Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
squid doesn't work - hardware router, intranet [SOLVED]
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
karol
n00b
n00b


Joined: 21 Jun 2005
Posts: 22

PostPosted: Tue Jul 26, 2005 6:15 pm    Post subject: squid doesn't work - hardware router, intranet [SOLVED] Reply with quote

Hi,
I just want to make sure...
Is it possible to setup squid in such intranet...
My new employer has hardware router and behind the router there is whole intranet. There is no dns-server, intranet is on dhcp.
And now he wishes to have a squid proxy... Everything would be nice, but he whants me to setup squid inside intranet... Is it possible ?
Router is conneted to inet with dsl and has static ip...

I'am sorry if I wrote something not correctly... (eng. I mean)

Thank you all for your answers.

cheers
_________________
gg: 1910078


Last edited by karol on Thu Jul 28, 2005 7:45 am; edited 1 time in total
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Tue Jul 26, 2005 7:59 pm    Post subject: Reply with quote

global answer: possible without bigger issues

exact: answer: more details needed

Is squid meant do act as proxy between internet and intranet OR is it meant to act as proxy in intranet for intranet?
In the first case dns access from the squid machine towards internet is needed, otherwise it would only be possible to surf the web by ip instead of names like forums.gentoo.org (obviously)...
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
karol
n00b
n00b


Joined: 21 Jun 2005
Posts: 22

PostPosted: Tue Jul 26, 2005 8:16 pm    Post subject: Reply with quote

"Is squid meant do act as proxy between internet and intranet OR is it meant to act as proxy in intranet for intranet? "
Well my employer would like a box from intranet to be a proxy for internet...
In my opinion in this case impossible...
Thank you...
_________________
gg: 1910078
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Tue Jul 26, 2005 8:33 pm    Post subject: Reply with quote

karol wrote:
"Is squid meant do act as proxy between internet and intranet OR is it meant to act as proxy in intranet for intranet? "
Well my employer would like a box from intranet to be a proxy for internet...
In my opinion in this case impossible...
Thank you...


possible, no problem at all
as i said before, the machine running squid needs to have dns access towards internet plus access to port 80/443 at least
this could either be done by having the router doing NAT for this machine (only)
the configuration for the internal clients is just a matter of correct ACLs in squid.conf
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
karol
n00b
n00b


Joined: 21 Jun 2005
Posts: 22

PostPosted: Tue Jul 26, 2005 8:49 pm    Post subject: Reply with quote

than what should I do ?
How to setup a squid box running inside intranet ?
I've lost all the steam, I feel pumped out...
_________________
gg: 1910078
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Tue Jul 26, 2005 9:11 pm    Post subject: Reply with quote

a) the router needs to be default gateway for the squid box
b) the router needs to do NAT for the machine running squid
it is NOT needed to configure any port forwardings on the router - just NAT 'internal ip squidbox'->'external IP on DSL side'
c) the machine running squid needs (at least) outgoing access (to internet) for ports 53/udp, 80/tcp + 443/tcp (dns, http, https)
everything else could be dropped at the router (if not needed otherwise of course)
d) http://gentoo-wiki.com/HOWTO_setup_a_home-server#Configuring_squid; adopt as needed (network address comes to mind)
e) configure all clients which want to have internet access with appropriate proxy settings
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
karol
n00b
n00b


Joined: 21 Jun 2005
Posts: 22

PostPosted: Wed Jul 27, 2005 6:20 am    Post subject: Reply with quote

Think4UrS11 thank you....
I'am going to try this in the afternoon... This way or another thank you...
There are moments, when I just feel hopeless... Yesterday was such a day...
_________________
gg: 1910078
Back to top
View user's profile Send private message
think4urs11
Bodhisattva
Bodhisattva


Joined: 25 Jun 2003
Posts: 6659
Location: above the cloud

PostPosted: Wed Jul 27, 2005 6:32 am    Post subject: Reply with quote

karol wrote:
Think4UrS11 thank you....
I'am going to try this in the afternoon... This way or another thank you...
There are moments, when I just feel hopeless... Yesterday was such a day...


no prob, we all have these days from time to time...
feel free to ask if you need further assistance
_________________
Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum