Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-15 Thread Matus UHLAR - fantomas
On 14.09.19 23:57, sknz wrote: eht1 is not useless really, Coovachilli created tun0 under eth1. Yes, I've heard about stateful firewall, though this is not my domain of expertise. it's very hard to guess what's the problem and how should the solution look like, when someone does this to

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread sknz
So I was testing from a client device(10.1.0.2) which is connected over WiFi to an AP and that AP is connected to eth1 physically. In case you're wondering, eth1 is connected to the server physically. Trying to connect an HTTP website from the above-mentioned client device...

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread sknz
eht1 is not useless really, Coovachilli created tun0 under eth1. Yes, I've heard about stateful firewall, though this is not my domain of expertise. /CoovaChilli takes control of the internal interface (eth1) using a raw promiscuous socket. It then uses the vtun kernel module to bring up a

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread Matus UHLAR - fantomas
On 14.09.19 06:01, sknz wrote: Sorry if I make it more puzzled. Here full packets and config : https://paste.grasehotspot.org/view/raw/384d2a8b Here full iptable rules : https://paste.grasehotspot.org/view/raw/eaf29a16 - do you really use IP to IP tunelling ? Does not look like it. - from

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread sknz
Sorry if I make it more puzzled. Here full packets and config : https://paste.grasehotspot.org/view/raw/384d2a8b Here full iptable rules : https://paste.grasehotspot.org/view/raw/eaf29a16 -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread Amos Jeffries
On 14/09/19 7:43 pm, sknz wrote: > Hello Amos, > Okay, ports are fixed from here and forwarded 80 to 3127 in iptables. > > http_port 3128 # for proxy client > http_port 3127 intercept # for http intercept > This does not match the config suggested. Can you please re-post the config used with

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-14 Thread sknz
Hello Amos, Okay, ports are fixed from here and forwarded 80 to 3127 in iptables. http_port 3128 # for proxy client http_port 3127 intercept # for http intercept When a user tries to connect an HTTP site, tcpdump -vv -ni eth1 port 80 >>> https://paste.grasehotspot.org/view/raw/f81a60e4

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-13 Thread Amos Jeffries
On 14/09/19 4:48 am, sknz wrote: > Hello reinerotto, > I've been stuck here for 3 days! This is complete iptable rules after > coova-chilli starts : https://paste.grasehotspot.org/view/raw/529efd6c > Each time you have posted details about your situation the ports used have been different from

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-13 Thread sknz
Hello reinerotto, I've been stuck here for 3 days! This is complete iptable rules after coova-chilli starts : https://paste.grasehotspot.org/view/raw/529efd6c Please have a look at it. -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-13 Thread reinerotto
Looks like an issue regarding iptables. Because coova-chilli modifies the rules, during start-up. So I doubt, the rules in your post are incomplete, _not_ after start of coova. Definitely, this is not a squid issue. BTW: I have squid intercept running on openwrt devices. For commercial hotspots.

[squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-12 Thread sknz
I'm running an AP-Hotspot server(coovachilli, freeradius, squid, etc.) with two NIC(eth0 and eth1). eth0 is for WAN(internet) and eth1 is for managing LAN(APs). Coovachilli is created tun0 under the eth1 interface. I'm using squid3 as an HTTP transparent proxy. Hardware Setup Diagram

Re: [squid-users] squid transparent proxy forward loop

2018-10-24 Thread Juan Carvajal B.
Thank you so much Matus, we were indeed missing a DNS service: Your proxy is already listening on port 80 and 443 for directly receiving traffic to any domain with a DNS entry of 192.168.0.188. best, *Juan Carlos* *Join our mailing list (Max

Re: [squid-users] squid transparent proxy forward loop

2018-10-22 Thread Amos Jeffries
On 23/10/18 1:26 AM, Juan Carvajal B. wrote: > Dear list, > > I hope you can give me some hints for my current task. > > I would like to achieve the following: > > 1. A user comes with the own device, for example phone or table. > 2. The user connects to our own WLAN network > 4. The user

Re: [squid-users] squid transparent proxy forward loop

2018-10-22 Thread Matus UHLAR - fantomas
On 22.10.18 14:26, Juan Carvajal B. wrote: I would like to achieve the following: 1. A user comes with the own device, for example phone or table. 2. The user connects to our own WLAN network 4. The user enters the addres of our website 3. The user can only access our website, which is hosted

