp;lt;/code&amp;gt; file that sets the default loggging level to WARN and then conditionally turns on some warnings at INFO level and DEBUG level based on &amp;quot;function name&amp;quot;, &amp;quot;class name&amp;quot;, &amp;quot;file name&amp;quot;, and &amp;quot;tag&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;xml&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;llsd&amp;gt;&lt;br /&gt;
&amp;lt;map&amp;gt;&lt;br /&gt;
    &amp;lt;!-- default-level can be ALL, DEBUG, INFO, WARN, ERROR, or NONE --&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;default-level&amp;lt;/key&amp;gt;    &amp;lt;string&amp;gt;WARN&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;print-location&amp;lt;/key&amp;gt;   &amp;lt;boolean&amp;gt;false&amp;lt;/boolean&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;settings&amp;lt;/key&amp;gt;&lt;br /&gt;
        &amp;lt;array&amp;gt;&lt;br /&gt;
            &amp;lt;map&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;level&amp;lt;/key&amp;gt;&amp;lt;string&amp;gt;INFO&amp;lt;/string&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;functions&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;LLAgentInfo::handleImageRequest&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;classes&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;LLBufferArray&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;files&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;!-- entries in &#039;files&#039; match partial pathnames:&lt;br /&gt;
                             everything below indra/ --&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;newview/lldrawpoolavatar.cpp&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;tags&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;AppInit&amp;lt;/string&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;TextureCache&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
            &amp;lt;/map&amp;gt;&lt;br /&gt;
            &amp;lt;map&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;level&amp;lt;/key&amp;gt;&amp;lt;string&amp;gt;DEBUG&amp;lt;/string&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;functions&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;classes&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;files&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;llui/llbutton.cpp&amp;lt;/string&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;llui/llcombobox.cpp&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
                &amp;lt;key&amp;gt;tags&amp;lt;/key&amp;gt;&lt;br /&gt;
                    &amp;lt;array&amp;gt;&lt;br /&gt;
                        &amp;lt;string&amp;gt;RenderInit&amp;lt;/string&amp;gt;&lt;br /&gt;
                    &amp;lt;/array&amp;gt;&lt;br /&gt;
            &amp;lt;/map&amp;gt;&lt;br /&gt;
        &amp;lt;/array&amp;gt;&lt;br /&gt;
&amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/llsd&amp;gt;&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Logging granularity conflict resolution ==&lt;br /&gt;
&lt;br /&gt;
The logging system decides in the following order what logging granularity to apply to a message:&lt;br /&gt;
&lt;br /&gt;
# Default log level&lt;br /&gt;
# BroadScopeTag&lt;br /&gt;
# File Name&lt;br /&gt;
# Class Name&lt;br /&gt;
# Function Name&lt;br /&gt;
# NarrowScopeTag&lt;br /&gt;
&lt;br /&gt;
The application uses the highest matching priority level found in the log control file to determine whether to print a particular log message.  For example, if a given log message is of a class set in the log control file to print all &#039;&#039;&#039;LL_DEBUGS()&#039;&#039;&#039; and below, but there is an entry for its function name that states to print only &#039;&#039;&#039;LL_WARNS()&#039;&#039;&#039; and below, then the system will print only &#039;&#039;&#039;LL_WARNS()&#039;&#039;&#039; and &#039;&#039;&#039;LL_ERRS()&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Continuing a log message after further computation ==&lt;br /&gt;
&lt;br /&gt;
Use the &#039;&#039;&#039;LL_CONT&#039;&#039;&#039; macro if you need to do computation in the middle of a log message:&lt;br /&gt;
	&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;    &lt;br /&gt;
    LL_DEBUGS(&amp;quot;AgentGesture&amp;quot;) &amp;lt;&amp;lt; &amp;quot;the agent &amp;quot; &amp;lt;&amp;lt; agend_id;&lt;br /&gt;
    switch (f)&lt;br /&gt;
    {&lt;br /&gt;
        case FOP_SHRUGS:   LL_CONT &amp;lt;&amp;lt; &amp;quot;shrugs&amp;quot;;              break;&lt;br /&gt;
        case FOP_TAPS:     LL_CONT &amp;lt;&amp;lt; &amp;quot;points at &amp;quot; &amp;lt;&amp;lt; who;   break;&lt;br /&gt;
        case FOP_SAYS:     LL_CONT &amp;lt;&amp;lt; &amp;quot;says &amp;quot; &amp;lt;&amp;lt; message;    break;&lt;br /&gt;
    }&lt;br /&gt;
    LL_CONT &amp;lt;&amp;lt; &amp;quot; for &amp;quot; &amp;lt;&amp;lt; t &amp;lt;&amp;lt; &amp;quot; seconds&amp;quot; &amp;lt;&amp;lt; LL_ENDL;   &lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Make sure to remember the &#039;&#039;&#039;LL_ENDL&#039;&#039;&#039; at the end and &#039;&#039;&#039;ONLY&#039;&#039;&#039; at the end.&lt;br /&gt;
		&lt;br /&gt;
Any computation embedded as above is done only if the message will be logged.&lt;br /&gt;
&lt;br /&gt;
This means that you can also use the macro functionality to conditionally call separate functions only if that granularity of logging is enabled, such as in the following example from &amp;lt;code&amp;gt;llfeaturemanager.cpp&amp;lt;/code&amp;gt;:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;source lang=&amp;quot;cpp&amp;quot;&amp;gt;    &lt;br /&gt;
LL_DEBUGS(&amp;quot;RenderInit&amp;quot;) &amp;lt;&amp;lt; &amp;quot;After applying mask &amp;quot; &amp;lt;&amp;lt; mask.mName;&lt;br /&gt;
// Will conditionally call dump only if the above message will be logged, thanks &lt;br /&gt;
// to it being wrapped by the LL_DEBUGS and LL_ENDL macros.&lt;br /&gt;
dump();&lt;br /&gt;
LL_CONT &amp;lt;&amp;lt; LL_ENDL;&lt;br /&gt;
&amp;lt;/source&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Log Line Format =&lt;br /&gt;
&lt;br /&gt;
Log entries are written as a single line formatted as:&lt;br /&gt;
 &#039;&#039;timestamp&#039;&#039; SPACE &#039;&#039;level&#039;&#039; SPACE &#039;&#039;tags&#039;&#039; SPACE &#039;&#039;location&#039;&#039; SPACE &#039;&#039;function&#039;&#039; SPACE COLON SPACE &#039;&#039;message&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Where&lt;br /&gt;
* &#039;&#039;timestamp&#039;&#039; is an ISO format date/time stamp like &amp;lt;tt&amp;gt;2018-09-19T13:38:53Z&amp;lt;/tt&amp;gt;&lt;br /&gt;
* &#039;&#039;level&#039;&#039; is the severity level&lt;br /&gt;
* &#039;&#039;tags&#039;&#039; is any tag values, surrounded by &#039;#&#039; characters, or a single &#039;#&#039; if there are no tags specified, like &amp;lt;tt&amp;gt;#HTTPCore#&amp;lt;/tt&amp;gt; or &amp;lt;tt&amp;gt;#HTTPCore#Initialize#&amp;lt;/tt&amp;gt;&lt;br /&gt;
* &#039;&#039;location&#039;&#039; is the path name (relative to the top level &amp;lt;tt&amp;gt;indra&amp;lt;/tt&amp;gt; directory) and line number in parenthesis like &amp;lt;tt&amp;gt;llcorehttp/httpstats.cpp(104)&amp;lt;/tt&amp;gt;&lt;br /&gt;
* &#039;&#039;function&#039;&#039; is the class and method or function name like &amp;lt;tt&amp;gt;LLControlGroup::get&amp;lt;/tt&amp;gt;&lt;br /&gt;
* SPACE is a single space character&lt;br /&gt;
* COLON is a single colon character (&#039;:&#039;)&lt;br /&gt;
* &#039;&#039;message&#039;&#039; is the log message, with any backslash, newline, and return characters escaped (see below)&lt;br /&gt;
&lt;br /&gt;
For example:&lt;br /&gt;
 2018-09-19T13:38:53Z WARNING #HTTPCore# llcorehttp/httpstats.cpp(104) dumpStats : HTTP DATA SUMMARY\nHTTP Transfer counts:\nData Sent: 0B   (0)\nData Recv: 0B   (0)\nTotal requests: 4(request objects created)\n\nResult Codes:\n--- -----\n200 1\n&lt;br /&gt;
&lt;br /&gt;
== Log Line Escaping ==&lt;br /&gt;
&lt;br /&gt;
The log message may be multiple lines; any line breaks will be escaped by substituting&lt;br /&gt;
 newline &amp;amp;rarr; \n&lt;br /&gt;
 return &amp;amp;rarr; \r&lt;br /&gt;
 \ &amp;amp;rarr; \\&lt;br /&gt;
&lt;br /&gt;
This escaping can be undone for readability by piping the log file through a filter like:&lt;br /&gt;
 perl -pe &#039;s/\\\\/\\/g; s/\\n/\n/g; s/\\r/\r/g;&#039; &lt;br /&gt;
&lt;br /&gt;
The example line above when run through that filter becomes:&lt;br /&gt;
 2018-09-19T13:38:53Z WARNING #HTTPCore# llcorehttp/httpstats.cpp(104) dumpStats : HTTP DATA SUMMARY&lt;br /&gt;
 HTTP Transfer counts:&lt;br /&gt;
 Data Sent: 0B   (0)&lt;br /&gt;
 Data Recv: 0B   (0)&lt;br /&gt;
 Total requests: 4(request objects created)&lt;br /&gt;
&lt;br /&gt;
 Result Codes:&lt;br /&gt;
 --- -----&lt;br /&gt;
 200 1&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=Project_Sunshine-Server_Side_Appearance&amp;diff=1175290</id>
		<title>Project Sunshine-Server Side Appearance</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=Project_Sunshine-Server_Side_Appearance&amp;diff=1175290"/>
		<updated>2012-12-14T21:49:43Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Server Side &amp;quot;Texture Baking&amp;quot; Viewer Release  =&lt;br /&gt;
&lt;br /&gt;
== Structure of Server side texture baking&amp;lt;br&amp;gt;  ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Server Side Appearance Architecture.png|720px]] &lt;br /&gt;
&lt;br /&gt;
== Viewer Architecture changes &amp;lt;br&amp;gt;  ==&lt;br /&gt;
&lt;br /&gt;
In order to accomodate the back-end server code we have refactored a significant portion of the avatar appearance pipeline. There is now a new &amp;quot;project&amp;quot; in the indra directory called &amp;quot;llappearance&amp;quot; which defines a set of interface and functional classes that are shared between the viewer and the back end rendering system. These classes were pulled out of newview, and range from avatar definitions (LLVOAvatar), to tex layers and visual parameters. In addition, a number of texture functions and classes have been moved from newview to llrender. In some cases, these classes were subclassed to contain the viewer-specific functionality back in newview. &lt;br /&gt;
&lt;br /&gt;
Since some of the functionality of the classes was moved to a different directory while other pieces stayed, many merge tools will get confused and not necessarily move your changes to the correct place and in some cases may believe that the proper solution is to remove your fixes or be unable to merge the patches at all. Expect that there will be some manual merging necessary, especially if your viewer has made avatar/appearance changes or tweaks. We will assist whenever possible with questions about the new architecture or merge questions, but the new changes will be necessary for viewers to have after we start to roll out new servers. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== New Network Protocols &amp;lt;br&amp;gt; ==&lt;br /&gt;
&lt;br /&gt;
To support the new featureset, a few of the network protocols have been modified or added to: &lt;br /&gt;
&lt;br /&gt;
#login now returns a texture fetch url for any baked texture requests&amp;lt;br&amp;gt; &lt;br /&gt;
#Agent Appearance message now contains an extra visual parameter to indicate that it is a new-style message&lt;br /&gt;
#Agent Appearance message has an extra (optional) block to indicate appearance version number and current outfit folder version number&lt;br /&gt;
#Regions now have a new capability to request an appearance message which will return or regenerate the agent appearance message&lt;br /&gt;
#Regions will soon have a new capability to request an increase in current outfit folder verion (see below).&lt;br /&gt;
&lt;br /&gt;
== Forwards and Backwards Compatibility &amp;lt;br&amp;gt;  ==&lt;br /&gt;
&lt;br /&gt;
This project was designed under the assumption that viewers will be updated before the server code gains widespread adoption. However, the server code will take a while to test, scale up, and roll out. As such, the viewer code provided can work fine on the grid as it stands today. The new code should still upload new baked textures and use the old protocols on the main grid. Once a new viewer connects to a new server, that user&#039;s appearance message will be converted to a server-generated message that will persist even once you return to an old region. New-style appearance messages will remain flagged as such even when sent by an old region. Since textures are fetched from a central service, updated viewers will be able to fetch an avatar&#039;s textures even if the server does not support it. &lt;br /&gt;
&lt;br /&gt;
If you force a rebake or change your outfit while standing on an old-style region, however, your viewer will revert to uploading its own bakes. These will be overwritten when you return to a new-style region. &lt;br /&gt;
&lt;br /&gt;
Our testing regions on Aditi are set up next to some server-trunk regions so that you can test these transitions. Please be certain to test with multiple viewers so that you can verify that avatar appearance is consistent from multiple users. &lt;br /&gt;
&lt;br /&gt;
== Status of viewer repository&amp;lt;br&amp;gt;  ==&lt;br /&gt;
&lt;br /&gt;
This code is provided as pre-alpha quality. We have done a recent merge from viewer-development, and QA&amp;amp;nbsp;has done a quick test to verify that there are not major regressions. However, it is not production ready and there will be additional patches and bug fixes that will need to be intergrated before release. We are releasing the current state of code to get feedback, identify and isolate bugs, and provide extra time for alternate viewers to start the merging process. Please do not merge this into your main repository, but start a fresh fork that can be merged in once the code is stabilized. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Initial testing appears to indicate that this viewer does the correct thing in most cases of login, region crossing between new and old simulators, etc. There are a few known bad edge cases currently: &lt;br /&gt;
&lt;br /&gt;
#Saving a wearable item while making no other changes to your appearance does not update your appearance. We&#039;re adding a new capability that will compensate for this case, and a fallback for old regions in the mixed-grid case.&amp;lt;br&amp;gt;&lt;br /&gt;
#Initial appearance message after transitioning from an old region to a server-bake region may send an inaccurate appearance, with COF&amp;amp;nbsp;version = 0.&lt;br /&gt;
#Bakes on aditi will be overlayed with some hex values (the first few digits of their UUIDs). This is temporary and on purpose (for determining whether an image is a local or a server-generated bake). This will be removed before release.&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Keep checking in for additional information on known issues and updates. More code will be pushed periodically as we fix the remaining issues and make any refinements. &lt;br /&gt;
&lt;br /&gt;
While the code is not finished, it does appear to be functional enough to test and we do not anticipate additional major refactoring. Please start your merge work soon, and let us know when your release schedule will allow you to present the new viewers to your userbase. Once we start rolling out the new server code on the main grid, viewers that have not been updated will fail to resolve avatar appearance for themselves and others. Avatars that have changed their appearance on a new-style region will continue to appear incorrectly even after moving back to current server-trunk regions. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Reporting Bugs, assistance with merge issues  ==&lt;br /&gt;
&lt;br /&gt;
The viewer should work as it does today on the main grid. There are regions on Aditi that have the new code ( SunshineTest, SunshineTest1 ). &lt;br /&gt;
&lt;br /&gt;
Bugs and edge cases with the current state of code, whether in the viewer code or the back-end service should be filed in JIRA under project sunshine ([https://jira.secondlife.com/browse/SUN SUN]).  If you are a developer and cannot access this project, contact [[User:Oz_Linden]].&lt;br /&gt;
&lt;br /&gt;
If you are having trouble with the new re-architecture or merging your appearance changes into the new codebase, please reach out to Nyx Linden (nyx at lindenlab.com). &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
== Source code &amp;amp; build links&amp;lt;br&amp;gt;  ==&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|SUN|Server Side Texture Baking}}| Support server side texture baking. |task=sunshine-external|repo=https://bitbucket.org/lindenlab/sunshine-external}}&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1166570</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1166570"/>
