Originally Posted by Fuzz
it appears the 'accept dest port 80' was only for input from another another proxy server. I should really pay more attention to what I'm reading!
I wondered as I was typing my previous post whether this might be one of those situations. We all have those slap-yourself-in-the-forehead kind of moments.
Can you post your new output rules?
I would think that if it works with the output chain passing everything, then there should be a way to make it work while locking down the output chain (as oppossed to changing a configuration in squid; which I understand you are looking at).
I would try opening up the output chain and running tcpdump while logging in to the forum to see if there is any traffic on ports you were not expecting.
Also, can you not temporarily set iptables to log what it denies?