[squid-users] Re: SNATing connections of a transparent proxy to their original IPs

From: Henrik Nordstrom <hno@dont-contact.us>
Date: Sun, 12 Feb 2006 02:06:59 +0100 (CET)

On Mon, 30 Jan 2006, Vicentiu Rizan wrote:

> This question has probably been asked before but I can't find anything
> relevant.
> I'm looking for a way to SNAT the connections that a transparent squid cache
> makes back to their original IPs.
>
> client(IP: a.b.c.d)->squid machine(a.b.c.e)->site server(w.x.y.z) (I want
> this server to see a.b.c.d instead of the a.b.c.e IP)
>
> Is there a plugin for squid that can work with netfilter to do this? (kernel
> 2.6)

There is the TPROXY patch (both kernel and Squid).

Or you can use tcp_outgoing_address + server_persistent_connections off +
NAT provided by your OS or network device in the path..

Regards
Henrik
Received on Sat Feb 11 2006 - 18:07:03 MST

This archive was generated by hypermail pre-2.1.9 : Wed Mar 01 2006 - 12:00:03 MST