/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Jake Colman <[EMAIL PROTECTED]> wrote:
>
> > if you set up Squid on the firewall, it can act as a transperant
> > proxy server, meaning that it will sit on your firewall and all
> > web traffic (as well as some other traffic depending on your
> > configuration) will be proxied by Squid.  This doesn't require any
> > changes to your client machine's browsers (I don't think).
>
> > I don't think you need to bother writing any special IPChains rules
> > to do this.
> 
> But it can only be a transparent proxy server if I configure netscape
> to use it as a proxy server (then I guess it's not totally
> transparent, is it?).

I think the notion of a "transparent proxy" is getting blurred in the
terminology here.  The strict term for Squid is that it is a "cacheing
web proxy."  A browser that's configured to use Squid as a proxy, will
send it a specially-formatted HTTP request, asking it to get an Internet
document on the browser's behalf.

In Linux, a "transparent proxy" is a server that receives connections
that were *not* intended for it in the first place.  It can proxy *any*
protocol; it just needs to be written to understand that connections it
receives were meant for another destination, and takes pains to find out
that destination and do the right thing.  Such a proxy requires some
application programming, as well as the use of the ipchains -j REDIRECT
target, to instruct the firewall as to which traffic should be
redirected, and where.


Daniell Freed <[EMAIL PROTECTED]> wrote:
>
> Thanks for the heads up.  I was for some reason thinking SQUID handled
> the packet redirection without needing IPCHAINs.

I haven't looked into this, but I wouldn't be surprised to learn that
Squid has built-in support for transparent proxying, meaning that you
can forward connections to it using the "ipchains -j REDIRECT", and it
will determine the necessary destination on its own, without the special
HTTP request format required for proxying the usual way.

> But, with this configuration it will run transparently (ie you don't
> need to do anything to your clients browsers to make them work with
> the proxy server.

I imagine the Squid documentation or mailing list would be more
revealing.  :)

-- 
   [EMAIL PROTECTED] (Fuzzy Fox)     || "Good judgment comes from experience.
sometimes known as David DeSimone  ||  Experience comes from bad judgment."
  http://www.dallas.net/~fox/      ||                 -- Life Lessons

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to