Gentoo Archives: gentoo-user

From: Stroller <stroller@××××××××××××××××××.uk>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] [SOLVED] squid - allowing only one domain
Date: Fri, 22 Jan 2010 18:06:23
Message-Id: 60462D0E-B630-46E9-ADB1-0F7A92979922@stellar.eclipse.co.uk
In Reply to: Re: [gentoo-user] [SOLVED] squid - allowing only one domain by Joseph
1 On 22 Jan 2010, at 14:41, Joseph wrote:
2
3 > On 01/22/10 10:43, Stroller wrote:
4 >>>
5 >>> I don't understand what kind of explanation you expect, just emerge squid iptable (make sure kernel has the correct entries compiled IN) and type those commends in at the command line; read the post above some other users clearly suggested what to type at the command line :-)
6 >>>
7 >>> It just works! I stated my objectives and I accomplished them.
8 >>
9 >> Maybe I'm being very dumb. I assumed a situation of router A, with Squid running on server B. The office staff are using browsers on client machines X, Y & Z. When a user on machine X browses to a website, his PC sends the packet to router A. The packet never reaches server B in order to be intercepted by B. We can configure B as the proxy in the browser settings of X, Y & Z, but then that no longer needs iptables configuration or interception mode.
10 >>
11 >> I'm not trying to argue with you, BTW. I'm just trying to learn from you.
12 >>
13 >> Stroller.
14 >
15 > I'm not an expert with iptables but since you have multiple machine on your network your best option is to configure single machine to run squid on it and forward the traffic to it. You have to tell us your setup, what kind of equipment you have, it it a small firewall/router from store you build it etc.
16 > How the traffic flow, I might suggest something.
17 > I think in your situation best option would be if router A runs squid if possible; if not router A intercept all packets from X,Y,X and sends them to squid B machine, B process the traffic and send it back to router A (rotter A forward all traffic from squid B to Internet).
18
19 I'm not asking for help with my configuration, because it works just fine as it is.
20
21 You asserted, I think, that Squid works in interception mode on a server with a single NIC.
22
23 Is that server a router?
24
25 Does it filter for the benefit of other computers?
26
27 How do the other computers know to send packets to the server?
28
29 Stroller.

Replies

Subject Author
Re: [gentoo-user] [SOLVED] squid - allowing only one domain Joseph <syscon780@×××××.com>