Solved

Free Proxy Server

Posted on 2009-07-11
7
351 Views
Last Modified: 2013-11-16
Hello Experts,
i'm going to close a MS ISA 2004 proxy server due to high license costs. Due to this business choice I have to find a valid substitute but freeware/GNU.

the aim is using this proxy as CACHE server for a big site (400 users). Only authenticated users can use the proxy. Windows 2003 Active Directory authentication based on AD group(s).

I have 10 years skills on most of the microsoft products but very poor in Linux/Unix OS.
I could use VMWare technology (ESX 3.5 vi3) with vitual appliance.

have you any suggestions how to approch this translaction? what about SQUID? i tried it 1 year ago but i had a lot of problems with AD authentications.

thanks in advance
Andrea.
0
Comment
Question by:ITDataCenter
  • 4
  • 2
7 Comments
 
LVL 40

Expert Comment

by:mrjoltcola
Comment Utility
Squid is certainly the most popular, by far. Thats what I would recommend, since it has the largest userbase and knowledgebase.

Have you see this article regarding Squid + AD?

http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

Google squid + ldap authentication to get some more articles

If you've already a working AD, then you should be able to work the squid config in on the side and fully test it with AD prior to ever doing any permanent changes to the main proxy.
0
 
LVL 1

Author Comment

by:ITDataCenter
Comment Utility
Wow! that's a great article, thanks so much! I'll have a try building a VM with Ubuntu+squid.

Yesterday I played with the latest IpCop appliance that looks very easy to manage and install. I succeeded having AD working with ipacop but i don't like the NTLM authentication mode which asks every time the user credentials. i'd like have the users enabled authenticated with kerberos without crendetials requests at any time they open the browser.

Do you know if exist a very easy step by step setup of squid in any linux box? i have very basic linux skills.. i'm a little bit lost on the OS/software setup on this environment. thanks!
0
 
LVL 14

Expert Comment

by:small_student
Comment Utility
An alternative solutoin for having the users enter logon information is to use firefox instead of IE.

You can also use squidguard with squid to do category based filtering much like websence and bluecoat does (Not that powerfull DB ofcourse but also not much less for a free product)

If you are stuck with any squidish stuff just post it here
0
Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

 
LVL 1

Author Comment

by:ITDataCenter
Comment Utility
Hi guys,
even if forefox is much better than IE, I have bloody corporate rules that force me using it.
at the top of all company divisions we have a websence filtering but at the site level we do not have any cache (MS ISA2004 to be dismissed). After hours of googling I found this nice article
http://www.thedailyadmin.com/2009/04/how-to-install-virtual-machine-with.html
I'll mix the papercut solution provide by you and I'll probably end this in to a realable cache proxy server based on linux OS. i'll keep you posted! ciao
0
 
LVL 1

Author Comment

by:ITDataCenter
Comment Utility
hi!i
i have just installed the squid+dansguardian.
how can i temporarely route the www traffic made by this new squid box to another proxy? in this staging I do not have corporate firewall ports open for the new squid server so I would first have a proxy chaning than move it as normal (if works ;))

staging:
new squid > proxy > firewall > internet
future:
new squid > firewall > internet


thanks
ciao
0
 
LVL 40

Expert Comment

by:mrjoltcola
Comment Utility
You'll get better help if you phrase a new question with that specific intent in mind. I do not work hands-on with squid or any other proxy server in the last 7 years or more. My experience is quite dated. I knew enough to recommend squid but not hands-on to config.
0
 
LVL 1

Accepted Solution

by:
ITDataCenter earned 0 total points
Comment Utility
hi,
i'm lost, i used papercut guidine but i'm not able to authenticate agaist active directory domain
http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

I used microsoft ldp to test the ldap bind and group CN path and all is okay.
when i open the browser i get the user name/password request. even if the user and password is typed manually the popup back again, no way to go further.
I don't understand what is wrong, pleasee help!!

0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

HOW TO REMOTELY CLEAN MEROND.O WITH ESET SILENTLY PROBLEM       If you have the fortunate luck to contract the Merond.O virus on your network, it can be quite troublesome to remove as it propagates to network shares on your network. In my case, the …
Hi All,  Recently I have installed and configured a Sonicwall NS220 in the network as a firewall and Internet access gateway. All was working fine until users started reporting that they cannot use the Cisco VPN client to connect to the customer'…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now