Solved

Allow specific hosts/IPs to bypass Squid authentication

Posted on 2009-05-12
3
3,592 Views
Last Modified: 2013-11-22
Is it possible to have an entry in the Squid.conf that would allow a specific host/IP to bypass NTLM authentication?

Currently all users surf the web an authenticate via NTLM to the Active Directory.  My problem is that I have a copier that we'd like setup for scan-to-email using an external SMTP server but the copier doesn't allow proxy configurations.
0
Comment
Question by:leadwave
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 13

Accepted Solution

by:
WizRd-Linux earned 500 total points
ID: 24371517
Add the site to a file called /etc/squid/whitelist

In the squid.conf file add the following:

acl whitelist dstdomain "/etc/squid/whitelist"
http_access allow whitelist

Make sure the http_access is before your ntlm authentication line.  Restart squid and you should be good.
0
 

Author Comment

by:leadwave
ID: 24373421
Thanks, I'll give that a try.
0
 
LVL 1

Expert Comment

by:joobz
ID: 25323595
leadwave, Another alternative is to just bypass Squid all together for this particular host.

Presuming you are routing the traffic to Squid via IPTables Prerouting - before your Prerouting rule that does the Squid redirect, just add something like..

> iptables -t nat -I PREROUTING -i eth0 -s <printer_ip> -p tcp --dport 25 -j ACCEPT

Benefit of this is it will keep the load away from Squid (though minor, it's not necessary for it to hit Squid).
0

Featured Post

Building an interactive eFuture classroom

Watch and learn how ATEN provided a total control system solution including seamless switching matrix switch, HDBaseT extenders, PDU, lighting control to build an interactive eFuture classroom.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

So you got the Conficker. You could go to each machine and run the eye chart test (http://www.confickerworkinggroup.org/infection_test/cfeyechart.html), but in a bigger environment, or if you prefer to work smarter and not harder, you need some …
PREFACE The purpose of this guide is to explain what the SEPC Status Utility is and how it works. I have written the utility using AutoIt and have included the source code for your review. You are welcome to modify the code to your liking, but I wi…
Established in 1997, Technology Architects has become one of the most reputable technology solutions companies in the country. TA have been providing businesses with cost effective state-of-the-art solutions and unparalleled service that is designed…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

734 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question