[squid-users] squid transparent proxy forward loop

2018-10-22 Thread Juan Carvajal B.
Dear list, I hope you can give me some hints for my current task. I would like to achieve the following: 1. A user comes with the own device, for example phone or table. 2. The user connects to our own WLAN network 4. The user enters the addres of our website 3. The user can only access our

Re: [squid-users] Squid Transparent Proxy with Policy Routing in pfSense

2018-03-13 Thread Rafael Akchurin
Akchurin Diladele B.V. From: squid-users [mailto:squid-users-boun...@lists.squid-cache.org] On Behalf Of Antonio Emiliano Sent: Tuesday, March 13, 2018 12:14 PM To: squid-users@lists.squid-cache.org Subject: [squid-users] Squid Transparent Proxy with Policy Routing in pfSense Hi guys. This is my

[squid-users] Squid Transparent Proxy with Policy Routing in pfSense

2018-03-13 Thread Antonio Emiliano
Hi guys. This is my last attempt before going to authenticated mode. I searched all over the internet for a way to set up a "transparent squid" but until then the most I can get is an exhausted timeout when I go to an http. My environment is as follows. - Box squid 3.5.20 - pfSense as the

[squid-users] Squid transparent proxy - IP and MAC address spoofed (unchanged)

2015-07-15 Thread Željko Vučetić
Hi all, Is it possible to spoof both IP and MAC addres of the http packets with the squid? With squid 3.3. I managed to spoof IP source address to be the client's one, but mac address is still being changed. (This manual wiki.squid-cache.org/Features/Tproxy4 ) Did someone manage to do

[squid-users] Squid transparent proxy with one nic access denied problem.

2014-02-17 Thread Spyros Vlachos
Hello! Thank you in advance for your help. I have a fairly simple home network setup. I have a modem (192.168.2.254) that connects to the internet. Connected to that modem through its own wan port I have an openwrt router (192.168.1.1). My internal network is the 192.168.1.0/24 one. On the router

[squid-users] Squid transparent proxy woes

2012-12-23 Thread Ali Jawad
Hi I am trying to setup a transparent proxy for my own use which I can use to access geo blocked services, I have tried with 3.1.10 and 3.3.0.1 and I am facing different problems in both cases. Let me first describe the network setup my lan -- GW--- Internet Dedicated Server-- Destination sites

[squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Michał Wiącek
Hello, I have small problem with configuring squid as transparent filtering gateway for http/https in my local Network. I redirected on firewall all http https to my squid host, and http working, https not . I know that problem with ssl is that it have to connect to destination Server not to

Re: [squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Amos Jeffries
On 24/03/2012 12:21 a.m., Michał Wiącek wrote: Hello, I have small problem with configuring squid as transparent filtering gateway for http/https in my local Network. I redirected on firewall all http https to my squid host, and http working, https not . tranparent filtering. Now there is a

RE: [squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Michał Wiącek
You seem to be speaking of a interception gateway filter. SSL was designed to prevent man-in-the-middle attacks (aka interception) from being done. Mayby i sayd wrong - i do not want intercept , but only decise wchich host can connect This is not possible. The URL is inside the encryption. You

Re: [squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Amos Jeffries
On 24/03/2012 1:44 a.m., Michał Wiącek wrote: You seem to be speaking of a interception gateway filter. SSL was designed to prevent man-in-the-middle attacks (aka interception) from being done. Mayby i sayd wrong - i do not want intercept , but only decise wchich host can connect This is

RE: [squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Michał Wiącek
If I am understanding you right, what you actually want is a whitelist or blacklist of destinations in the firewall. This would work better than what Squid can offer with HTTPS. Yes , whitelist would be best for me In both cases you have the same problems of figuring out and listing what

Re: [squid-users] Squid transparent proxy issues with redirecting from HTTP to HTTPs

2012-03-23 Thread guest01
ok, in my setup I am using the same IP with different Ports: http_port 10.122.125.2:3129 intercept name=transparentHTTPPort https_port 10.122.125.2:3130 intercept cert=/etc/squid/squid.pem name=transparentHTTPsPort acl redirectbehavior myportname transparentHTTPPort And how would I apply

