[squid-users] Squid Intercept - From inside LAN with DNAT on router and docker on host

Guilherme Scaglia cadastros.scaglia at gmail.com
Thu Jul 21 12:12:34 UTC 2016


Bruno,

> No, no, Amos was just explaining the use of DNAT in this case; REDIRECT
won't work either.
> You should do as intructed by Antony and try policy routing.

That's what I'm planing; Policy routing at Mikrotik, so the packets arrive
at the squid machine. At squid machine, redirect from port 80 to whatever
port squid is on (intercept). That's exactly what the REDIRECT link says to
do. The main difference from DNAT is not enabling ip-forward in the squid
box, which is exactly what I want to avoid.


2016-07-21 9:07 GMT-03:00 Bruno de Paula Larini <bruno.larini at riosoft.com.br
>:

> Em 21/07/2016 08:55, Guilherme Scaglia escreveu:
>
> Amos,
>
> > There is a different config example for REDIRECT <
> http://wiki.squid-cache.org/ConfigExamples/Intercept/LinuxRedirect>
>
> Ty, I'm going to try it using REDIRECT. I was unwilling to follow the DNAT
> guide because of having to enable ip-forwarding in a non-router machine.
> The REDIRECT version seems cleaner and is similar to what I'
>
> No, no, Amos was just explaining the use of DNAT in this case; REDIRECT
> won't work either.
> You should do as intructed by Antony and try policy routing.
>
> _______________________________________________
> squid-users mailing list
> squid-users at lists.squid-cache.org
> http://lists.squid-cache.org/listinfo/squid-users
>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20160721/61b189b6/attachment.html>


More information about the squid-users mailing list