RE: [squid-users] Where are the DNS entries stored?

From: Elsen Marc <elsen@dont-contact.us>
Date: Wed, 9 Jun 2004 14:58:23 +0200

 
>
> On Wednesday 09 June 2004 10:27, Elsen Marc wrote:
> > > On Wednesday 09 June 2004 08:48, Elsen Marc wrote:
> > > > > Hi everyone,
> > > > >
> > > > > I have recently started using squid (not transparent yet). I
> > > > > have a few questions:
> > > >
> > > > Not transparant = good = keep it that way.
> > >
> > > Why?
> >
> > Because transparant proxying violates TCP/IP networking
> semantics; in the
> > case for instance a browser through http thinks it talks
> directly to
> > a remote webserver over ip. This and the way http
> interacts with the
> > networking layer can lead to subttle issues and problems.
> >
> > Sometimes users start reporting problems with hotmail and
> other sites,
> > often due to , for instance interleaving auth. mechanism(s), which
> > subsequently check the origin of http - https connections.
> >
> > Other issues may 'appear' and apply, such as browser not succeeding
> > to revalidate objects because it thinks, it was talking to
> the remote
> > webserver directly, which it ain't in the case of
> transparant proxying.
>
> You are right.
>
> Although I am not going to remove transparent setup on my router
> because it's not scalable to run around and configure proxy
> on each and every Internet Exploder-infested box. There are
> more than 400 of them here, spread across 30 km^2 area :(
 
  That is true; but there other viewpoints to address this issue :

     - at our company the SQUID proxy must be used , else people
can have no web access.

     - we use a commercial tool to install PC's (over 2000 installed
base) where user get's various
applications either under Linux or Windows. We can package browser(s)
so that the proxy settings are already correct.
So user's don't know anything, about these issue(s), and are happy;except
when they try to be smart and change the browser proxy setting; and then
they loose Web access on our Intranet... Doesn't happen very often,as you might
guess.

M.
Received on Wed Jun 09 2004 - 07:00:32 MDT

This archive was generated by hypermail pre-2.1.9 : Thu Jul 01 2004 - 12:00:02 MDT