Re: [squid-users] TPROXY vs Netfilter (transparency)

From: Gonzalo Arana <gonzalo.arana@dont-contact.us>
Date: Wed, 12 Dec 2007 17:39:15 -0300

On Dec 12, 2007 2:49 PM, Jason Gauthier <jgauthier@lastar.com> wrote:
> All,
>
> Is there really any difference on a Linux system between utilizing the TPROXY
> method versus Netfilter method? And are there anything that outweighs one from the other?

AFAIK, the differences are:
1) TPROXY allows you to connect with user's ip address, so web servers
do not require to log X-Forwarded-For.
2) TPROXY provides automatic fallback to plain routing (for new
connections) if case squid is no longer accepting connections.

Regards,

-- 
Gonzalo A. Arana
Received on Wed Dec 12 2007 - 13:39:18 MST

This archive was generated by hypermail pre-2.1.9 : Tue Jan 01 2008 - 12:00:01 MST