Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Allow specific hosts/IPs to bypass Squid authentication

Posted on 2009-05-12
3
3,512 Views
Last Modified: 2013-11-22
Is it possible to have an entry in the Squid.conf that would allow a specific host/IP to bypass NTLM authentication?

Currently all users surf the web an authenticate via NTLM to the Active Directory.  My problem is that I have a copier that we'd like setup for scan-to-email using an external SMTP server but the copier doesn't allow proxy configurations.
0
Comment
Question by:leadwave
3 Comments
 
LVL 13

Accepted Solution

by:
WizRd-Linux earned 500 total points
ID: 24371517
Add the site to a file called /etc/squid/whitelist

In the squid.conf file add the following:

acl whitelist dstdomain "/etc/squid/whitelist"
http_access allow whitelist

Make sure the http_access is before your ntlm authentication line.  Restart squid and you should be good.
0
 

Author Comment

by:leadwave
ID: 24373421
Thanks, I'll give that a try.
0
 
LVL 1

Expert Comment

by:joobz
ID: 25323595
leadwave, Another alternative is to just bypass Squid all together for this particular host.

Presuming you are routing the traffic to Squid via IPTables Prerouting - before your Prerouting rule that does the Squid redirect, just add something like..

> iptables -t nat -I PREROUTING -i eth0 -s <printer_ip> -p tcp --dport 25 -j ACCEPT

Benefit of this is it will keep the load away from Squid (though minor, it's not necessary for it to hit Squid).
0

Featured Post

Master Your Team's Linux and Cloud Stack

Come see why top tech companies like Mailchimp and Media Temple use Linux Academy to build their employee training programs.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
IPA client Config problems 2 215
installed old nagios.... 13 153
iOS vulnerability (9.3.5) 5 92
Allowing Youtube access only for 30 PCs on the network - BLOXX filtering system 3 98
Change your password...do it now!. Probably the easiest point of access to your account is through guessing your password. If your password is guessable, do change it now. If not for your sake but for everyone else in your friends list. Remember …
OVERVIEW This guide provides information on the process performed when the Symantec Endpoint Protection (SEP) client checks in with the Symantec Endpoint Protection Manager (SEPM). AUDIENCE Information Technology personnel responsible for suppo…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

856 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question