Free Proxy Server

Hello Experts,
i'm going to close a MS ISA 2004 proxy server due to high license costs. Due to this business choice I have to find a valid substitute but freeware/GNU.

the aim is using this proxy as CACHE server for a big site (400 users). Only authenticated users can use the proxy. Windows 2003 Active Directory authentication based on AD group(s).

I have 10 years skills on most of the microsoft products but very poor in Linux/Unix OS.
I could use VMWare technology (ESX 3.5 vi3) with vitual appliance.

have you any suggestions how to approch this translaction? what about SQUID? i tried it 1 year ago but i had a lot of problems with AD authentications.

thanks in advance
Andrea.
LVL 1
ITDataCenterAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mrjoltcolaCommented:
Squid is certainly the most popular, by far. Thats what I would recommend, since it has the largest userbase and knowledgebase.

Have you see this article regarding Squid + AD?

http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

Google squid + ldap authentication to get some more articles

If you've already a working AD, then you should be able to work the squid config in on the side and fully test it with AD prior to ever doing any permanent changes to the main proxy.
0
ITDataCenterAuthor Commented:
Wow! that's a great article, thanks so much! I'll have a try building a VM with Ubuntu+squid.

Yesterday I played with the latest IpCop appliance that looks very easy to manage and install. I succeeded having AD working with ipacop but i don't like the NTLM authentication mode which asks every time the user credentials. i'd like have the users enabled authenticated with kerberos without crendetials requests at any time they open the browser.

Do you know if exist a very easy step by step setup of squid in any linux box? i have very basic linux skills.. i'm a little bit lost on the OS/software setup on this environment. thanks!
0
Monis MontherSystem ArchitectCommented:
An alternative solutoin for having the users enter logon information is to use firefox instead of IE.

You can also use squidguard with squid to do category based filtering much like websence and bluecoat does (Not that powerfull DB ofcourse but also not much less for a free product)

If you are stuck with any squidish stuff just post it here
0
Challenges in Government Cyber Security

Has cyber security been a challenge in your government organization? Are you looking to improve your government's network security? Learn more about how to improve your government organization's security by viewing our on-demand webinar!

ITDataCenterAuthor Commented:
Hi guys,
even if forefox is much better than IE, I have bloody corporate rules that force me using it.
at the top of all company divisions we have a websence filtering but at the site level we do not have any cache (MS ISA2004 to be dismissed). After hours of googling I found this nice article
http://www.thedailyadmin.com/2009/04/how-to-install-virtual-machine-with.html
I'll mix the papercut solution provide by you and I'll probably end this in to a realable cache proxy server based on linux OS. i'll keep you posted! ciao
0
ITDataCenterAuthor Commented:
hi!i
i have just installed the squid+dansguardian.
how can i temporarely route the www traffic made by this new squid box to another proxy? in this staging I do not have corporate firewall ports open for the new squid server so I would first have a proxy chaning than move it as normal (if works ;))

staging:
new squid > proxy > firewall > internet
future:
new squid > firewall > internet


thanks
ciao
0
mrjoltcolaCommented:
You'll get better help if you phrase a new question with that specific intent in mind. I do not work hands-on with squid or any other proxy server in the last 7 years or more. My experience is quite dated. I knew enough to recommend squid but not hands-on to config.
0
ITDataCenterAuthor Commented:
hi,
i'm lost, i used papercut guidine but i'm not able to authenticate agaist active directory domain
http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

I used microsoft ldp to test the ldap bind and group CN path and all is okay.
when i open the browser i get the user name/password request. even if the user and password is typed manually the popup back again, no way to go further.
I don't understand what is wrong, pleasee help!!

0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Anti-Virus Apps

From novice to tech pro — start learning today.