Re: Squid/Cisco trans proxy

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Wed, 26 Jan 2000 01:27:33 +0100

hohum@sydney.cc wrote:
>
> Thanks Henrik,
>
> Did you see my later message? I have completed a tcpdump & found out
> that what is happening is that the router is sending an ICMP redirect
> to the client to go to our proxy & the proxy is sending an ICMP
> redirect to the client to go to our router - it gets caught in a loop
> & goes nowhere.

Sounds like your redirection rule on the Linux box is the error. It
should only generate a ICMP redirect if it forwards the packet, and the
packet should only be forwarded if it is not redirected to the local TCP
port.

Hmm.. have you enabled always defragment? It is a requirement when doing
TCP redirection.. (I think this may actually be enforced by the
makefiles or kernel, but I am not sure).

/Henrik
Received on Tue Jan 25 2000 - 17:58:41 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:50:42 MST