Re: [squid-users] squid transparent proxy - https ssl filtering url

2012-03-23 Thread Amos Jeffries
On 24/03/2012 2:22 a.m., Michał Wiącek wrote: If I am understanding you right, what you actually want is a whitelist or blacklist of destinations in the firewall. This would work better than what Squid can offer with HTTPS. Yes , whitelist would be best for me In both cases you have the

Re: [squid-users] Squid transparent proxy issues with redirecting from HTTP to HTTPs

2012-03-23 Thread Amos Jeffries
On 24/03/2012 2:27 a.m., guest01 wrote: ok, in my setup I am using the same IP with different Ports: http_port 10.122.125.2:3129 intercept name=transparentHTTPPort https_port 10.122.125.2:3130 intercept cert=/etc/squid/squid.pem name=transparentHTTPsPort acl redirectbehavior myportname

[squid-users] Squid transparent proxy issues with redirecting from HTTP to HTTPs

2012-03-16 Thread guest01
Hi guys, We are currently using our Squid (3.1.x) as transparent HTTP proxy (with dst nat). We also want to use our Squid as transparent HTTPs proxy, which works too, despite our Internet research in which we got many results for transparent https proxying is not possible. I admit that there are

Re: [squid-users] Squid transparent proxy issues with redirecting from HTTP to HTTPs

2012-03-16 Thread Amos Jeffries
On 17/03/2012 2:27 a.m., guest01 wrote: Hi guys, We are currently using our Squid (3.1.x) as transparent HTTP proxy (with dst nat). We also want to use our Squid as transparent HTTPs proxy, which works too, despite our Internet research in which we got many results for transparent https

Re: [squid-users] Squid transparent proxy issues with redirecting from HTTP to HTTPs

2012-03-16 Thread guest01
Hi, Thanks for the fast response. On Fri, Mar 16, 2012 at 3:08 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 17/03/2012 2:27 a.m., guest01 wrote: Can anybody offer a solution or how do you allow HTTPs in your guest (W)LANs? Direct connection or using proxy-scripts (WPAD,...)? Add a

[squid-users] squid transparent proxy + parent proxy

2011-05-27 Thread Phillip Evans
Hi, I've tried searching the mailing list and google but I can't seem to find a solution. I'm trying to set-up a squid proxy server (squid V3.1)  in our organisation for external users. I've configured a Linux box (fedora 14) with 2 NIC, the first (eth0 IP address 172.20.104.148 - gateway

Re: [squid-users] squid transparent proxy + parent proxy

2011-05-27 Thread Amos Jeffries
On 28/05/11 02:54, Phillip Evans wrote: Hi, I've tried searching the mailing list and google but I can't seem to find a solution. I'm trying to set-up a squid proxy server (squid V3.1) in our organisation for external users. I've configured a Linux box (fedora 14) with 2 NIC, the first (eth0

Re: [squid-users] squid transparent proxy + parent proxy

2011-05-27 Thread Amos Jeffries
On 28/05/11 04:16, Phillip Evans wrote: You just said this was for for external users.. Did you mean internal/LAN users? The requirements and limits are very different. My apologies, these are internal lan users but external to the organisations users i.e. visitors. We want to allow them to

[squid-users] squid transparent proxy server: can't access local web server

2010-04-23 Thread Donatas
Hello everyone, i have a transparent squid proxy server. Here i will try to display the scheme of networking Internet - Router - Transparent Proxy (linux) - Clients, Web server When i try to access web server, no matter from network or internet - i can't access it and i'm getting error The

[squid-users] squid transparent proxy setup

2010-01-03 Thread scatter
Hi everyone, I'm currently attempt to setup a transparent proxy between my linksys router and my wifi access point. The hardware setup like the following Linksys Router -- Ubuntu PC (2 Network Card) -- switch -- Access Point -- Laptop On the Ubuntu PC, eth0 is connected to the router, eth1 is

Re: [squid-users] squid transparent proxy

2008-05-01 Thread Amos Jeffries
PROTECTED] Cc: [EMAIL PROTECTED], squid-users@squid-cache.org Sent: Friday, April 25, 2008 9:04:59 AM (GMT+0300) Asia/Kuwait Subject: Re: [squid-users] squid transparent proxy Wennie V. Lagmay wrote: Hi all, I am reading the procedure for transparent proxy but I am hesitant to implement

