/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Jake Colman <[EMAIL PROTECTED]> wrote:
>
> > if you set up Squid on the firewall, it can act as a transperant
> > proxy server, meaning that it will sit on your firewall and all
> > web traffic (as well as some other traffic depending on your
> > configuration) will be proxied by Squid. This doesn't require any
> > changes to your client machine's browsers (I don't think).
>
> > I don't think you need to bother writing any special IPChains rules
> > to do this.
>
> But it can only be a transparent proxy server if I configure netscape
> to use it as a proxy server (then I guess it's not totally
> transparent, is it?).
I think the notion of a "transparent proxy" is getting blurred in the
terminology here. The strict term for Squid is that it is a "cacheing
web proxy." A browser that's configured to use Squid as a proxy, will
send it a specially-formatted HTTP request, asking it to get an Internet
document on the browser's behalf.
In Linux, a "transparent proxy" is a server that receives connections
that were *not* intended for it in the first place. It can proxy *any*
protocol; it just needs to be written to understand that connections it
receives were meant for another destination, and takes pains to find out
that destination and do the right thing. Such a proxy requires some
application programming, as well as the use of the ipchains -j REDIRECT
target, to instruct the firewall as to which traffic should be
redirected, and where.
Daniell Freed <[EMAIL PROTECTED]> wrote:
>
> Thanks for the heads up. I was for some reason thinking SQUID handled
> the packet redirection without needing IPCHAINs.
I haven't looked into this, but I wouldn't be surprised to learn that
Squid has built-in support for transparent proxying, meaning that you
can forward connections to it using the "ipchains -j REDIRECT", and it
will determine the necessary destination on its own, without the special
HTTP request format required for proxying the usual way.
> But, with this configuration it will run transparently (ie you don't
> need to do anything to your clients browsers to make them work with
> the proxy server.
I imagine the Squid documentation or mailing list would be more
revealing. :)
--
[EMAIL PROTECTED] (Fuzzy Fox) || "Good judgment comes from experience.
sometimes known as David DeSimone || Experience comes from bad judgment."
http://www.dallas.net/~fox/ || -- Life Lessons
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.