[squid-users] Skype for Business behind a transparent squid (TProxy) HTTP/S

Amos Jeffries squid3 at treenet.co.nz
Tue Dec 6 01:33:13 UTC 2016

On 6/12/2016 1:11 p.m., Sameh Onaissi wrote:
> Hey,
> Let me see if I understood that right.
> I can change TPROXY to REDIRECT in my iptables.sh and in the ssl-bump 
> replace proxy with intercept.

You _can_ but dont have to. It is just an optimization made possible by 
what that machine is doing to TCP traffic.

> Then, I can run your bash script after creating domains-to-bypass.txt 
> and putting skype domains in there.
> Is that right? or am I missing something?
> P.S: Skype for Business uses Lync servers, I do not think skype.com 
> <http://skype.com> is its domain at all.

That is likely to be part of the problem. The common tutorials and 
how-tos are based on home Skype versions that are easy for random people 
to get hold of and write about.

Good luck.

More information about the squid-users mailing list