		<updated>2012-04-30T22:40:47Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Packet Capture Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
# Accept either username auth or no auth. If using username auth, use the same username and password that are used to sign on to this machine.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it. We need to open up some ports, enable SSL communication via the CONNECT method, and disable caching.&lt;br /&gt;
* A patch that will give us the access we need:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-08-16 15:22:55.420862811 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -661,7 +661,8 @@&lt;br /&gt;
 # Deny requests to unknown ports&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 # Deny CONNECT to other than SSL ports&lt;br /&gt;
-http_access deny CONNECT !SSL_ports&lt;br /&gt;
+## Removed to allow connection to caps router on simhosts.&lt;br /&gt;
+#http_access deny CONNECT !SSL_ports&lt;br /&gt;
 #&lt;br /&gt;
 # We strongly recommend the following be uncommented to protect innocent&lt;br /&gt;
 # web applications running on the proxy server who think the only&lt;br /&gt;
@@ -675,6 +676,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1114,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
@@ -3939,7 +3943,7 @@&lt;br /&gt;
 #      &amp;quot;0&amp;quot;.  May be overridden with -u on the command line.&lt;br /&gt;
 #&lt;br /&gt;
 #Default:&lt;br /&gt;
-# icp_port 3130&lt;br /&gt;
+icp_port 0&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: htcp_port&lt;br /&gt;
 #      The port number where Squid sends and receives HTCP queries to&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* To apply the patch, save it to a file named squid.diff in your home directory and run the following command:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo patch /etc/squid/squid.conf ~/squid.diff&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* If you would rather edit by hand, a sequence of instructions to do the above are listed below.1&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Comment out the following line:&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
* It should look like this:&lt;br /&gt;
 #http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* Now that the configuration file is correct, we need to restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors related to squid.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Packet Capture Tools == &lt;br /&gt;
* On a machine with the X11 graphical environment, you can use wireshark to capture packets going through the computer. Install wireshark with the following command.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install wireshark &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Allow non-root users to perform captures. Note that this should not be done on a machine that you do not trust all the users to monitor traffic.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo setcap &#039;CAP_NET_RAW+eip CAP_NET_ADMIN+eip&#039; /usr/bin/dumpcap &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Start wireshark. In the list of capture device, select &amp;quot;pseudo-device that captures on all interface&amp;quot;.  The program should be capturing packets.&lt;br /&gt;
* Use the filter box at the top to filter for specific protocols, like &amp;quot;http&amp;quot; or certain hosts with strings like &amp;quot;ip.addr == 192.168.1.120&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1166569</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1166569"/>
		<updated>2012-04-30T22:40:30Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Packet Capture Tools */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
# Accept either username auth or no auth. If using username auth, use the same username and password that are used to sign on to this machine.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it. We need to open up some ports, enable SSL communication via the CONNECT method, and disable caching.&lt;br /&gt;
* A patch that will give us the access we need:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-08-16 15:22:55.420862811 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -661,7 +661,8 @@&lt;br /&gt;
 # Deny requests to unknown ports&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 # Deny CONNECT to other than SSL ports&lt;br /&gt;
-http_access deny CONNECT !SSL_ports&lt;br /&gt;
+## Removed to allow connection to caps router on simhosts.&lt;br /&gt;
+#http_access deny CONNECT !SSL_ports&lt;br /&gt;
 #&lt;br /&gt;
 # We strongly recommend the following be uncommented to protect innocent&lt;br /&gt;
 # web applications running on the proxy server who think the only&lt;br /&gt;
@@ -675,6 +676,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1114,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
@@ -3939,7 +3943,7 @@&lt;br /&gt;
 #      &amp;quot;0&amp;quot;.  May be overridden with -u on the command line.&lt;br /&gt;
 #&lt;br /&gt;
 #Default:&lt;br /&gt;
-# icp_port 3130&lt;br /&gt;
+icp_port 0&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: htcp_port&lt;br /&gt;
 #      The port number where Squid sends and receives HTCP queries to&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* To apply the patch, save it to a file named squid.diff in your home directory and run the following command:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo patch /etc/squid/squid.conf ~/squid.diff&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* If you would rather edit by hand, a sequence of instructions to do the above are listed below.1&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Comment out the following line:&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
* It should look like this:&lt;br /&gt;
 #http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* Now that the configuration file is correct, we need to restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors related to squid.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Packet Capture Tools == &lt;br /&gt;
* On a machine with the X11 graphical environment, you can use wireshark to capture packets going through the computer. Install wireshark with the following command.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install wireshark &amp;lt;bash&amp;gt;&lt;br /&gt;
* Allow non-root users to perform captures. Note that this should not be done on a machine that you do not trust all the users to monitor traffic.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo setcap &#039;CAP_NET_RAW+eip CAP_NET_ADMIN+eip&#039; /usr/bin/dumpcap &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Start wireshark. In the list of capture device, select &amp;quot;pseudo-device that captures on all interface&amp;quot;.  The program should be capturing packets.&lt;br /&gt;
* Use the filter box at the top to filter for specific protocols, like &amp;quot;http&amp;quot; or certain hosts with strings like &amp;quot;ip.addr == 192.168.1.120&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer&amp;diff=1156120</id>
		<title>User:Log Linden/Socks5Viewer</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer&amp;diff=1156120"/>
		<updated>2011-10-26T17:42:28Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Test Builds */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Project Pages ==&lt;br /&gt;
* [https://jira.secondlife.com/browse/STORM-1112 Project Jira ]&lt;br /&gt;
* [https://codereview.secondlife.com/r/374/ Code Review ]&lt;br /&gt;
* [[/TestPlan | Test Plan ]]&lt;br /&gt;
== Test Builds ==&lt;br /&gt;
Use any current viewer, this code has been merged with viewer-development.&lt;br /&gt;
&lt;br /&gt;
== Screenshots ==&lt;br /&gt;
===First Revision===&lt;br /&gt;
[[File:Socks5_old.png]]&amp;lt;br /&amp;gt;&lt;br /&gt;
===Second Revision===&lt;br /&gt;
[[File:Socks5_new.png]]&amp;lt;br /&amp;gt;&lt;br /&gt;
__NOTOC__&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152473</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152473"/>
		<updated>2011-08-26T21:13:37Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Integrated Web Browser */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* You need a Second Life account that is able to upload mesh assets on the grid being tested. This will require you to have payment information on file and to pass a brief test on intellectual property rights. A tutorial to help you get set up is available in the [http://community.secondlife.com/t5/English-Knowledge-Base/Uploading-a-mesh-model/ta-p/974185 Second Life Knowledge Base].&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has both web parcel media and video parcel media.  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ collada.org website].&lt;br /&gt;
* To test the gpu table and feature table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dump is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in. If you are in Basic mode, change to Advanced and restart.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.)&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Reset &amp;quot;Other HTTP traffic proxy&amp;quot; radio button when configuration is not possible.&#039;&#039;&#039;&lt;br /&gt;
** Enable HTTP Proxy.&lt;br /&gt;
** Select HTTP proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable HTTP Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
** Enable SOCKS 5 Proxy.&lt;br /&gt;
** Select SOCKS 5 proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable SOCKS 5 Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test a configuration that asks for HTTP via SOCKS 5 when SOCKS 5 is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;.&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &amp;quot;Do not proxy&amp;quot;.&lt;br /&gt;
** Enable the SOCKS 5 proxy, and authentication. Make other http traffic use SOCKS 5. &lt;br /&gt;
** Click OK and quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:33:25Z WARNING: LLStartUp::startLLProxy: Invalid other HTTP proxy configuration.&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, change the value of Socks5AuthType to &amp;quot;FakeAuth&amp;quot;, a fake value.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:30:38Z WARNING: LLStartUp::startLLProxy: Invalid SOCKS 5 authentication type.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
** Re-enable HTTP Textures and HTTP inventory.&lt;br /&gt;
** Log out and back in for the next test.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
** Drop the object back into the world for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to the object you created.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152472</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152472"/>
		<updated>2011-08-26T21:13:02Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Reordered object creation tests to ease testing flow.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* You need a Second Life account that is able to upload mesh assets on the grid being tested. This will require you to have payment information on file and to pass a brief test on intellectual property rights. A tutorial to help you get set up is available in the [http://community.secondlife.com/t5/English-Knowledge-Base/Uploading-a-mesh-model/ta-p/974185 Second Life Knowledge Base].&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has both web parcel media and video parcel media.  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ collada.org website].&lt;br /&gt;
* To test the gpu table and feature table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dump is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in. If you are in Basic mode, change to Advanced and restart.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.)&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Reset &amp;quot;Other HTTP traffic proxy&amp;quot; radio button when configuration is not possible.&#039;&#039;&#039;&lt;br /&gt;
** Enable HTTP Proxy.&lt;br /&gt;
** Select HTTP proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable HTTP Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
** Enable SOCKS 5 Proxy.&lt;br /&gt;
** Select SOCKS 5 proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable SOCKS 5 Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test a configuration that asks for HTTP via SOCKS 5 when SOCKS 5 is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;.&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &amp;quot;Do not proxy&amp;quot;.&lt;br /&gt;
** Enable the SOCKS 5 proxy, and authentication. Make other http traffic use SOCKS 5. &lt;br /&gt;
** Click OK and quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:33:25Z WARNING: LLStartUp::startLLProxy: Invalid other HTTP proxy configuration.&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, change the value of Socks5AuthType to &amp;quot;FakeAuth&amp;quot;, a fake value.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:30:38Z WARNING: LLStartUp::startLLProxy: Invalid SOCKS 5 authentication type.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
** Re-enable HTTP Textures and HTTP inventory.&lt;br /&gt;
** Log out and back in for the next test.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
** Drop the object back into the world for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to the object you created.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152063</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152063"/>
		<updated>2011-08-23T01:51:43Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added check to make sure the other HTTP proxy radio button resets when the selected proxy type becomes disabled.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* You need a Second Life account that is able to upload mesh assets on the grid being tested. This will require you to have payment information on file and to pass a brief test on intellectual property rights. A tutorial to help you get set up is available in the [http://community.secondlife.com/t5/English-Knowledge-Base/Uploading-a-mesh-model/ta-p/974185 Second Life Knowledge Base].&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has both web parcel media and video parcel media.  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ collada.org website].&lt;br /&gt;
* To test the gpu table and feature table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dump is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in. If you are in Basic mode, change to Advanced and restart.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.)&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Reset &amp;quot;Other HTTP traffic proxy&amp;quot; radio button when configuration is not possible.&#039;&#039;&#039;&lt;br /&gt;
** Enable HTTP Proxy.&lt;br /&gt;
** Select HTTP proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable HTTP Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
** Enable SOCKS 5 Proxy.&lt;br /&gt;
** Select SOCKS 5 proxy as the &amp;quot;other HTTP traffic proxy&amp;quot;. &lt;br /&gt;
** Disable SOCKS 5 Proxy. &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that &amp;quot;Do not proxy.&amp;quot; is now selected as the Other HTTP traffic Proxy.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test a configuration that asks for HTTP via SOCKS 5 when SOCKS 5 is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;.&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &amp;quot;Do not proxy&amp;quot;.&lt;br /&gt;
** Enable the SOCKS 5 proxy, and authentication. Make other http traffic use SOCKS 5. &lt;br /&gt;
** Click OK and quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:33:25Z WARNING: LLStartUp::startLLProxy: Invalid other HTTP proxy configuration.&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, change the value of Socks5AuthType to &amp;quot;FakeAuth&amp;quot;, a fake value.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:30:38Z WARNING: LLStartUp::startLLProxy: Invalid SOCKS 5 authentication type.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
** Re-enable HTTP Textures and HTTP inventory.&lt;br /&gt;
** Log out and back in for the next test.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152062</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1152062"/>
		<updated>2011-08-23T01:43:57Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Fixes to test steps from the first runthrough of the test plan.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* You need a Second Life account that is able to upload mesh assets on the grid being tested. This will require you to have payment information on file and to pass a brief test on intellectual property rights. A tutorial to help you get set up is available in the [http://community.secondlife.com/t5/English-Knowledge-Base/Uploading-a-mesh-model/ta-p/974185 Second Life Knowledge Base].&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has both web parcel media and video parcel media.  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ collada.org website].&lt;br /&gt;
