[squid-users] dual internet connections traffic routing

From: Adam Parsons <adamp@dont-contact.us>
Date: Wed, 21 Feb 2007 15:18:25 +1030 (CST)

Hi,
This is my second attempt at asking this, as i obviously wasn't too clear last time.. Hopefully i do better this time.

The organisation i work for has many sites, all connecting to our core servers via frame-relay or other links. They need to use our organisations proxy address to go anywhere, which requires authentication for internet access. Now we have some sites that have two network links, the standard frame-relay and an additional ADSL connection. The intention is to have all organisational traffic (i.e. xxx.gov.au and xxx.edu.au) go through the frame-relay link and all other internet traffic (i.e. cisco.com, squid-cache.org, etc) go through the ADSL connection. I have rebuilt one of these sites with two links, and copied their configuration which i dont think is working as intended.

Now i cant use a proxy.pac file, as i need to put a default username and password in for all traffic going out the frame-relay, otherwise they will be prompted and i dont want that as the traffic is free and doesnt need to be metered. On the otherhand traffic out the ADSL link we use authentication on the squidbox (smb) and that works fine.

My question is (finally you say), if i use the cache_peer_domain directive. i.e.

cache_peer proxy.xxx.xx.edu.au parent 8080 0 no-query login=username:password
cache_peer_domain proxy.xxx.xx.edu.au .xx.edu.au .xx.gov.au

Will this only go out the frame-relay link (when the router sees proxy.xxx.xx.edu.au it forwards out the organisation link) and check if the URL has been cached, and if not, come back to the local squid and retrieve the URL from the ADSL connection? Can anyone see a better way of doing this?

Will having two network cards help? and have all traffic to xxx.gov.au and xxx.edu.au site go to eth0 and all other traffic go out eth1, then the router can forward all eth0 traffic through the organisational link and eth1 through the ADSL link?

Thanks, i hope that is clearer.. I definitely need advice.
Adam
Received on Tue Feb 20 2007 - 21:48:33 MST

This archive was generated by hypermail pre-2.1.9 : Thu Mar 01 2007 - 12:00:01 MST