Re: [squid-users] Transparent intercept Squid 3.5.20: where VPNs go to die.

2016-08-29 Thread Alex Rousskov
On 08/29/2016 10:43 AM, Stanford Prescott wrote: > Is there a way to tell Squid that there may be port 443 connections that > don't use TLS/SSL so that a useful message could be generated other than > the "connection failed" message the VPN client gives? Not quite, but we are slowly getting there

[squid-users] Transparent intercept Squid 3.5.20: where VPNs go to die.

2016-08-29 Thread Stanford Prescott
I have successfully gotten Squid 3.5.20 to filter both HTTP and HTTPS in transparent intercept mode. With intercept mode, iptables rules redirect port 80 to squid's http_port 800 and HTTPS port 443 is redirected to Squid's https_port 801. It all seems to work exactly as it should. I have recently