On Friday 24 January 2003 6:19 pm, Kenn Murrah wrote: > I guess I should have supplied more details ... i AM running a transparent > proxy, but that simply saves me from having to configure everyone's browser > .. they can STILL hit the gateway directly if they know the address ... > isn't that right?
Yep, it's right until you add a firewall rule on the gateway to allow *only* the squid machine to route... Of course, you can then also add firewall rules to allow specific machines (management, etc.) direct Internet access for chat / ICQ / MSN / warez / porn, etc. :) gdh