Re: [squid-users] squid transparent proxy

2008-04-25 Thread Amos Jeffries
- From: Wennie V. Lagmay [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, April 3, 2008 2:36:42 PM (GMT+0300) Asia/Kuwait Subject: Fwd: [squid-users] squid transparent proxy - Forwarded Message - From: Indunil Jayasooriya [EMAIL PROTECTED] To: Wennie V. Lagmay [EMAIL PROTECTED

Re: [squid-users] squid transparent proxy

2008-04-25 Thread Wennie V. Lagmay
PROTECTED] Cc: [EMAIL PROTECTED], squid-users@squid-cache.org Sent: Friday, April 25, 2008 9:04:59 AM (GMT+0300) Asia/Kuwait Subject: Re: [squid-users] squid transparent proxy Wennie V. Lagmay wrote: Hi all, I am reading the procedure for transparent proxy but I am hesitant to implement it because

Re: [squid-users] squid transparent proxy

2008-04-24 Thread Wennie V. Lagmay
: Wennie V. Lagmay [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, April 3, 2008 2:36:42 PM (GMT+0300) Asia/Kuwait Subject: Fwd: [squid-users] squid transparent proxy - Forwarded Message - From: Indunil Jayasooriya [EMAIL PROTECTED] To: Wennie V. Lagmay [EMAIL PROTECTED] Cc: squid-users

[squid-users] squid transparent proxy

2008-04-03 Thread Wennie V. Lagmay
Dear all, I am trying to activate transparent proxy on my setup but I cannot run it. with the standard setup (configuring the client PC with browser configuration) everything is working good, squid is responding and the client can browse the internet. Now we are trying to implement a setup

Re: [squid-users] squid transparent proxy

2008-04-03 Thread Wennie V. Lagmay
PROTECTED] Sent: Thursday, April 3, 2008 10:48:31 AM (GMT+0300) Asia/Kuwait Subject: Re: [squid-users] squid transparent proxy There are whole a lot of firewall settings. I think your are running squid on port 8080 ( NOT 3128 ). Since you have below rule iptables -A INPUT DROP you will have

Re: [squid-users] squid transparent proxy

2008-04-03 Thread Amos Jeffries
Subject: Re: [squid-users] squid transparent proxy There are whole a lot of firewall settings. I think your are running squid on port 8080 ( NOT 3128 ). Since you have below rule iptables -A INPUT DROP you will have to accept port 8080 as below. #Redirecting traffic destined to port 80 to port 8080

Re: [squid-users] squid transparent proxy

2008-04-03 Thread Indunil Jayasooriya
You are right I am using port 8080. As I mentioned I have 2 machine the 1st machine is my Firewall/NAT server wherein the iptables configuration already stated that it should redirect port 80 to 8080 Oh , Squid is Not running on this box. then, REDIRECT will not work. What Your firewall can

Re: [squid-users] squid transparent proxy

2008-04-03 Thread dhottinger
Quoting Wennie V. Lagmay [EMAIL PROTECTED]: Hi, You are right I am using port 8080. As I mentioned I have 2 machine the 1st machine is my Firewall/NAT server wherein the iptables configuration already stated that it should redirect port 80 to 8080 iptables -t nat -A PREROUTING -s

Re: [squid-users] squid transparent proxy still not working

2008-02-12 Thread Indunil Jayasooriya
So, here are the rules again. iptables -t nat -A PREROUTING -i eth1 -s 192.168.10.0/24 -p tcp --dport 80 -j REDIRECT --to-port 8080 iptables -t filter -A FORWARD -i eth1 -s 192.168.10.0/24 -p tcp --dport 80 -j ACCEPT it's meant 80 or 8080? i was try with 80 8080 but no

Re: Fwd: Re: [squid-users] squid transparent proxy still not working

2008-02-12 Thread Amos Jeffries
Jayasooriya [EMAIL PROTECTED] To: kang ason [EMAIL PROTECTED] CC: squid-users@squid-cache.org Subject: Re: [squid-users] squid transparent proxy still not working and this is my iptables for squid transparent iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.10 -p tcp --dport 80 -j ACCEPT iptables

Re: [squid-users] squid transparent proxy still not working

2008-02-11 Thread Indunil Jayasooriya
and this is my iptables for squid transparent iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.10 -p tcp --dport 80 -j ACCEPT iptables -t nat -A PREROUTING -i eth1 -s 192.168.10/24 -p tcp --dport 80 -j REDIRECT --to-port 8080 what is this ? -s 192.168.10/24 it should be -s

