Page 1 of 1

issues with external squid

Posted: Tue Nov 12, 2013 9:02 am
by obomz
Hi,

I have been trying for quite a while now with no apparent success to create a transparent squid for my network.

Attached is a rough network diagram.

I am encountering a problem pushing traffic to the squid. But if I make the squid non-transparent it works quite well but the issue I have with that is that we operate a fairly large and still growing base of users so I don't think I can go round each one and start inputting the proxy settings for each, and also there is the issue of ip-tables to settle with for the smtp ports and so on. So I think I will Just stick with the transparent squid for convenience sake.

I have seen many CLI commands on forums that did not work for me on both my RB1100 & X86 each and every time I input these CLI commands I would end up resetting my routerboard! This is because the routerboard always seems to hang Or freezes shortly after I do the CLI input! Presently I run on 5.22 as am comfortable with that.

I would appreciate it if you could please send me a set of CLI commands that I can use to make this happen.

Thank you.

Re: issues with external squid

Posted: Tue Nov 12, 2013 1:18 pm
by CTrain
Does the mikrotik on your network handle the masquerading nat on your network?

If yes it needs to dstnat any traffic from the lan to the squid server.
Use winbox to build the rule based upon my post in the below topic. you should be able to specify IP range or in/out interfaces based upon your exact network setup. Just remember to not keep the Squid server in an infinite loop by accident, inside the nat.

http://forum.mikrotik.com/viewtopic.php?f=13&t=77635