[squid-users] How to extract decrypted traffic for further analysis using Snort?

Antony Stone Antony.Stone at squid.open.source.it
Mon Mar 11 19:58:52 UTC 2019


On Monday 11 March 2019 at 20:53:13, Felipe Arturo Polanco wrote:

> Hi,
> 
> I'm trying to find a way to get the HTTP traffic analysed after being
> decrypted, by using Snort.
> 
> Does someone know how to do this? I can redirect IP traffic with regular
> HTTP into Snort but I haven't found a way inside squid to do the same.

How about https://wiki.squid-cache.org/Features/ICAP ?


Antony.

-- 
Please apologise my errors, since I have a very small device.

                                                   Please reply to the list;
                                                         please *don't* CC me.


More information about the squid-users mailing list