Fwd: Re: [squid-users] squid transparent proxy still not working

2008-02-11 Thread kang ason
Subject: Re: [squid-users] squid transparent proxy still not working and this is my iptables for squid transparent iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.10 -p tcp --dport 80 -j ACCEPT iptables -t nat -A PREROUTING -i eth1 -s 192.168.10/24 -p tcp --dport 80 -j REDIRECT

Re: [squid-users] squid transparent proxy still not working

2008-02-10 Thread Amos Jeffries
Adrian Chadd wrote: Have you followed http://wiki.squid-cache.org/ConfigExamples/ and setup the forwarding, et al, correctly? Just so you know, I can build a proxy from a default debian install by following one of the examples there and transparent proxying just works. Adriank On Sat, Feb

Re: [squid-users] squid transparent proxy still not working

2008-02-10 Thread Indunil Jayasooriya
and this is my iptables for squid transparent iptables -t nat -A PREROUTING -i eth0 -s 192.168.10.10 -p tcp --dport 80 -j ACCEPT iptables -t nat -A PREROUTING -i eth1 -s 192.168.10/24 -p tcp --dport 80 -j REDIRECT --to-port 8080 iptables -t filter -A FORWARD -i eth1 -s 192.168.10/24 -p tcp

[squid-users] squid transparent proxy still not working

2008-02-09 Thread kang ason
Dear All I was succesfully installing squid 2.6 STABLE 18 in debian 4.0 with command and option bellow ./configure --prefix=/usr/local/squid --enable-delay-pools--enable-poll --disable-indent-lookup --enable-truncate --enable-cache-digests --enable-linux-netfilter --enable-async-io=16

Re: [squid-users] squid transparent proxy still not working

2008-02-09 Thread Adrian Chadd
Have you followed http://wiki.squid-cache.org/ConfigExamples/ and setup the forwarding, et al, correctly? Just so you know, I can build a proxy from a default debian install by following one of the examples there and transparent proxying just works. Adriank On Sat, Feb 09, 2008, kang ason

[squid-users] Squid Transparent Proxy not work

2008-01-25 Thread duren duren
i have server running squid (transparent proxy) in Ubuntu linux server (squid installed using apt-get) this server have two interfaces, eth0 to internet eth1 to LAN this is my squid.conf ## --- squid.conf - http_port 192.168.10.1:3128 transparent hierarchy_stoplist cgi-bin ? acl QUERY

Re: [squid-users] Squid Transparent Proxy not work

2008-01-25 Thread Amos Jeffries
duren duren wrote: i have server running squid (transparent proxy) in Ubuntu linux server (squid installed using apt-get) this server have two interfaces, eth0 to internet eth1 to LAN this is my squid.conf ## --- squid.conf - http_port 192.168.10.1:3128 transparent hierarchy_stoplist

Re: [squid-users] Squid Transparent Proxy not work

2008-01-25 Thread duren duren
--- Amos Jeffries [EMAIL PROTECTED] wrote: USER 1 $IPT -A PREROUTING -t nat -i $LAN -s $USER1 -m mac --mac-source $MAC_USER1 -j ACCEPT $IPT -t nat -A PREROUTING -i $LAN -s $USER1 -p tcp --dport 80 -j REDIRECT --to-port 3128 $IPT -A PREROUTING -t nat -i $LAN -s ! $USER1 -m mac

Re: [squid-users] Squid Transparent Proxy with Auth User

2006-07-14 Thread Visolve Squid
RdBSD wrote: Dear All, Is there any futures in squid-3 that will auth user with transparent proxy mode ? Hello, No . It is not possible. With interception proxying, the client thinks it is talking to an origin server and would never send the /Proxy-authorization/ request header. For

[squid-users] Squid Transparent Proxy with Auth User

2006-07-13 Thread RdBSD
Dear All, Is there any futures in squid-3 that will auth user with transparent proxy mode ? Thanks for the information, Rmn

Re: [squid-users] Squid Transparent Proxy with Auth User

2006-07-13 Thread Neil A. Hillard
Hi, RdBSD wrote: Is there any futures in squid-3 that will auth user with transparent proxy mode ? Please don't ask the same question multiple times. The answer you are seeking is in the FAQ at:

