Re: [squid-users] Tproxy vs Squid Transparent For Gtalk

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Fri, 29 Jan 2010 23:35:52 +1300

anand phulwani wrote:
> Dear List,
>
> I dont know what is the status of the gtalk binary problem but as i
> last read for the post from Amos i think the problem is not yet
> solved, Amos if you have read this, requesting you to comment on the
> present status, i was using squid3.1 for sslBump and was wondering
> that if Tproxy is able to solve the gtalk problem, moreover will it
> be able to allow acl on HTTPS.

Maybe. I'm not going to advise you to do it though. Least of all in
public and writing.

There are plenty of other applications to use than gtalk. Most of whom
don't encrypt.

>
> I dont have a cisco router in my enviroment and i was just going
> through the configuration which raised a question that what i would
> be using at
>
> wccp2_router y.y.y.y
>
> and as i dont have the router,how i would be doing this
>
> ip wccp 80 ip wccp 90 int fasteth0 -->ip wccp 80 redirect out
> (gateway to internet) int fasteth1 -->ip wccp 90 redirect out (my
> client gateway) int fasteth3 -->ip wccp redirect exclude in
> (squid-box attached here)
>

WCCP _will_not_ redirect HTTPS. By design.

> i am in an ADSL enviroment with the beetel basic router cum modem,and
> i am trying to use my linux machine as a router.

Linux machine a router can pass arbitrary packets to Squid. No WCCP or
Cisco involved. Just make sure the content is the HTTP protocol format
that Squid can process.

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE7 or 3.0.STABLE21
   Current Beta Squid 3.1.0.15
Received on Fri Jan 29 2010 - 10:36:01 MST

This archive was generated by hypermail 2.2.0 : Fri Jan 29 2010 - 12:00:05 MST