RE: [squid-users] Really transparent proxy

From: Henrik Nordstrom <henrik@dont-contact.us>
Date: Thu, 17 May 2007 23:01:08 +0200

tor 2007-05-17 klockan 17:49 -0300 skrev Facundo Vilarnovo:

> we are now discarting last options, like the MUST tcp_outgoing_address
> (wich makes that clients times out while surfing)......but any clues are
> welcome

If you see timeouts then there most likely is a routing issue.

Have you arranged your network so that all port 80 traffic in all
directions (yes ALL) passes via the proxy?

Running TPROXY requires a fairly more complex setup than plain
interception as you also need to worry about return traffic from the
Internet, not just the clients outgoing requests..

For testing TPROXY i recommend first doing it on a box running as
router/gateway between a small LAN and the rest.. then when you have got
that working move into deploying it in a larger network using WCCP2 with
two services (one per direction) or similar...

Regards
Henrik

Received on Thu May 17 2007 - 15:01:19 MDT

This archive was generated by hypermail pre-2.1.9 : Fri Jun 01 2007 - 12:00:05 MDT