Re: [squid-users] Transparent Squid with Check Point FW-1

From: Simon White <simon@dont-contact.us>
Date: Sun, 31 Mar 2002 12:20:51 +0000

30-Mar-02 at 17:25, Henrik Nordstrom (hno@marasystems.com) wrote :
> Simon White wrote:
>
> > I am using SRV_REDIRECT, and the firewall logs tell me that packets are
> > redirecting to the Squid machine OK... but I can't surf, and I see nothing
> > in access.log.
>
> Should work..
>
> any hints if you run "tcpdump -n" on the Squid box?
>
> Do the Squid box know how to route packets back to the original client
> proper?

Perhaps not. The way I was testing it was on the same subnet as the actual
clients, I think the firewall is redirecting to Squid, then Squid is not
replying via the firewall thus state information is being lost.

I am going to put Squid on a different subnet on a different interface of
the firewall and try again on Monday or Tuesday.

I also seem to be having intermittent problems with AUFS on Linux 2.4.7-10
(stock RH7.2) but I haven't finished testing yet, however any pointers on
how many threads I should have for 128Mb Physical RAM and 1.6Gb of cache
would be appreciated.

-- 
[Simon White. vim/mutt. simon@mtds.com. GIMPS:60.64% see www.mersenne.org]
In a time of universal lies, telling the truth is a revolutionary act.
  -- George Orwell
[Linux user #170823 http://counter.li.org. Home cooked signature rotator.]
Received on Sun Mar 31 2002 - 05:20:53 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:07:13 MST