RE: [squid-users] Squid Transparent Proxy with Auth User

2006-07-13 Thread Ilker GOKHAN
Sorry no way.. Best regards, Ilker G. -Original Message- From: RdBSD [mailto:[EMAIL PROTECTED] Sent: Thursday, July 13, 2006 9:46 AM To: squid-users@squid-cache.org Subject: [squid-users] Squid Transparent Proxy with Auth User Dear All, Is there any futures in squid-3 that will auth

[squid-users] Squid transparent proxy + VPN problem

2006-02-23 Thread David Clymer
I can't decide if this is a squid problem or an iptables problem, so I'm asking here in case someone can point me in the right direction. - Software/Environment details: - jekyl:/home/david# uname -a Linux jekyl 2.4.27-2-686 #1 Wed Aug 17

Re: [squid-users] Squid transparent proxy + VPN problem

2006-02-23 Thread Mark Elsen
I can't decide if this is a squid problem or an iptables problem, so I'm asking here in case someone can point me in the right direction. - Software/Environment details: - jekyl:/home/david# uname -a Linux jekyl 2.4.27-2-686 #1 Wed

Re: [squid-users] Squid transparent proxy + VPN problem

2006-02-23 Thread Henrik Nordstrom
tor 2006-02-23 klockan 10:54 -0500 skrev David Clymer: I am having problems with networks connected via IPSec VPN. I am using native 2.6 ipsec, so there are no interfaces associated with individual VPN connections as when using KLIPS (the openswan IPSec implementation). The native 2.6 ipsec

Re: [squid-users] squid Transparent proxy with authentication

2005-07-19 Thread Matus UHLAR - fantomas
On 18.07 08:12, Abbas Salehi wrote: Hi guys sorry for duplication mail, this is not duplication. This was the third mail and first two your mails weer answered. Give us some time to answer. And you should read the squid FAQ (http://www.squid-cache.org/Doc/FAQ/FAQ.html) in the meantime. Can

[squid-users] squid Transparent proxy with authentication

2005-07-18 Thread Abbas Salehi
Hi guys Can you advice me how i can configure squid to authenticate without set the proxy server ,actully i want transparent proxy with authentication,the authentication method is not important, How we can have transparent proxy with authentication ( both of them) I'm looking forward to your

Re: [squid-users] squid Transparent proxy with authentication

2005-07-18 Thread Mohammad Halawah
On Monday 18 July 2005 03:09, Abbas Salehi wrote: Hi guys Can you advice me how i can configure squid to authenticate without set the proxy server ,actully i want transparent proxy with authentication,the authentication method is not important, How we can have transparent proxy with

[squid-users] squid Transparent proxy with authentication

2005-07-18 Thread Abbas Salehi
Hi guys sorry for duplication mail, Can you advice me how i can configure squid to authenticate without set the proxy server ,actully i want transparent proxy with authentication,the authentication method is not important, How we can have transparent proxy with authentication ( both of them)

Re: [squid-users] squid Transparent proxy with authentication

2005-07-18 Thread Odhiambo Washington
* On 18/07/05 08:12 +0430, Abbas Salehi wrote: Hi guys sorry for duplication mail, Can you advice me how i can configure squid to authenticate without set the proxy server ,actully i want transparent proxy with authentication,the authentication method is not important, How we can have

[squid-users] Antwort: Re: [squid-users] squid transparent proxy loop problem

2004-09-21 Thread Thomas . Elsaesser
: | |Thema: Re: [squid-users] squid transparent proxy loop problem

[squid-users] squid transparent proxy loop problem

2004-09-20 Thread Thomas . Elsaesser
Transparent proxy 172.17.248.48 - - [20/Sep/2004:14:51:32 +0200] GET http://www.google.de:8080/ HTTP/1.1 504 2415 TCP_MISS:NONE I have this log entry in my transp. proxy . I believe it's a loop. How can i change this??? Have any a solution for me? thank you Thomas

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-25 Thread Henrik Nordstrom
On Wed, 24 Mar 2004, Matthew Tanase wrote: OK - I have gotten it working, but not sure if it is optimal. Linux, 3 network interfaces. eth0 and eth1 acting as the bridge, assigned an IP. eth2 - not connected. Couldn't get anything to work wtih squid, although the bridge worked. So I enable

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-25 Thread Henrik Nordstrom
On Thu, 25 Mar 2004, usman fool wrote: a machine with 2 ethernet cards (eth0,eth1) operating as bridge whereas its 1 ethernet interface(eth1) has ip address and squid is running on it, now that machine is connected to internet through ppp0 (as pp0 is not part of bridge) . ipforwarding is

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-25 Thread Matthew Tanase
I assigned the bridge an IP of 192.168.X.X, but Squid would not work. So I assigned the 3rd interface this IP and removed it from the bridge, now it works. I guess I didn't set up routing, but the third interface is just using DHCP - what is missing - the gateway? DNS already in resolv.conf...