* To test the gpu table and feature table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dump is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in. If you are in Basic mode, change to Advanced and restart.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.)&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test HTTP via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;.&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &amp;quot;Do not proxy&amp;quot;.&lt;br /&gt;
** Enable the SOCKS 5 proxy, and authentication. Make other http traffic use SOCKS 5. &lt;br /&gt;
** Click OK and quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:33:25Z WARNING: LLStartUp::startLLProxy: Invalid other HTTP proxy configuration.&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, change the value of Socks5AuthType to &amp;quot;FakeAuth&amp;quot;, a fake value.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 2011-08-23T01:30:38Z WARNING: LLStartUp::startLLProxy: Invalid SOCKS 5 authentication type.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
** Re-enable HTTP Textures and HTTP inventory.&lt;br /&gt;
** Log out and back in for the next test.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151822</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151822"/>
		<updated>2011-08-19T21:30:41Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added wireshark info.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
# Accept either username auth or no auth. If using username auth, use the same username and password that are used to sign on to this machine.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it. We need to open up some ports, enable SSL communication via the CONNECT method, and disable caching.&lt;br /&gt;
* A patch that will give us the access we need:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-08-16 15:22:55.420862811 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -661,7 +661,8 @@&lt;br /&gt;
 # Deny requests to unknown ports&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 # Deny CONNECT to other than SSL ports&lt;br /&gt;
-http_access deny CONNECT !SSL_ports&lt;br /&gt;
+## Removed to allow connection to caps router on simhosts.&lt;br /&gt;
+#http_access deny CONNECT !SSL_ports&lt;br /&gt;
 #&lt;br /&gt;
 # We strongly recommend the following be uncommented to protect innocent&lt;br /&gt;
 # web applications running on the proxy server who think the only&lt;br /&gt;
@@ -675,6 +676,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1114,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
@@ -3939,7 +3943,7 @@&lt;br /&gt;
 #      &amp;quot;0&amp;quot;.  May be overridden with -u on the command line.&lt;br /&gt;
 #&lt;br /&gt;
 #Default:&lt;br /&gt;
-# icp_port 3130&lt;br /&gt;
+icp_port 0&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: htcp_port&lt;br /&gt;
 #      The port number where Squid sends and receives HTCP queries to&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* To apply the patch, save it to a file named squid.diff in your home directory and run the following command:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo patch /etc/squid/squid.conf ~/squid.diff&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* If you would rather edit by hand, a sequence of instructions to do the above are listed below.1&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Comment out the following line:&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
* It should look like this:&lt;br /&gt;
 #http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* Now that the configuration file is correct, we need to restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors related to squid.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
== Packet Capture Tools == &lt;br /&gt;
* On a machine with the X11 graphical environment, you can use wireshark to capture packets going through the computer. Install wireshark with the following command.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install wireshar &amp;lt;bash&amp;gt;&lt;br /&gt;
* Allow non-root users to perform captures. Note that this should not be done on a machine that you do not trust all the users to monitor traffic.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo setcap &#039;CAP_NET_RAW+eip CAP_NET_ADMIN+eip&#039; /usr/bin/dumpcap &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Start wireshark. In the list of capture device, select &amp;quot;pseudo-device that captures on all interface&amp;quot;.  The program should be capturing packets.&lt;br /&gt;
* Use the filter box at the top to filter for specific protocols, like &amp;quot;http&amp;quot; or certain hosts with strings like &amp;quot;ip.addr == 192.168.1.120&amp;quot;.&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151783</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151783"/>
		<updated>2011-08-19T20:06:28Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Configuration Consistency Checks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test HTTP via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;. The block should look like the following:&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &amp;quot;Do not proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151782</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151782"/>
		<updated>2011-08-19T20:06:05Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Configuration Consistency Checks */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test HTTP via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;. The block should look like the following:&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;&#039;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151781</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151781"/>
		<updated>2011-08-19T20:05:46Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Avatar Communication */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test HTTP via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;. The block should look like the following:&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can receive messages from other people.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are receiving group chat messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the display names of avatars are visible in your friends list.&lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151780</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151780"/>
		<updated>2011-08-19T19:44:30Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: capitalized http&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test HTTP via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;. The block should look like the following:&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151779</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151779"/>
		<updated>2011-08-19T19:43:10Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Fixed lists, converted all numbered lists to unordered list due to inability to include code blocks into steps.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{*if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
** Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
** Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
** Change these settings before logging into Second Life.&lt;br /&gt;
** Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
** Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
** Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
** Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
** Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
** Confirm that you want to clear the cache.&lt;br /&gt;
** Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
* &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
** Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
** Start the viewer that was installed, but do not log in.&lt;br /&gt;
** Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
** Inspect the settings.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
** Leave this floater open for the next test.&lt;br /&gt;
* &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039; Test http via socks when socks is disabled.&lt;br /&gt;
** Enable both proxies, enter valid information for both proxies.&lt;br /&gt;
** Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
** Change the value of Socks5ProxyEnabled to &amp;quot;0&amp;quot;. The block should look like the following:&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Restart the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
** Open the proxy preferences floater.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
** Quit the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
* &#039;&#039;&#039;Invalid Authentication Configuration Error-Handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
** Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
* Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
* This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
* &#039;&#039;&#039;Verify&#039;&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
* &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
** The proxy should be enabled before starting this test.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
** Start the viewer but do not log in.&lt;br /&gt;
** Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
** Close the viewer.&lt;br /&gt;
** Inspect the Secondlife.log file.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
* &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
** Start the viewer, but do not log in.&lt;br /&gt;
**&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
* &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
* &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
* &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
* &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
** Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
** Close the World Map.&lt;br /&gt;
* &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
** Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
* &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
** Fly or walk across a region boundary.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
* &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
* &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
** Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
* &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to others avatars standing nearby.  &lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
* &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
** Try sending messages to a group chat channel.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
* &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
** Try sending private IM messages to another avatar.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
* &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
* Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
* &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
** Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
* &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
** Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Travel to a region with mesh assets available.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
* &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
** Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
** Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
** Clear the viewer cache.&lt;br /&gt;
** Log back into Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
* Move to a region where you have permission to build.&lt;br /&gt;
* &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
** Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
** When the upload is complete, apply that texture to an object.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
* &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
** Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
** When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
* &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
** In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
** In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
** Add some text in the body of the notecard and click save.&lt;br /&gt;
** Close the notecard&lt;br /&gt;
** Reopen the notecard from your inventory.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
* &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
** Move to a mesh-enabled region.&lt;br /&gt;
** Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
** In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
** Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
** After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
** Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
* &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
** Create a simple object using the build tools.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
* &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
** Right click the object you created in the previous test and select edit.&lt;br /&gt;
** Select the content tab of the build floater.&lt;br /&gt;
** Click the New Script button.&lt;br /&gt;
** Double click the new script to edit.&lt;br /&gt;
** Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
** Click save&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
* &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
** Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
** Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
** Click the link in the text chat window.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
* &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
* &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
** Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
* &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
** Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
** Disable the proxy as described above.&lt;br /&gt;
** Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
*** Viewer Initialization&lt;br /&gt;
*** Avatar Navigation and Movement&lt;br /&gt;
*** Avatar Communication&lt;br /&gt;
*** Asset Download Tests&lt;br /&gt;
*** Asset Upload Tests&lt;br /&gt;
*** Integrated Web Browser&lt;br /&gt;
*** Media On a Prim&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
** Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
* &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
** Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
** Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
** Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
** Select OK.&lt;br /&gt;
** Try to log in to Second Life.&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
** Leave authentication enabled for the next test.&lt;br /&gt;
** Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
* &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
** Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
** Close all running instances of the viewer.&lt;br /&gt;
** Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
** Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
** Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
** step 1&lt;br /&gt;
** step 2&lt;br /&gt;
** &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
* &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
** No unexpected behaviors are observed&lt;br /&gt;
* &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
** Deviation from expected behavior is observed&lt;br /&gt;
** A bug is detected that was not accounted for by this test plan&lt;br /&gt;
** Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
* &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
** SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151762</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151762"/>
		<updated>2011-08-19T18:51:42Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
*# Change these settings before logging into Second Life.&lt;br /&gt;
*# Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
*# Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
*# Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
*# Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
*# Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
*# Change these settings before logging into Second Life.&lt;br /&gt;
*# Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
*# Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
*# Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
*# Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
*# Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
