I have a dual-homed gateway machine, which acts as my firewall to an
internal network. It performs IP masquerading, defines filters for incoming
and outgoing packets, and is also my primary DNS server. This is also the
machine where I am running Squid.
When I allow everything through my firewall (for testing purposes), i.e.,
ipfwadm -I -p accept
ipfwadm -O -p accept
ipfwadm -F -a m -p accept
ipfwadm -I -f
ipfwadm -O -f
ipfwadm -F -f
then Squid fires up fine without a problem. It is ony when my firewall is
up (upon starting squid) that I get the error message:
"Warning: Cannot run '/usr/bin/dnsserver' process."
If I edit the /etc/squid/squid.conf file and specify 'dns_testname -D' (to
disable DNS tests) then the error message changes to
"FATAL: ipcCache-init: DNS name lookup test failed."
It appears that my filter rules are correct as all my internal host are able
to resolve hostnames through the firewall and do the IP masquerade shake
rattle and roll just fine.
I read in the Squid documentation
(http://squid.nlanr.net/Squid/FAQ/FAQ-4.html#ss4.8) that "if you are behind
a firewall then you can't make direct connections to the outside world, so
you must use a parent cache."
Is my Squid considered to be "behind a firewall, being that it is actually
on the gateway itself and thus can access the external network through the
external IP address of the second ethernet card?
Either way, can anyone offer any hints to overcome these error messages.
Thank you.
--Daniel G. Rodriguez
Nippon Timeshare Co., Ltd.
No.2 Takatori Building
2-3-31, Shibaura Minato-Ku
Tokyo 108-0023, Japan
Tel: 03-3769-1001
Fax: 03-3769-1168
[EMAIL PROTECTED]
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]