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-25 Thread Henrik Nordstrom
On Thu, 25 Mar 2004, Matthew Tanase wrote: I assigned the bridge an IP of 192.168.X.X, but Squid would not work. So I assigned the 3rd interface this IP and removed it from the bridge, now it works. I guess I didn't set up routing, but the third interface is just using DHCP - what is missing

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-25 Thread Henrik Nordstrom
On Thu, 25 Mar 2004, Matthew Tanase wrote: I assigned the bridge an IP of 192.168.X.X, but Squid would not work. So I assigned the 3rd interface this IP and removed it from the bridge, now it works. I guess I didn't set up routing, but the third interface is just using DHCP - what is missing

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread usman fool
] To: [EMAIL PROTECTED] Subject: [squid-users] Squid transparent proxy and bridge question Date: Tue, 23 Mar 2004 12:47:54 -0800 (PST) Hello I have setup Mandrake Linux 10.0 as a bridge. I have confirmed the interfaces (eth0 and eth1) are acting as a bridge. I have installed Squid on this device and would

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread Matthew Tanase
] Reply-To: Matthew Tanase [EMAIL PROTECTED] To: [EMAIL PROTECTED] Subject: [squid-users] Squid transparent proxy and bridge question Date: Tue, 23 Mar 2004 12:47:54 -0800 (PST) Hello I have setup Mandrake Linux 10.0 as a bridge. I have confirmed the interfaces (eth0 and eth1

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread usman fool
From: Matthew Tanase [EMAIL PROTECTED] Reply-To: Matthew Tanase [EMAIL PROTECTED] To: usman fool [EMAIL PROTECTED] CC: [EMAIL PROTECTED] Subject: Re: [squid-users] Squid transparent proxy and bridge question Date: Wed, 24 Mar 2004 11:43:17 -0800 (PST) A couple of things since my initial post. I

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread Henrik Nordstrom
On Wed, 24 Mar 2004, usman fool wrote: keep 3 things in mind 1.the clients gateway must be that ip on which squid is listening on.( your bridge ip) Not in case of a bridge (won't be a bridge then)... but the bridge needs to be inbetween the clients and their gateway.. 2.the clients must

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread Henrik Nordstrom
On Wed, 24 Mar 2004, Matthew Tanase wrote: A couple of things since my initial post. I verified the machine do indeed have DNS access (I can ping hosts), so that shouldn't be a problem. I had to use iptables -t nat -A PREROUTING -p tcp --dport 80 -j DNAT squidbox:3128 to get Squid working,

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread usman fool
keep 3 things in mind 1.the clients gateway must be that ip on which squid is listening on.( your bridge ip) Not in case of a bridge (won't be a bridge then)... but the bridge needs to be inbetween the clients and their gateway.. i was saying this because it was looking like he is running

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread Henrik Nordstrom
On Wed, 24 Mar 2004, usman fool wrote: i was saying this because it was looking like he is running squid on that bridge. bsd bridges can have ip addresses dont know if its possible in linux or not. Linux bridges can have IP addresses, and in fact is a must if you want to run a proxy there

RE: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread usman fool
From: Henrik Nordstrom [EMAIL PROTECTED] To: usman fool [EMAIL PROTECTED] CC: [EMAIL PROTECTED] Subject: RE: [squid-users] Squid transparent proxy and bridge question Date: Thu, 25 Mar 2004 00:34:39 +0100 (CET) On Wed, 24 Mar 2004, usman fool wrote: i was saying this because it was looking like

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-24 Thread Matthew Tanase
OK - I have gotten it working, but not sure if it is optimal. Linux, 3 network interfaces. eth0 and eth1 acting as the bridge, assigned an IP. eth2 - not connected. Couldn't get anything to work wtih squid, although the bridge worked. So I enable debugging and can see that Squid cannot talk to