*# Change these settings before logging into Second Life.&lt;br /&gt;
*# Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
*# Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
*# Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
*# Click OK.&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
*# Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
*# Confirm that you want to clear the cache.&lt;br /&gt;
*# Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
## Start the viewer that was installed, but do not log in.&lt;br /&gt;
## Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
## Inspect the settings.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
## Leave this floater open for the next test.&lt;br /&gt;
# &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039;&lt;br /&gt;
## Enable both proxies, type in valid information for both proxies.&lt;br /&gt;
## Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
## Change the value of Socks5ProxyEnabled to be &amp;quot;0&amp;quot;. The block should look like the following.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
##: Restart the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
## Open the proxy preferences floater.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
# &#039;&#039;&#039;Invalid authentication configuration error-handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
## Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
## Start the viewer, but do not log in.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
# This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
# &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
## The proxy should be enabled before starting this test.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
## Start the viewer but do not log in.&lt;br /&gt;
## Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## Inspect the Secondlife.log file.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
## Start the viewer, but do not log in.&lt;br /&gt;
##&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
# &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
## Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
## Close the World Map.&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## Fly or walk across a region boundary.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to others avatars standing nearby.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to a group chat channel.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## Try sending private IM messages to another avatar.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
# &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
# Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
# &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
## Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Travel to a region with mesh assets available.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
## Clear the viewer cache.&lt;br /&gt;
## Log back into Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
# Move to a region where you have permission to build.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
## When the upload is complete, apply that texture to an object.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
## When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
## In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
## Add some text in the body of the notecard and click save.&lt;br /&gt;
## Close the notecard&lt;br /&gt;
## Reopen the notecard from your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Move to a mesh-enabled region.&lt;br /&gt;
## Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
## In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
## Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
## After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
## Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## Create a simple object using the build tools.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## Right click the object you created in the previous test and select edit.&lt;br /&gt;
## Select the content tab of the build floater.&lt;br /&gt;
## Click the New Script button.&lt;br /&gt;
## Double click the new script to edit.&lt;br /&gt;
## Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
## Click save&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
## Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
## Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
## Click the link in the text chat window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
# &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151671</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151671"/>
		<updated>2011-08-18T21:51:05Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added http tables test.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
* To test the gpu_table and feature_table download functionality of the viewer, a packet capture tool on the proxy host such as wireshark or tcp_dup is necessary to verify that the request tool is making use of the proxy. This might not be possible if you do not have access to your organization&#039;s proxy host.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
## Start the viewer that was installed, but do not log in.&lt;br /&gt;
## Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
## Inspect the settings.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
## Leave this floater open for the next test.&lt;br /&gt;
# &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039;&lt;br /&gt;
## Enable both proxies, type in valid information for both proxies.&lt;br /&gt;
## Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
## Change the value of Socks5ProxyEnabled to be &amp;quot;0&amp;quot;. The block should look like the following.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
## Restart the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
## Open the proxy preferences floater.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
# &#039;&#039;&#039;Invalid authentication configuration error-handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
## Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
## Start the viewer, but do not log in.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
# This should be run with the firewall fully enabled to ensure the only traffic is being sent through the proxy.&lt;br /&gt;
# &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the viewer is able to fetch the GPU table and feature table via the proxy.&lt;br /&gt;
## The proxy should be enabled before starting this test.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## Start a packet capture on the proxy host that captures on all interfaces. Note: Even if you are unable to use packet filtering software, complete the test and verify that the error strings below are not in the log file.&lt;br /&gt;
## Start the viewer but do not log in.&lt;br /&gt;
## Inspect the capture for an HTTP request for an HTTP GET for a file of the form gpu_table.X.Y.Z.txt and for featuretable.X.Y.Z.txt.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that there was a request originating from the test machine for each of these files, and a subsequent request from the proxy host for the same files.  It is normal for each of these requests to receive a 404 response.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## Inspect the Secondlife.log file.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that there are no logs matching the following in Secondlife.log.&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/featuretable_xp.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
 2011-08-18T21:42:07Z WARNING: LLURLRequest::process_impl: URLRequest Error: 56, Failure when receiving data from the peer, http://viewer-settings.secondlife.com/gpu_table.3.0.1.238013.txt&lt;br /&gt;
 2011-08-18T21:42:07Z INFO: LLPumpIO::processChain: Pump generated pipe err: &#039;STATUS_ERROR&#039;&lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&#039;&#039;&#039; The logon screen should be able to load content from the web using the configured proxy.&lt;br /&gt;
## Start the viewer, but do not log in.&lt;br /&gt;
##&#039;&#039;&#039;Verify&#039;&#039;&#039; that the contents of the login screen are displayed.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
# &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
## Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
## Close the World Map.&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## Fly or walk across a region boundary.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to others avatars standing nearby.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to a group chat channel.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## Try sending private IM messages to another avatar.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
# &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
# Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
# &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
## Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Travel to a region with mesh assets available.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
## Clear the viewer cache.&lt;br /&gt;
## Log back into Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
# Move to a region where you have permission to build.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
## When the upload is complete, apply that texture to an object.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
## When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
## In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
## Add some text in the body of the notecard and click save.&lt;br /&gt;
## Close the notecard&lt;br /&gt;
## Reopen the notecard from your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Move to a mesh-enabled region.&lt;br /&gt;
## Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
## In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
## Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
## After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
## Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## Create a simple object using the build tools.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## Right click the object you created in the previous test and select edit.&lt;br /&gt;
## Select the content tab of the build floater.&lt;br /&gt;
## Click the New Script button.&lt;br /&gt;
## Double click the new script to edit.&lt;br /&gt;
## Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
## Click save&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
## Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;).&lt;br /&gt;
## Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
## Click the link in the text chat window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Configure the viewer as described in the &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039; section above.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039; that you are able to successfully log into Second Life.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
# &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;br /&gt;
* Disable the built-in browser.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151635</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151635"/>
		<updated>2011-08-18T15:13:23Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added configuration validation.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the LLProxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## Install a version of the viewer that supports LLProxy communication.&lt;br /&gt;
## Start the viewer that was installed, but do not log in.&lt;br /&gt;
## Navigate to the proxy control floater (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;Adjust proxy Settings.&lt;br /&gt;
## Inspect the settings.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that both proxies are disabled.&lt;br /&gt;
## Leave this floater open for the next test.&lt;br /&gt;
# &#039;&#039;&#039;Invalid HTTP Proxy Configuration Error-Handling&#039;&#039;&#039;&lt;br /&gt;
## Enable both proxies, type in valid information for both proxies.&lt;br /&gt;
## Change the &amp;quot;Other HTTP traffic proxy&amp;quot; option to &amp;quot;Use SOCKS 5 proxy&amp;quot;.&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## Edit the settings.xml file that corresponds to the channel of the viewer you are using to test with (e.g. settings_developer.xml, settings.xml, settings_beta.xml, etc.).&lt;br /&gt;
## Change the value of Socks5ProxyEnabled to be &amp;quot;0&amp;quot;. The block should look like the following.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5ProxyEnabled&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Use Socks5 Proxy&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Boolean&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;0&amp;lt;/integer&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
## Restart the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash&lt;br /&gt;
## Open the proxy preferences floater.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the &amp;quot;Other HTTP traffic&amp;quot; proxy option is now set to &#039;&#039;&#039;Do not proxy&#039;&#039;.&#039;&lt;br /&gt;
## Quit the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid other HTTP proxy configuration.&amp;quot;&lt;br /&gt;
# &#039;&#039;&#039;Invalid authentication configuration error-handling.&#039;&#039;&#039; Test that an unexpected authentication method will not crash the viewer.&lt;br /&gt;
## Before starting the viewer, replace the block controlling the Socks5AuthType in settings.xml with another with a fake value. The following block should work.&lt;br /&gt;
&amp;lt;xml&amp;gt;&lt;br /&gt;
    &amp;lt;key&amp;gt;Socks5AuthType&amp;lt;/key&amp;gt;&lt;br /&gt;
    &amp;lt;map&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Comment&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;Selected Auth mechanism for Socks5&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Persist&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;integer&amp;gt;1&amp;lt;/integer&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Type&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;String&amp;lt;/string&amp;gt;&lt;br /&gt;
      &amp;lt;key&amp;gt;Value&amp;lt;/key&amp;gt;&lt;br /&gt;
      &amp;lt;string&amp;gt;FakeAuth&amp;lt;/string&amp;gt;&lt;br /&gt;
    &amp;lt;/map&amp;gt;&lt;br /&gt;
&amp;lt;/xml&amp;gt;&lt;br /&gt;
## Start the viewer, but do not log in.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the viewer doesn&#039;t crash.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that in the settings proxy floater, that authentication is disabled.&lt;br /&gt;
## Close the viewer.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that Secondlife.log contains the following warning:&lt;br /&gt;
 &amp;quot;Invalid SOCKS 5 authentication type.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the GPU table and feature table are able to be fetched by the proxy.&lt;br /&gt;
## Browse to the install directory of the viewer. &lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;goo&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
# &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
## Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
## Close the World Map.&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## Fly or walk across a region boundary.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to others avatars standing nearby.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to a group chat channel.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## Try sending private IM messages to another avatar.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
# &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
# Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
# &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
## Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Travel to a region with mesh assets available.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
## Clear the viewer cache.&lt;br /&gt;
## Log back into Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
# Move to a region where you have permission to build.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
## When the upload is complete, apply that texture to an object.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
## When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
## In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
## Add some text in the body of the notecard and click save.&lt;br /&gt;
## Close the notecard&lt;br /&gt;
## Reopen the notecard from your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Move to a mesh-enabled region.&lt;br /&gt;
## Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
