[squid-users] Squid Intercept - From inside LAN with DNAT on router and docker on host

Bruno de Paula Larini bruno.larini at riosoft.com.br
Wed Jul 20 20:44:46 UTC 2016


Em 20/07/2016 17:10, Antony Stone escreveu:
>> My router is a Mikrotik router board, so it's trivial to setup a DNAT rule
>> >to redirect all TCP requests to the squid server.
> That won't work.  You*must*  perform the DNAT on the machine running Squid,
> which means that the packets from your clients must pass through the Squid
> server, either because it is in the default route, or because you use some
> form of policy routing (not NAT) to direct port 80 requests through it.

If that's the case I think it would be better if the document instructed 
to use REDIRECT --to-port instead DNAT as an implicit way to explain that.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20160720/42e0e71b/attachment.html>


More information about the squid-users mailing list