[squid-users] Squid transparent proxy and bridge question

2004-03-23 Thread Matthew Tanase
Hello I have setup Mandrake Linux 10.0 as a bridge. I have confirmed the interfaces (eth0 and eth1) are acting as a bridge. I have installed Squid on this device and would like it to act as a forced, transparent proxy. So I am redirecting requests coming into the bridge to port 3128,

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-23 Thread Henrik Nordstrom
On Tue, 23 Mar 2004, Matthew Tanase wrote: I have setup Mandrake Linux 10.0 as a bridge. I have confirmed the interfaces (eth0 and eth1) are acting as a bridge. I have installed Squid on this device and would like it to act as a forced, transparent proxy. So I am redirecting requests coming

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-23 Thread Matthew Tanase
Not sure - the bridge itself works but how can I see if bridging firewalling is enabled? mt -Original Message from Henrik Nordstrom [EMAIL PROTECTED]- On Tue, 23 Mar 2004, Matthew Tanase wrote: I have setup Mandrake Linux 10.0 as a bridge. I have confirmed the

Re: [squid-users] Squid transparent proxy and bridge question

2004-03-23 Thread Henrik Nordstrom
On Tue, 23 Mar 2004, Matthew Tanase wrote: Not sure - the bridge itself works but how can I see if bridging firewalling is enabled? You can see this in the config file used when your kernel was built.. If unsure build your own kernel with this option enabled. Regards Henrik

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-20 Thread Henrik Nordstrom
On Thu, 19 Feb 2004 [EMAIL PROTECTED] wrote: Thanks again for being patient with me. Hopefully we can get to the bottom of this. Which exact Squid and kernel versions? (including patches). Squid configure flags uses? (Output of squid -v) Regards Henrik

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-20 Thread jwebb
Which exact Squid and kernel versions? (including patches). Squid configure flags uses? (Output of squid -v) Regards Henrik It's squid 2.5.STABLE4. Configure options are just --enable-linux-netfilter. I'm running a vanilla version of Linux 2.4.22 with the bare essentials to make

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread Muthukumar
1077206929.504307 local squid/firewall IP TCP_MISS/200 173 GET remote URL - DIRECT/remote IP text/plain The local squid/firewall is always the same, which makes it impossible for me to track down the client going by squid's access log. Did you enable this header

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread Henrik Nordstrom
On Thu, 19 Feb 2004 [EMAIL PROTECTED] wrote: I have httpd_accel_uses_host_header enabled, but I didn't have emulate_httpd_log enabled. I enabled and restarted that option and it switched me over to httpd style log files. However, I'm still getting the IP of my squid/firewall box as the

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread Henrik Nordstrom
On Thu, 19 Feb 2004 [EMAIL PROTECTED] wrote: I'm also using Dansguardian for content filtering. All traffic is redirected by ipfilter to port 8080 (Dansguardian), which then forwards to 3128 if necessary. Ah, then only Dansguardian has the IP of the user. To Squid the traffic is coming from

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread jwebb
What OS are you using? Is there any difference if you configure the browser to use the proxy? Regards Henrik I'm using RH8.1 with a custom (non RPM) 2.4.22 kernel. And actually, yes. I put the proxy in manually and it's displaying it fine. I never noticed that before. However, with

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread Henrik Nordstrom
On Thu, 19 Feb 2004 [EMAIL PROTECTED] wrote: I'm using RH8.1 with a custom (non RPM) 2.4.22 kernel. And actually, yes. I put the proxy in manually and it's displaying it fine. I never noticed that before. However, with over 5 thousand machines we're pretty much dependent on the proxy

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread Henrik Nordstrom
On Thu, 19 Feb 2004 [EMAIL PROTECTED] wrote: We've got about 200 (private) class C's, so there are many entries that look like this: *nat :PREROUTING ACCEPT [1149084:79155898] :POSTROUTING ACCEPT [2574077:165548111] :OUTPUT ACCEPT [1884442:115362888] -A PREROUTING -s

Re: [squid-users] Squid, transparent proxy, and logs

2004-02-19 Thread jwebb
Ok. Is there any SNAT rules? Regards Henrik Nope, no SNAT rules. Thanks again for being patient with me. Hopefully we can get to the bottom of this.