## In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
## Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
## After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
## Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## Create a simple object using the build tools.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## Right click the object you created in the previous test and select edit.&lt;br /&gt;
## Select the content tab of the build floater.&lt;br /&gt;
## Click the New Script button.&lt;br /&gt;
## Double click the new script to edit.&lt;br /&gt;
## Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
## Click save&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
## Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;.&lt;br /&gt;
## Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
## Click the link in the text chat window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
# &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151459</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151459"/>
		<updated>2011-08-16T19:31:21Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Configure the HTTP proxy */ Removed a restriction on the which ports squid will allow a client to establish a ssl connection with.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
# Accept either username auth or no auth. If using username auth, use the same username and password that are used to sign on to this machine.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it. We need to open up some ports, enable SSL communication via the CONNECT method, and disable caching.&lt;br /&gt;
* A patch that will give us the access we need:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-08-16 15:22:55.420862811 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -661,7 +661,8 @@&lt;br /&gt;
 # Deny requests to unknown ports&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 # Deny CONNECT to other than SSL ports&lt;br /&gt;
-http_access deny CONNECT !SSL_ports&lt;br /&gt;
+## Removed to allow connection to caps router on simhosts.&lt;br /&gt;
+#http_access deny CONNECT !SSL_ports&lt;br /&gt;
 #&lt;br /&gt;
 # We strongly recommend the following be uncommented to protect innocent&lt;br /&gt;
 # web applications running on the proxy server who think the only&lt;br /&gt;
@@ -675,6 +676,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1114,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
@@ -3939,7 +3943,7 @@&lt;br /&gt;
 #      &amp;quot;0&amp;quot;.  May be overridden with -u on the command line.&lt;br /&gt;
 #&lt;br /&gt;
 #Default:&lt;br /&gt;
-# icp_port 3130&lt;br /&gt;
+icp_port 0&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: htcp_port&lt;br /&gt;
 #      The port number where Squid sends and receives HTCP queries to&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* To apply the patch, save it to a file named squid.diff in your home directory and run the following command:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo patch /etc/squid/squid.conf ~/squid.diff&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* If you would rather edit by hand, a sequence of instructions to do the above are listed below.1&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Comment out the following line:&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
* It should look like this:&lt;br /&gt;
 #http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* Now that the configuration file is correct, we need to restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors related to squid.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151240</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151240"/>
		<updated>2011-08-12T17:24:42Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the GPU table and feature table are able to be fetched by the proxy.&lt;br /&gt;
## Browse to the install directory of the viewer. &lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
# &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
## Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
## Close the World Map.&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## Fly or walk across a region boundary.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to others avatars standing nearby.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to a group chat channel.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## Try sending private IM messages to another avatar.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
# &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
# Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
# &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
## Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Travel to a region with mesh assets available.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
## Clear the viewer cache.&lt;br /&gt;
## Log back into Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
# Move to a region where you have permission to build.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
## When the upload is complete, apply that texture to an object.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
## When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
## In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
## Add some text in the body of the notecard and click save.&lt;br /&gt;
## Close the notecard&lt;br /&gt;
## Reopen the notecard from your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Move to a mesh-enabled region.&lt;br /&gt;
## Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
## In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
## Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
## After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
## Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## Create a simple object using the build tools.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## Right click the object you created in the previous test and select edit.&lt;br /&gt;
## Select the content tab of the build floater.&lt;br /&gt;
## Click the New Script button.&lt;br /&gt;
## Double click the new script to edit.&lt;br /&gt;
## Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
## Click save&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser should be able to browse while accessing the internet through a proxy.&lt;br /&gt;
## Enable the built-in browser. (Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Use built-in browser&amp;quot;, under &amp;quot;Web:&amp;quot;.&lt;br /&gt;
## Enter a full url, like http://secondlife.com into text chat and send.&lt;br /&gt;
## Click the link in the text chat window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the built-in browser is able to access web content.&lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that overall viewer performance is approximately the same as usual for the machine you are testing on.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
# &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151102</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151102"/>
		<updated>2011-08-10T22:43:33Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added asset tests.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group for testing.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and collada model available to test upload functionality. A sample collada model is available from the [collada.org website | https://collada.org/owl/download.php?sess=0&amp;amp;parent=126&amp;amp;expand=1&amp;amp;order=name&amp;amp;curview=0&amp;amp;binary=1&amp;amp;id=698/ ].&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the GPU table and feature table are able to be fetched by the proxy.&lt;br /&gt;
## Browse to the install directory of the viewer. &lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can move around the world.&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your avatar can sit on objects.&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can fly around the region.&lt;br /&gt;
# &#039;&#039;&#039;World Map&#039;&#039;&#039;&lt;br /&gt;
## Open the World Map Floater (World-&amp;gt;World Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles load and display the layout of the surrounding regions.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that green dots representing avatars are displayed.&lt;br /&gt;
## Close the World Map.&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## Open the Mini-Map Floater (World-&amp;gt;Mini-Map).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that map tiles are displayed.&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## Fly or walk across a region boundary.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you successfully arrive in the other region.&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, within the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the place you clicked.&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## Teleport by double clicking in the World Map floater, somewhere other than the current region.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you arrive in the new region.&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to others avatars standing nearby.  &lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other people receive your messages and that you can receive messages from them.&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## Try sending messages to a group chat channel.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can send messages and receive other messages.&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## Try sending private IM messages to another avatar.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the other avatar receives your messages, and that you are able to receive their response.&lt;br /&gt;
# &#039;&#039;&#039;Display Names&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that custom display names are visible for avatars that have them set. &lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
# Before starting this test, clear your viewer cache and relog.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## Locate the Button_click_down asset in your inventory.  Double click the sound to play it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## Locate the Community Standards notecard in the Library of your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard loads and is readable.&lt;br /&gt;
# &#039;&#039;&#039;Gestures&#039;&#039;&#039;&lt;br /&gt;
## Select a gesture from the &amp;quot;Gesture&amp;quot; menu at the bottom of the window.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the gesture plays.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Travel to a region with mesh assets available.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh assets rez and are visible.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Enable the Develop menu if you haven&#039;t already. (Me-&amp;gt;Preferences-&amp;gt;Advanced-&amp;gt;Show Developer Menu)&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures in the Develop menu.&lt;br /&gt;
## Clear the viewer cache.&lt;br /&gt;
## Log back into Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that textures load onto surfaces in your view.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that your inventory loads.&lt;br /&gt;
&lt;br /&gt;
=== Asset Creation Tests ===&lt;br /&gt;
# Move to a region where you have permission to build.&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## Upload a test image using the upload tool (Build-&amp;gt;Upload-&amp;gt;Image).&lt;br /&gt;
## When the upload is complete, apply that texture to an object.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the image uploaded successfully.&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## Upload a test sound using the upload tool (Build-&amp;gt;Upload-&amp;gt;Sound)&lt;br /&gt;
## When the upload is complete, double click the sound in your inventory to play it back.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the sound plays.&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## In the inventory sidebar, click the &amp;quot;plus sign&amp;quot; (+) button at the bottom of the list of assets. &lt;br /&gt;
## In the menu that appears, select &amp;quot;New Notecard&amp;quot;.&lt;br /&gt;
## Add some text in the body of the notecard and click save.&lt;br /&gt;
## Close the notecard&lt;br /&gt;
## Reopen the notecard from your inventory.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the notecard text loads.&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## Move to a mesh-enabled region.&lt;br /&gt;
## Select Build-&amp;gt;Upload-&amp;gt;Model to start the mesh upload process.&lt;br /&gt;
## In the file selection dialog, select the mesh object you prepared while setting up.  The example file is named duck.dae.&lt;br /&gt;
## Select &amp;quot;Calculate weights &amp;amp; fee&amp;quot; at the bottom of the Upload Model dialog.&lt;br /&gt;
## After the upload fee has been calculated, select the &amp;quot;Upload&amp;quot; button.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is added to your inventory.&lt;br /&gt;
## Drag the mesh object out of your inventory onto the ground to rez it.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the mesh object is rezzed.&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## Create a simple object using the build tools.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object is created&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that you can take a copy of the created object into your inventory.&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## Right click the object you created in the previous test and select edit.&lt;br /&gt;
## Select the content tab of the build floater.&lt;br /&gt;
## Click the New Script button.&lt;br /&gt;
## Double click the new script to edit.&lt;br /&gt;
## Edit the string &amp;quot;Hello, Avatar!&amp;quot; to be &amp;quot;Hi, Avatar!&amp;quot;&lt;br /&gt;
## Click save&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the script compiles.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the object has sent the message &amp;quot;Hi, Avatar!&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser can navigate web pages. &lt;br /&gt;
## &lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with &amp;quot;other&amp;quot; traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of connectivity tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is behaviorally very similar to the no authentication test, and should either connect or not connect.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; The SOCKS 5 password should not be stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Pass/Fail Criteria =&lt;br /&gt;
# &#039;&#039;&#039;Passes&#039;&#039;&#039; if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# &#039;&#039;&#039;Fails&#039;&#039;&#039; if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# &#039;&#039;&#039;Known Issues&#039;&#039;&#039;&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall that blocks the ports used for voice communication. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
= Tear Down =&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151100</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151100"/>
		<updated>2011-08-10T21:19:03Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: More fleshing out of the test cases.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
= Scope =&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 3 hours/platform after securing the appropriate test environment.&lt;br /&gt;
&lt;br /&gt;
= Set-up =&lt;br /&gt;
== Environment ==&lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
== Other ==&lt;br /&gt;
* Second Life account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* At least one notecard, sound, and animation in your avatar&#039;s inventory.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group.&lt;br /&gt;
* Part of the test is making sure land parcel media is functional. Find somewhere in world that has botha  &lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
* Enable advanced mode. The proxy options are not available in basic mode.&lt;br /&gt;
* Have a test image file, sound file, and mesh file available to test upload functionality.&lt;br /&gt;
&lt;br /&gt;
= Common Procedures =&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
= Test Steps =&lt;br /&gt;
== Configuration Consistency Checks ==&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through Web Proxy ==&lt;br /&gt;
# Follow the instructions above to enable the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
&lt;br /&gt;
