Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Nguyen Hai Nam
Hi Edmonds, That's really like my setup right now. But, as Amos said, the traffic just pass from eth0 to eth1 but don't come to Squid, because it's bridged. Actually, when watching IP nat table, I still found some nat rules show up, but at client-side it still looks direct access. And more

Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Edmonds Namasenda
Your diagram or illustration shows a difference with my illustration. If you believe they are the same and getting header fields shown, look through your firewall and squid acls. # Edz. On Tue, Dec 6, 2011 at 5:05 PM, Nguyen Hai Nam nam...@nd24.net wrote: Hi Edmonds, That's really like my

Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Nguyen Hai Nam
Ah, sorry my mistake, you mean Squid box will be the new default gateway, right? If do so, I have to change default gateway on every computers, it's also like config proxy setting on each PC. Best regards ~ Neddie On Tue, Dec 6, 2011 at 9:19 PM, Edmonds Namasenda namase...@gmail.com wrote: Your

Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Amos Jeffries
On Tue, 6 Dec 2011 21:05:27 +0700, Nguyen Hai Nam wrote: Hi Edmonds, That's really like my setup right now. But, as Amos said, the traffic just pass from eth0 to eth1 but don't come to Squid, because it's bridged. Actually, when watching IP nat table, I still found some nat rules show up, but

Re: [squid-users] Make Squid in interception mode completely

2011-12-05 Thread Amos Jeffries
On 5/12/2011 7:34 p.m., Nguyen Hai Nam wrote: Hi, As last time I had a squid box working in interception mode as well: traffic was redirected from default gateway to squid box, then IP-filter will NAT to intercepting squid. Look like this: INTERNET Router | | SwitchDefault

Re: [squid-users] Make Squid in interception mode completely

2011-12-05 Thread Nguyen Hai Nam
Hi Amos, You're right, switch is not really true. But I still can't find the way on Solaris-like system like /proc/sys/net/bridge On Mon, Dec 5, 2011 at 7:25 PM, Amos Jeffries squ...@treenet.co.nz wrote: Like a switch? or or did you really mean like a bridge? * switch ... no solution.

Re: [squid-users] Make Squid in interception mode completely

2011-12-05 Thread Edmonds Namasenda
Hai, Seems your network set-up is what might be ruining your connection expectations or the default gateway needs a rule (possibly using a firewall) to direct all HTTP traffic to the squid box rather than to the internet. Otherwise, think of the set-up below (with the Squid box the same as the

[squid-users] Make Squid in interception mode completely

2011-12-04 Thread Nguyen Hai Nam
Hi, As last time I had a squid box working in interception mode as well: traffic was redirected from default gateway to squid box, then IP-filter will NAT to intercepting squid. Look like this: INTERNET Router | | SwitchDefault gateway | \ | \ |+ Squid box |