Re: Squid/Cisco trans proxy

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Wed, 26 Jan 2000 02:01:09 +0100

Marc Lucke wrote:
>
> I am running Rehat Linux 6. Is this known to work with the Cisco/Squid
> trans proxy? Is a recompilation of the kernel with different options
> necessary? (I have read that it shouldn't be & if it were, then why does it
> still work with most clients?)

RedHat Linux 6 should work fine I think. However transparent proxying
isn't the easiest thing to set up properly. It is a big hack way outside
any official TCP/IP protocol standards, and it is not that easy to
diagnose when you have problems or why.

Most people having problems have it due to the dual identity nature of
the redirected destination IP addresses (both the proxy AND the origin
server shares the same IP). This has mainly effects on path MTU
discovery and on routing.

What makes it hard to diagnose is that it isn't always very obvious
where return traffic from that IP has originated (was it sent by the
proxy, or by the origin server? Both share the same IP and TCP port),
and if there is errors in the redirection on the way then only part of
the traffic may be seen.

--
Henrik Nordstrom
Squid hacker
Received on Tue Jan 25 2000 - 18:23:58 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:50:42 MST