=== Viewer Initialization ===&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; Verify that the GPU table and feature table are able to be fetched by the proxy.&lt;br /&gt;
## Browse to the install directory of the viewer. &lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&lt;br /&gt;
=== Avatar Navigation and Movement ===&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Map&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Avatar Communication ===&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
=== Asset Download Tests ===&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Animation&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=== Asset Upload Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039;&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
# &#039;&#039;&#039;Browsing Test&#039;&#039;&#039; The integrated webkit browser can navigate web pages. &lt;br /&gt;
## &lt;br /&gt;
&lt;br /&gt;
=== Media on a Prim ===&lt;br /&gt;
# &#039;&#039;&#039;Web Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that web media is visible.&lt;br /&gt;
# &#039;&#039;&#039;Video Media&#039;&#039;&#039;&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that video media is visible.&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that sending other HTTP traffic through the SOCKS 5 proxy works correctly.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
# &#039;&#039;&#039;Repeat Connectivity Tests&#039;&#039;&#039; Verify that users that are not using the proxy will not be negatively impacted by the change.&lt;br /&gt;
## Either test on another computer that is not firewalled, or relax the firewall restrictions on the testing network. If using the reference gateway configuration, run the &#039;&#039;nat_forward_all.sh&#039;&#039; script to allow traffic through without going through a proxy.&lt;br /&gt;
## Disable the proxy as described above.&lt;br /&gt;
## Rerun the following list of test cases, which are described in the section above.&lt;br /&gt;
### Viewer Initialization&lt;br /&gt;
### Avatar Navigation and Movement&lt;br /&gt;
### Avatar Communication&lt;br /&gt;
### Asset Download Tests&lt;br /&gt;
### Asset Upload Tests&lt;br /&gt;
### Integrated Web Browser&lt;br /&gt;
### Media On a Prim&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that all tests pass.&lt;br /&gt;
## Re-enable the firewall if you disabled it before further testing.&lt;br /&gt;
&lt;br /&gt;
== SOCKS 5 with Username/Password Authentication ==&lt;br /&gt;
# &#039;&#039;&#039;Successful Login with SOCKS Authentication&#039;&#039;&#039; Test that the viewer can connect when the SOCKS 5 host requires a password.&lt;br /&gt;
## Enable both proxies, with other traffic going through SOCKS 5.  &lt;br /&gt;
## Also in the proxy settings floater, select Username/Password as the SOCKS Authentication method.&lt;br /&gt;
## Enter your SOCKS 5 username and password in the appropriate fields.  If you followed the reference gateway instructions, your linux username and password should work for the socks credentials.&lt;br /&gt;
## Select OK.&lt;br /&gt;
## Try to log in to Second Life.&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that login is successful.&lt;br /&gt;
## Leave authentication enabled for the next test.&lt;br /&gt;
## Optional: The previous set of tests could be run in this mode as well to verify that the Username/Password authentication method works as well. This is a lower priority than the other three modes because this configuration is very similar to the no authentication test, and should either work or not work.&lt;br /&gt;
# &#039;&#039;&#039;SOCKS 5 Password Security&#039;&#039;&#039; Make sure the password isn&#039;t being stored in cleartext.&lt;br /&gt;
## Leave SOCKS 5 authentication enabled in the viewer from the previous test.&lt;br /&gt;
## Close all running instances of the viewer.&lt;br /&gt;
## Navigate to the user&#039;s Second Life settings directory.  &lt;br /&gt;
## Search, using grep or ctrl-f in notepad depending on the platform, for the username and password you used to connect to the SOCKS 5 server in the previous step in the settings.xml that corresponds to the viewer version you are testing with (settings.xml if using a release version, settings_development.xml if using a development build, etc).&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; that the username and password do not appear in the settings files.&lt;br /&gt;
## Start the viewer and disable authentication.&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# Known Issues&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall. If voice is enabled, an error message will appear when the viewer fails to connect to the voice server.&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151099</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1151099"/>
		<updated>2011-08-10T20:10:21Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Set up the SOCKS 5 proxy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
# Accept either username auth or no auth. If using username auth, use the same username and password that are used to sign on to this machine.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151002</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1151002"/>
		<updated>2011-08-09T22:05:57Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Added more test steps skeleton.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* At least one notecard, sound, and animation in your avatar&#039;s inventory.&lt;br /&gt;
* Your avatar should be a member of a group and be allowed to send messages in that group.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Configuration Consistency Checks ===&lt;br /&gt;
# &#039;&#039;&#039;Expected Defaults&#039;&#039;&#039; Check the default configuration.&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
=== Proxy Enabled, other HTTP through Web Proxy ===&lt;br /&gt;
Before starting this section, follow the instructions above to enabled the proxy and send HTTP traffic through the web proxy.&lt;br /&gt;
&lt;br /&gt;
==== Viewer Intialization ====&lt;br /&gt;
# &#039;&#039;&#039;HTTP Tables Loading&#039;&#039;&#039; &lt;br /&gt;
# &#039;&#039;&#039;Login Screen Renders Correctly&lt;br /&gt;
==== Avatar Navigation and Movement ====&lt;br /&gt;
# &#039;&#039;&#039;Walking&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sitting&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Flying&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Map&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Minimap&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Region Crossing&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Intra-region teleport&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Inter-region teleport&#039;&#039;&#039;&lt;br /&gt;
==== Avatar Communication ====&lt;br /&gt;
# &#039;&#039;&#039;Local Chat&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Group Chat&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;IM&#039;&#039;&#039;&lt;br /&gt;
==== Asset Download Tests ====&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sounds&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Notecard&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Animation&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Legacy Fetch Methods&#039;&#039;&#039;&lt;br /&gt;
## Disable HTTP Inventory and HTTP Textures&lt;br /&gt;
&lt;br /&gt;
==== Asset Upload Tests ====&lt;br /&gt;
# &#039;&#039;&#039;Texture&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Sound&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Mesh&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Object Creation&#039;&#039;&#039;&lt;br /&gt;
# &#039;&#039;&#039;Scripting&#039;&#039;&#039;&lt;br /&gt;
=== Integrated Web Browser ===&lt;br /&gt;
&lt;br /&gt;
==== Media Textures ====&lt;br /&gt;
&lt;br /&gt;
== Proxy Enabled, other HTTP through SOCKS 5 Proxy ==&lt;br /&gt;
&lt;br /&gt;
== No Proxy Enabled ==&lt;br /&gt;
&lt;br /&gt;
== SOCKS Authentication Test ==&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# Known Issues&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall.&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150976</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150976"/>
		<updated>2011-08-09T21:42:22Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Other */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* At least one notecard, sound, and animation in your avatar&#039;s inventory.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# Known Issues&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall.&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150974</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150974"/>
		<updated>2011-08-09T21:41:30Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Fleshed out the common procedures section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through web proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use HTTP Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Enable proxy connection with HTTP traffic sent through SOCKS 5 proxy.&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Check &amp;quot;Use HTTP Proxy for Web pages&amp;quot; and enter the address and port number.&lt;br /&gt;
## Check &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot; and enter the address and port number.&lt;br /&gt;
## Under other HTTP traffic proxy, select &amp;quot;Use SOCKS 5 Proxy&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Disable all proxies&#039;&#039;&#039;&lt;br /&gt;
## Change these settings before logging into Second Life.&lt;br /&gt;
## Open the Proxy settings floater. Me-&amp;gt;Preferences-&amp;gt;Setup-&amp;gt;&amp;quot;Adjust Proxy Settings&amp;quot;&lt;br /&gt;
## Uncheck &amp;quot;Use HTTP Proxy for Web pages&amp;quot;.&lt;br /&gt;
## Uncheck &amp;quot;Use SOCKS 5 Proxy for UDP traffic&amp;quot;.&lt;br /&gt;
## Click OK.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## Click the &amp;quot;Clear Cache&amp;quot; button on the advanced tab of the preferences floater.&lt;br /&gt;
## Confirm that you want to clear the cache.&lt;br /&gt;
## Restart the Viewer.&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Configuration ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# Known Issues&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall.&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150945</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150945"/>
		<updated>2011-08-09T19:26:32Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Pass/Fail Criteria */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable SOCKS 5 proxy &#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## Deviation from expected behavior is observed&lt;br /&gt;
## A bug is detected that was not accounted for by this test plan&lt;br /&gt;
## Performance degradation is observed when the proxy is disabled.&lt;br /&gt;
# Known Issues&lt;br /&gt;
## SLVoice does not support proxies, therefore voice is not expected to work when running the viewer behind a strict firewall.&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150944</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150944"/>
		<updated>2011-08-09T19:22:34Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Redirected to the right address&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[User:Log_Linden/Socks5Viewer/TestPlan]]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150943</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan&amp;diff=1150943"/>
		<updated>2011-08-09T19:21:30Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable SOCKS 5 proxy &#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## e.g. No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## e.g. Expected behaviors are broken&lt;br /&gt;
## e.g. A bug is detected that was not accounted for by this test plan&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150940</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150940"/>
		<updated>2011-08-09T19:16:27Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Fixed links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [https://jira.secondlife.com/browse/STORM-1112 STORM-1112 ].&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway [[User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway | are available]].&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable SOCKS 5 proxy &#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## e.g. No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## e.g. Expected behaviors are broken&lt;br /&gt;
## e.g. A bug is detected that was not accounted for by this test plan&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150939</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150939"/>
		<updated>2011-08-09T19:12:36Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Right aligned TOC&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
{| cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;0&amp;quot; style=&amp;quot;clear: {{{clear|right}}}; margin-bottom: .5em; float: right; padding: .5em 0 .8em 1.4em; background: none; width: {{{width|{{{1|auto}}}}}};&amp;quot; {{#if:{{{limit|}}}|class=&amp;quot;toclimit-{{{limit}}}&amp;quot;}}&lt;br /&gt;
| __TOC__&lt;br /&gt;
|}&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [[STORM-1112 | https://jira.secondlife.com/browse/STORM-1112 ]]&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway are available on the wiki.&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable SOCKS 5 proxy &#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## e.g. No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## e.g. Expected behaviors are broken&lt;br /&gt;
## e.g. A bug is detected that was not accounted for by this test plan&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150937</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/&amp;diff=1150937"/>
		<updated>2011-08-09T18:39:26Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Created page, added introductory sections, working on skeleton of test cases.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:Test Scripts]]&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Scope ==&lt;br /&gt;
* This test is to verify that newly added proxy support in the viewer works as expected.&lt;br /&gt;
* The user story that prompted the changes is [[STORM-1112 | https://jira.secondlife.com/browse/STORM-1112 ]]&lt;br /&gt;
* This test will only be meaningful if performed in a network environment that does not have access to second life.&lt;br /&gt;
* The test also requires a working web proxy host and SOCKS 5 proxy host. &lt;br /&gt;
* Estimated running time: 2 hours/platform after securing the appropriate test environment&lt;br /&gt;
&lt;br /&gt;
== Set-up ==&lt;br /&gt;
=== Environment === &lt;br /&gt;
* Viewer: This test requires a build of the viewer that contains the Proxy code. Grab the latest for your platform from the link below:&lt;br /&gt;
{{ViewerInstallers|{{JiraIssue|STORM-1112|Implement SOCKS 5 proxy}}| Allow the Second Life Viewer to connect through a SOCKS 5 proxy. |task=log_viewer-socks5|repo=https://bitbucket.org/log_linden/viewer_socks5}}&lt;br /&gt;
* Server: The test requires testing of mesh upload and download functionality, so access to a region with mesh support is required.  Agni or Aditi are each fine. Region crossing will also be tested, so adjacent regions to test in will also be required.&lt;br /&gt;
* A restrictive, firewalled network to connect the testing machine to is required to obtain valid test results.&lt;br /&gt;
* A working web proxy host and a working SOCKS 5 host are required to complete the test.&lt;br /&gt;
* Instructions to set up a reference Ubuntu Linux server that will act as a firewall and proxy gateway are available on the wiki.&lt;br /&gt;
* While 3rd party testers are welcome to set up a duplicate of our reference gateway server, we are also interested in results you might get in your organization&#039;s specific network setup, rather than using our reference setup. Since you might not be allowed to reconfigure your organization&#039;s firewall or proxy host, feel free to only test in the proxy configuration your organization supports and report on results you observe.&lt;br /&gt;
&lt;br /&gt;
=== Other === &lt;br /&gt;
* Second Life Account that is able to upload mesh assets on the grid being tested.&lt;br /&gt;
* Sandbox, or other area where building is allowed.&lt;br /&gt;
&lt;br /&gt;
== Common Procedures ==&lt;br /&gt;
Refer to this section when asked to do one of the following in a test step.&lt;br /&gt;
# &#039;&#039;&#039;Enable SOCKS 5 proxy &#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Clear Viewer Caches&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Test Steps ==&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
=== Functional Tests ===&lt;br /&gt;
