Hi all,
after lots of searching, i finally come to ask YOU for a solution:
I have 3 Internet connections, WAN1 to WAN3. I have a Loadbalancer, which distributes the Internet access of my network equally to those 3 lines. Now I want to set up a proxy for Microsoft, Adobe, Apple and other Updates ( IP-COP with Update Accelerator), because those updates (Microsoft Windows most) use lots of bandwith i would like to use in other ways.
I came to the conclusion, that routing all http-requests to the domains of *.microsoft.*, *.apple.* and so on through the ipcop would be the best way to get things going.
I cannot put the proxy behind the loadbalancer and all Users behind the proxy, because proxy only works with NAT enabled, so loadbalancer would only see one ip (the one of proxy) accessing the internet. As PFSENSE (my Loadbalancer) is configured to use sticky connections (meaning, a single IP-address in his LAN network will only use one of the three Internet connections to avoid changeing Source IP's for the User (seen from the view of the webservers in the internet)) .
From reading in the forums, i got the idea that a Layer 7 filter (for each domain preferreably, easier to construct with regex and easier to add new domains later) could do the trick.
Would anyone be so kind as to give me one example how to tell the Layer7 filter that "anything.microsoft.something" is L7 name "Microsoft" and has to be routed (perhaps with routing mark?) to gateway 1.2.3.4 (or WAN3)?
I have a Routerboard 600 that i could use as router or transparent bridge to do this L7 and routing stuff, please advise what's better, routing or bridgeing?
Thanks in advance
Sincerely
Schnulch