# &#039;&#039;&#039;Test case 1&#039;&#039;&#039; (you can briefly outline the goal of the test case here)&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 2&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
# &#039;&#039;&#039;Test case 3&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;!-- Commented until regressions are reported.&lt;br /&gt;
=== Regression Tests ===&lt;br /&gt;
(Optional) - as new failures are observed, new test cases can be added here to supplement the functional tests in the section above.&lt;br /&gt;
&lt;br /&gt;
# &#039;&#039;&#039;Test for bug VWR-xxxx&#039;&#039;&#039;&lt;br /&gt;
## step 1&lt;br /&gt;
## step 2&lt;br /&gt;
## &#039;&#039;&#039;Verify&#039;&#039;&#039; against expected behavior&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Pass/Fail Criteria ==&lt;br /&gt;
# Passes if&lt;br /&gt;
## e.g. No unexpected behaviors are observed&lt;br /&gt;
# Fails if&lt;br /&gt;
## e.g. Expected behaviors are broken&lt;br /&gt;
## e.g. A bug is detected that was not accounted for by this test plan&lt;br /&gt;
&lt;br /&gt;
== Tear Down ==&lt;br /&gt;
* Disable all proxies in the viewer configuration.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149731</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149731"/>
		<updated>2011-07-28T15:41:14Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* nat_block_all.sh */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149702</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149702"/>
		<updated>2011-07-27T21:58:10Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Set up the SOCKS 5 proxy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/24 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/24&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/24 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149696</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149696"/>
		<updated>2011-07-27T20:10:14Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Configure the HTTP proxy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/16&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines after to make it look like this:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149695</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149695"/>
		<updated>2011-07-27T19:58:22Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Configure the HTTP proxy */  fixed instruction to disable cacheing of fetched items.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/16&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache deny all&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines to make it be:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149690</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1149690"/>
		<updated>2011-07-27T15:48:24Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Set up the SOCKS 5 proxy */  Changed danted.conf to allow udp replies.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
logoutput: /var/log/dante.log&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
                &lt;br /&gt;
client pass     {&lt;br /&gt;
                    from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
                }&lt;br /&gt;
                        &lt;br /&gt;
client block    {&lt;br /&gt;
                    from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
                    log: connect error&lt;br /&gt;
                }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
        # Block connections to loopback interfaces&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
        # Allow udp reply packets from outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 0.0.0.0/0 to: 192.168.1.0/16&lt;br /&gt;
            command: udpreply&lt;br /&gt;
        }                                &lt;br /&gt;
&lt;br /&gt;
        # Allow the internal network to connect to everything outside&lt;br /&gt;
pass    {&lt;br /&gt;
            from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
            protocol: tcp udp&lt;br /&gt;
        }&lt;br /&gt;
    &lt;br /&gt;
        # Block anything else&lt;br /&gt;
block   {&lt;br /&gt;
            from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
            log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines to make it be:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148712</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148712"/>
		<updated>2011-07-14T14:17:51Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Set up the HTTP (Web) proxy */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#logoutput: stderr&lt;br /&gt;
logoutput: syslog&lt;br /&gt;
#the above line will send any logs to /var/log/syslog instead to a terminal&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
#client pass {&lt;br /&gt;
#        from: 136.201.251.21/0 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
#                # 136.201.251.21/0 = specific ip address.&lt;br /&gt;
#                } &lt;br /&gt;
                &lt;br /&gt;
client pass {&lt;br /&gt;
        from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
            }&lt;br /&gt;
                        &lt;br /&gt;
client block {&lt;br /&gt;
        from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
        log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
                                   &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
    &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 127.0.0.0/8 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
                                                   &lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
=== Configure the HTTP proxy ===&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines to make it be:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== Test the HTTP Proxy ===&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser on the test machine, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.&lt;br /&gt;
* Remove any SOCKS proxy configuration in the browser.&lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148711</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148711"/>
		<updated>2011-07-14T14:15:45Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Set up the HTTP (Web) proxy */ Changed the proxy configuration to support http through the CONNECT method&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#logoutput: stderr&lt;br /&gt;
logoutput: syslog&lt;br /&gt;
#the above line will send any logs to /var/log/syslog instead to a terminal&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
#client pass {&lt;br /&gt;
#        from: 136.201.251.21/0 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
#                # 136.201.251.21/0 = specific ip address.&lt;br /&gt;
#                } &lt;br /&gt;
                &lt;br /&gt;
client pass {&lt;br /&gt;
        from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
            }&lt;br /&gt;
                        &lt;br /&gt;
client block {&lt;br /&gt;
        from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
        log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
                                   &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
    &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 127.0.0.0/8 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
                                                   &lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
* Append two lines to make it be:&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 #       Enable SSL via CONNECT&lt;br /&gt;
 acl SSL method CONNECT&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-13 18:44:17.324652415 -0400&lt;br /&gt;
@@ -606,8 +606,6 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
@@ -628,6 +626,8 @@&lt;br /&gt;
 acl Safe_ports port 901                # SWAT&lt;br /&gt;
 acl purge method PURGE&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
+#      Enable SSL via CONNECT&lt;br /&gt;
+acl SSL method CONNECT&lt;br /&gt;
 &lt;br /&gt;
 #  TAG: http_access&lt;br /&gt;
 #      Allowing or Denying access based on defined access lists&lt;br /&gt;
@@ -675,6 +675,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1113,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Try to connect through the http proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the HTTP and HTTPS proxy server with 3128 as the port in both cases.. &lt;br /&gt;
* Attempt to browse to an internet website. Also try browsing to an https:// website such as [https://codereview.secondlife.com https://codereview.secondlife.com]. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148454</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148454"/>
		<updated>2011-07-11T21:54:39Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Hardware */  wording fix&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually test the viewer on.&lt;br /&gt;
&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#logoutput: stderr&lt;br /&gt;
logoutput: syslog&lt;br /&gt;
#the above line will send any logs to /var/log/syslog instead to a terminal&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
#client pass {&lt;br /&gt;
#        from: 136.201.251.21/0 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
#                # 136.201.251.21/0 = specific ip address.&lt;br /&gt;
#                } &lt;br /&gt;
                &lt;br /&gt;
client pass {&lt;br /&gt;
        from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
            }&lt;br /&gt;
                        &lt;br /&gt;
client block {&lt;br /&gt;
        from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
        log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
                                   &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
    &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 127.0.0.0/8 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
                                                   &lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-11 14:37:18.640566228 -0400&lt;br /&gt;
@@ -606,9 +606,7 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
+acl localnet src 192.168.1.0/8 # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
 acl SSL_ports port 563         # snews&lt;br /&gt;
@@ -675,6 +673,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1111,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Try to connect through the http proxy.&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as thettings in a web browser on the test machine that is behind the firewall.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the HTTP proxy server and 3128 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148453</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148453"/>
		<updated>2011-07-11T21:53:33Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Connect network hardware */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually run the viewer on.&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.2.png|border|600px|SOCKS Testing Network Setup]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#logoutput: stderr&lt;br /&gt;
logoutput: syslog&lt;br /&gt;
#the above line will send any logs to /var/log/syslog instead to a terminal&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
#client pass {&lt;br /&gt;
#        from: 136.201.251.21/0 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
#                # 136.201.251.21/0 = specific ip address.&lt;br /&gt;
#                } &lt;br /&gt;
                &lt;br /&gt;
client pass {&lt;br /&gt;
        from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
            }&lt;br /&gt;
                        &lt;br /&gt;
client block {&lt;br /&gt;
        from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
        log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
                                   &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
    &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 127.0.0.0/8 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
                                                   &lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-11 14:37:18.640566228 -0400&lt;br /&gt;
@@ -606,9 +606,7 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
+acl localnet src 192.168.1.0/8 # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
 acl SSL_ports port 563         # snews&lt;br /&gt;
@@ -675,6 +673,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1111,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Try to connect through the http proxy.&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as thettings in a web browser on the test machine that is behind the firewall.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the HTTP proxy server and 3128 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.2.png&amp;diff=1148452</id>
		<title>File:Socks test setup.2.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.2.png&amp;diff=1148452"/>
		<updated>2011-07-11T21:49:10Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148451</id>
		<title>File:Socks test setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148451"/>
		<updated>2011-07-11T21:48:42Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: uploaded a new version of &amp;quot;File:Socks test setup.png&amp;quot;:&amp;amp;#32;test setup without obnoxious border&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Test setup for SOCKS 5 proxy testing of the viewer.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148450</id>
		<title>File:Socks test setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148450"/>
		<updated>2011-07-11T21:46:44Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: uploaded a new version of &amp;quot;File:Socks test setup.png&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Test setup for SOCKS 5 proxy testing of the viewer.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148449</id>
		<title>File:Socks test setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148449"/>
		<updated>2011-07-11T21:45:43Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: uploaded a new version of &amp;quot;File:Socks test setup.png&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Test setup for SOCKS 5 proxy testing of the viewer.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148448</id>
		<title>File:Socks test setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148448"/>
		<updated>2011-07-11T21:45:21Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: uploaded a new version of &amp;quot;File:Socks test setup.png&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Test setup for SOCKS 5 proxy testing of the viewer.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148446</id>
		<title>User:Log Linden/Socks5Viewer/TestPlan/ProxyGateway</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=User:Log_Linden/Socks5Viewer/TestPlan/ProxyGateway&amp;diff=1148446"/>
		<updated>2011-07-11T21:44:05Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: /* Connect network hardware */ Added diagram of network setup&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Introduction =&lt;br /&gt;
These instructions will help you set up a simple Ubuntu gateway machine that will allow you to control access to the outside network for computers that are operating behind the gateway. This setup was created for testing the SOCKS 5 proxy. With some modification, the same setup could be used for testing various other network conditions, including throttling the connection speed down to something closer to residential DSL speeds. The instructions are intended for someone with a reasonable familiarity with Ubuntu Linux and will only discuss the customisations needed to set up the gateway.&lt;br /&gt;
&lt;br /&gt;
= Requirements =&lt;br /&gt;
== Hardware ==&lt;br /&gt;
* A standard off-the-shelf PC with two Ethernet NICs&lt;br /&gt;
* 1 Ethernet switch for the &amp;quot;internal&amp;quot; network&lt;br /&gt;
* Network cables&lt;br /&gt;
* Other computers to actually run the viewer on.&lt;br /&gt;
== Software ==&lt;br /&gt;
* Ubuntu Linux 11.04 (Natty) [http://www.ubuntu.com/download/ubuntu/download install media] (Other flavors of Ubuntu, including Ubuntu server should work with these instructions as well.)&lt;br /&gt;
&lt;br /&gt;
= Instructions =&lt;br /&gt;
== Connect network hardware ==&lt;br /&gt;
* Connect one network card to the outside network.&lt;br /&gt;
* Connect the other network card to the internal ethernet switch.&lt;br /&gt;
* Connect testing computers to the internal network switch.&lt;br /&gt;
[[File:Socks_test_setup.png]]&lt;br /&gt;
&lt;br /&gt;
== Install Ubuntu and Packages ==&lt;br /&gt;
* Install Ubuntu on the gateway machine. Consult the official Ubuntu install [https://help.ubuntu.com/community/GraphicalInstall instructions] for more information.&lt;br /&gt;
* Reboot into the installed system.&lt;br /&gt;
* Update the packages on the system.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo apt-get update &lt;br /&gt;
sudo apt-get upgrade&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Install some additional useful packages that we will need.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo apt-get install dnsmasq dante-server openssh &amp;lt;/bash&amp;gt;&lt;br /&gt;
== Configure Network Interfaces ==&lt;br /&gt;
* IMPORTANT NOTE: For the purpose of this document, eth0 is the device that is connecting to the outside network, and eth1 is connecting to the internal network.  Verify which is which on your setup.&lt;br /&gt;
&amp;lt;bash&amp;gt;ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
Chances are, only one of the ethX devices will have been assigned an IP address by your network, this is the one connected to the external network.  If this is not eth0 you need to either switch the network cables connected to the computer or remember to swap the interface names everywhere in the rest of this document. We are going to be assigning eth1 with a static IP address, which can cause problems if it conflicts with the rest of your network. &lt;br /&gt;
* Edit, with sudo, &#039;/etc/network/interfaces&#039; and replace its contents with the following&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
auto lo eth0 eth1&lt;br /&gt;
&lt;br /&gt;
iface lo inet loopback&lt;br /&gt;
&lt;br /&gt;
# External network&lt;br /&gt;
iface eth0 inet dhcp&lt;br /&gt;
&lt;br /&gt;
# Internal network&lt;br /&gt;
iface eth1 inet static&lt;br /&gt;
        address 192.168.1.1&lt;br /&gt;
        network 192.168.1.0&lt;br /&gt;
        netmask 255.255.255.0&lt;br /&gt;
        broadcast 192.168.1.255&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* This configuration makes eth0 continue to get its configuration through DHCP, and statically configures eth1.  Listing both interfaces on the auto line will mean that they will automatically connect on startup.  &lt;br /&gt;
* Because we are setting up the interfaces in this config file, we should probably prevent networkmanager from trying to do it as well.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo update-rc.d NetworkManager remove&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart the network&lt;br /&gt;
&amp;lt;bash&amp;gt; &lt;br /&gt;
sudo /etc/init.d/networking stop&lt;br /&gt;
sudo /etc/init.d/networking start&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Verify the network configuration by looking for the correct IP addresses for eth0 and eth1.&lt;br /&gt;
&amp;lt;bash&amp;gt; ifconfig&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up DNS and DHCP ==&lt;br /&gt;
* dnsmasq is a lightweight combination DNS/DHCP server.  For the anticipated number of clients for this network, it should be sufficient.&lt;br /&gt;
* Warning: Again, it is important to get the network interfaces correct for this.  Running a rogue DHCP server on the wrong interface could cause major network problems. eth1 should be the &#039;&#039;&#039;internal&#039;&#039;&#039; network card.&lt;br /&gt;
* Replace /etc/dnsmasq.conf with the following:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
interface=eth1&lt;br /&gt;
&lt;br /&gt;
dhcp-range=192.168.1.50,192.168.1.150,12h&lt;br /&gt;
dhcp-authoritative&lt;br /&gt;
dhcp-script=/bin/echo&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Restart dnsmasq&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/dnsmasq restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the Firewall ==&lt;br /&gt;
* Save the following two scripts to ~/scripts&lt;br /&gt;
=== nat_forward_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_irc, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_irc&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$EXTIF&amp;quot; -o &amp;quot;$INTIF&amp;quot; -m conntrack --ctstate ESTABLISHED,RELATED -j ACCEPT &lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -o &amp;quot;$EXTIF&amp;quot; -j ACCEPT&lt;br /&gt;
-A FORWARD -j LOG&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
=== nat_block_all.sh ===&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
echo -e &amp;quot;\n\nLoading simple rc.firewall-iptables version $FWVER..\n&amp;quot;&lt;br /&gt;
DEPMOD=/sbin/depmod&lt;br /&gt;
MODPROBE=/sbin/modprobe&lt;br /&gt;
&lt;br /&gt;
EXTIF=&amp;quot;eth0&amp;quot;&lt;br /&gt;
INTIF=&amp;quot;eth1&amp;quot;&lt;br /&gt;
echo &amp;quot;   External Interface:  $EXTIF&amp;quot;&lt;br /&gt;
echo &amp;quot;   Internal Interface:  $INTIF&amp;quot;&lt;br /&gt;
&lt;br /&gt;
#======================================================================&lt;br /&gt;
#== No editing beyond this line is required for initial MASQ testing == &lt;br /&gt;
echo -en &amp;quot;   loading modules: &amp;quot;&lt;br /&gt;
echo &amp;quot;  - Verifying that all kernel modules are ok&amp;quot;&lt;br /&gt;
$DEPMOD -a&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -en &amp;quot;ip_tables, &amp;quot;&lt;br /&gt;
$MODPROBE ip_tables&lt;br /&gt;
echo -en &amp;quot;nf_conntrack, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack&lt;br /&gt;
echo -en &amp;quot;nf_conntrack_ftp, &amp;quot; &lt;br /&gt;
$MODPROBE nf_conntrack_ftp&lt;br /&gt;
echo -en &amp;quot;iptable_nat, &amp;quot;&lt;br /&gt;
$MODPROBE iptable_nat&lt;br /&gt;
echo -en &amp;quot;nf_nat_ftp, &amp;quot;&lt;br /&gt;
$MODPROBE nf_nat_ftp&lt;br /&gt;
echo &amp;quot;----------------------------------------------------------------------&amp;quot;&lt;br /&gt;
echo -e &amp;quot;   Done loading modules.\n&amp;quot;&lt;br /&gt;
echo &amp;quot;   Enabling forwarding..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_forward&lt;br /&gt;
echo &amp;quot;   Enabling DynamicAddr..&amp;quot;&lt;br /&gt;
echo &amp;quot;1&amp;quot; &amp;gt; /proc/sys/net/ipv4/ip_dynaddr &lt;br /&gt;
echo &amp;quot;   Clearing any existing rules and setting default policy..&amp;quot;&lt;br /&gt;
&lt;br /&gt;
iptables-restore &amp;lt;&amp;lt;-EOF&lt;br /&gt;
*nat&lt;br /&gt;
-A POSTROUTING -o &amp;quot;$EXTIF&amp;quot; -j MASQUERADE&lt;br /&gt;
COMMIT&lt;br /&gt;
*filter&lt;br /&gt;
:INPUT ACCEPT [0:0]&lt;br /&gt;
:FORWARD DROP [0:0]&lt;br /&gt;
:OUTPUT ACCEPT [0:0]&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j LOG&lt;br /&gt;
-A FORWARD -i &amp;quot;$INTIF&amp;quot; -j REJECT&lt;br /&gt;
COMMIT&lt;br /&gt;
EOF&lt;br /&gt;
&lt;br /&gt;
echo -e &amp;quot;\nrc.firewall-iptables v$FWVER done.\n&amp;quot;&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Make both scripts executable&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
chmod a+x ~/scripts/nat_block_all.sh&lt;br /&gt;
chmod a+x ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test the wide-open script. Inspect the output for errors indicating something is wrong.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo ~/scripts/nat_forward_all.sh&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* If the previous command was successful and you got dns and dhcp configured before, you should be able to connect through your gateway on computers on the internal network.&lt;br /&gt;
* Test this now, by connecting a test computer to the network if you haven&#039;t already.  Try browsing the web on one of the test machines as a quick test. Use &#039;&#039;&#039;ipconfig /all&#039;&#039;&#039; or &#039;&#039;&#039;ifconfig&#039;&#039;&#039; to see how the test computer is being configured.  Expected values are below: &amp;lt;/br&amp;gt;&lt;br /&gt;
{| class=&amp;quot;lltable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|+ &#039;&#039;&#039;Test Machine Network Parameters&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
!Parameter&lt;br /&gt;
!Expected Value&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| IP Address &lt;br /&gt;
| 192.168.1.50-192.168.1.150&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Subnet Mask &lt;br /&gt;
| 255.255.255.0 &lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Default Gateway &lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|--&lt;br /&gt;
| Nameserver (DNS Server)&lt;br /&gt;
| 192.168.1.1&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
* If everything seems to be working correctly, make the wide-open config run during system startup.&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo cp nat_forward_all.sh /etc/init.d/nat.sh&lt;br /&gt;
sudo ln -s /etc/init.d/nat.sh /etc/rc2.d/S95masquradescript&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Set up the SOCKS 5 proxy==&lt;br /&gt;
* Replace /etc/danted.conf with the following.&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#logoutput: stderr&lt;br /&gt;
logoutput: syslog&lt;br /&gt;
#the above line will send any logs to /var/log/syslog instead to a terminal&lt;br /&gt;
&lt;br /&gt;
internal: eth1 port = 1080&lt;br /&gt;
&lt;br /&gt;
external: eth0&lt;br /&gt;
&lt;br /&gt;
method: username none&lt;br /&gt;
#the above puts no username or password. Access will instead be controlled via client ip address/range.&lt;br /&gt;
#if there is no username or password - then danted socks server needs to run as nobody, i.e.&lt;br /&gt;
&lt;br /&gt;
#user.privileged: proxy&lt;br /&gt;
user.notprivileged: nobody&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
### &amp;quot;client-rules&amp;quot; ###&lt;br /&gt;
#client pass {&lt;br /&gt;
#        from: 136.201.251.21/0 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
#                # 136.201.251.21/0 = specific ip address.&lt;br /&gt;
#                } &lt;br /&gt;
                &lt;br /&gt;
client pass {&lt;br /&gt;
        from: 192.168.1.0/16 port 1-65535 to: 0.0.0.0/0&lt;br /&gt;
            }&lt;br /&gt;
                        &lt;br /&gt;
client block {&lt;br /&gt;
        from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
        log: connect error&lt;br /&gt;
        }&lt;br /&gt;
&lt;br /&gt;
         &lt;br /&gt;
### &amp;quot;socks-rules&amp;quot; ###&lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 127.0.0.0/8&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
                                   &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 192.168.1.0/16 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
    &lt;br /&gt;
       pass {&lt;br /&gt;
       from: 127.0.0.0/8 to: 0.0.0.0/0&lt;br /&gt;
       protocol: tcp udp&lt;br /&gt;
       }&lt;br /&gt;
                                                   &lt;br /&gt;
       block {&lt;br /&gt;
       from: 0.0.0.0/0 to: 0.0.0.0/0&lt;br /&gt;
       log: connect error&lt;br /&gt;
       }&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
* Start the proxy server&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo /etc/init.d/danted restart &amp;lt;/bash&amp;gt;&lt;br /&gt;
* If you get a &amp;quot;Failed to open libc.so...&amp;quot; error message when starting the proxy server, this is caused by a [https://bugs.launchpad.net/ubuntu/+source/dante/+bug/767085 mistake] in the dante-server debian package.  To work around this, create a simlink to the correct libc.so and try to start danted again.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ln -sf /lib/i386-linux-gnu/libc-2.13.so /lib/i386-linux-gnu/libc.so &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Test connecting through the proxy by configuring the web browser on one of the test machines connected through the gateway to use the proxy.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the SOCKS server and 1080 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Set up the HTTP (Web) proxy ==&lt;br /&gt;
* Edit /etc/squid/squid.conf.  We will be editing the existing file instead of replacing it.&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_port 3128&lt;br /&gt;
* Replace with the following:&lt;br /&gt;
 http_port 192.168.1.1:3128&lt;br /&gt;
 cache&lt;br /&gt;
* Look for the following lines:&lt;br /&gt;
 acl localnet src 10.0.0.0/8     # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 172.16.0.0/12  # RFC1918 possible internal network&lt;br /&gt;
 acl localnet src 192.168.0.0/16 # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Replace with&lt;br /&gt;
 acl localnet src 192.168.1.0/8  # RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
* Look for the following line:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
* Append another line after it so that it now looks like this:&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access allow localnet&lt;br /&gt;
&lt;br /&gt;
* A patch to do the above:&lt;br /&gt;
&amp;lt;diff&amp;gt;&lt;br /&gt;
--- squid.conf.original 2011-07-11 13:58:12.640564821 -0400&lt;br /&gt;
+++ squid.conf  2011-07-11 14:37:18.640566228 -0400&lt;br /&gt;
@@ -606,9 +606,7 @@&lt;br /&gt;
 # Example rule allowing access from your local networks.&lt;br /&gt;
 # Adapt to list your (internal) IP networks from where browsing&lt;br /&gt;
 # should be allowed&lt;br /&gt;
-acl localnet src 10.0.0.0/8    # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 172.16.0.0/12 # RFC1918 possible internal network&lt;br /&gt;
-acl localnet src 192.168.0.0/16        # RFC1918 possible internal network&lt;br /&gt;
+acl localnet src 192.168.1.0/8 # RFC1918 possible internal network&lt;br /&gt;
 #&lt;br /&gt;
 acl SSL_ports port 443         # https&lt;br /&gt;
 acl SSL_ports port 563         # snews&lt;br /&gt;
@@ -675,6 +673,8 @@&lt;br /&gt;
 # from where browsing should be allowed&lt;br /&gt;
 #http_access allow localnet&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
+http_access allow localnet&lt;br /&gt;
+&lt;br /&gt;
 &lt;br /&gt;
 # And finally deny all other access to this proxy&lt;br /&gt;
 http_access deny all&lt;br /&gt;
@@ -1111,8 +1111,9 @@&lt;br /&gt;
 #      visible on the internal address.&lt;br /&gt;
 #&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
-http_port 3128&lt;br /&gt;
+http_port 192.168.1.1:3128&lt;br /&gt;
 &lt;br /&gt;
+cache deny all&lt;br /&gt;
 #  TAG: https_port&lt;br /&gt;
 # Note: This option is only available if Squid is rebuilt with the&lt;br /&gt;
 #       --enable-ssl option&lt;br /&gt;
&amp;lt;/diff&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Restart the squid proxy:&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo stop squid&lt;br /&gt;
sudo start squid&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Examine syslog for any errors&lt;br /&gt;
&amp;lt;bash&amp;gt;&lt;br /&gt;
sudo tail /var/log/syslog&lt;br /&gt;
&amp;lt;/bash&amp;gt;&lt;br /&gt;
* Try to connect through the http proxy.&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as thettings in a web browser on the test machine that is behind the firewall.&lt;br /&gt;
* Restrict outgoing traffic through the gateway by enabling the more restrictive iptables configuration.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo ~/scripts/nat_block_all.sh &amp;lt;/bash&amp;gt;&lt;br /&gt;
* In the proxy options section of the browser, supply 192.168.1.1 as the HTTP proxy server and 3128 as the port. &lt;br /&gt;
* Attempt to browse to an internet website. If you can browse as usual, the proxy is working correctly. &lt;br /&gt;
* Disable the proxy in the browser.&lt;br /&gt;
&lt;br /&gt;
== Cleanup ==&lt;br /&gt;
* Reboot the machine, using the graphical menus to reboot or the following command. Verify that everything still works as before.&lt;br /&gt;
&amp;lt;bash&amp;gt; sudo shutdown -r now &amp;lt;/bash&amp;gt;&lt;br /&gt;
* Note that we left the unrestricted firewall configuration as the default.  When the gateway is rebooted, you will need to rerun &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to restrict connections again.  If you would like that to be the default state, copy &#039;&#039;&#039;~/scripts/nat_blocked_all.sh&#039;&#039;&#039; to &#039;&#039;&#039;/etc/init.d/nat.sh&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
= Useful References =&lt;br /&gt;
If you run into difficulties with these instructions, there is more information in the official documentation. I based the configurations in this document mostly from the following sites:&lt;br /&gt;
*[https://help.ubuntu.com/community/Router Ubuntu Router Instructions]&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
	<entry>
		<id>https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148445</id>
		<title>File:Socks test setup.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.secondlife.com/w/index.php?title=File:Socks_test_setup.png&amp;diff=1148445"/>
		<updated>2011-07-11T21:42:54Z</updated>

		<summary type="html">&lt;p&gt;Log Linden: Test setup for SOCKS 5 proxy testing of the viewer.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Test setup for SOCKS 5 proxy testing of the viewer.&lt;/div&gt;</summary>
		<author><name>Log Linden</name></author>
	</entry>
</feed>