Solved

Free Proxy Server

Posted on 2009-07-11
7
355 Views
Last Modified: 2013-11-16
Hello Experts,
i'm going to close a MS ISA 2004 proxy server due to high license costs. Due to this business choice I have to find a valid substitute but freeware/GNU.

the aim is using this proxy as CACHE server for a big site (400 users). Only authenticated users can use the proxy. Windows 2003 Active Directory authentication based on AD group(s).

I have 10 years skills on most of the microsoft products but very poor in Linux/Unix OS.
I could use VMWare technology (ESX 3.5 vi3) with vitual appliance.

have you any suggestions how to approch this translaction? what about SQUID? i tried it 1 year ago but i had a lot of problems with AD authentications.

thanks in advance
Andrea.
0
Comment
Question by:ITDataCenter
  • 4
  • 2
7 Comments
 
LVL 40

Expert Comment

by:mrjoltcola
ID: 24831241
Squid is certainly the most popular, by far. Thats what I would recommend, since it has the largest userbase and knowledgebase.

Have you see this article regarding Squid + AD?

http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

Google squid + ldap authentication to get some more articles

If you've already a working AD, then you should be able to work the squid config in on the side and fully test it with AD prior to ever doing any permanent changes to the main proxy.
0
 
LVL 1

Author Comment

by:ITDataCenter
ID: 24833642
Wow! that's a great article, thanks so much! I'll have a try building a VM with Ubuntu+squid.

Yesterday I played with the latest IpCop appliance that looks very easy to manage and install. I succeeded having AD working with ipacop but i don't like the NTLM authentication mode which asks every time the user credentials. i'd like have the users enabled authenticated with kerberos without crendetials requests at any time they open the browser.

Do you know if exist a very easy step by step setup of squid in any linux box? i have very basic linux skills.. i'm a little bit lost on the OS/software setup on this environment. thanks!
0
 
LVL 14

Expert Comment

by:small_student
ID: 24834179
An alternative solutoin for having the users enter logon information is to use firefox instead of IE.

You can also use squidguard with squid to do category based filtering much like websence and bluecoat does (Not that powerfull DB ofcourse but also not much less for a free product)

If you are stuck with any squidish stuff just post it here
0
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.

 
LVL 1

Author Comment

by:ITDataCenter
ID: 24846812
Hi guys,
even if forefox is much better than IE, I have bloody corporate rules that force me using it.
at the top of all company divisions we have a websence filtering but at the site level we do not have any cache (MS ISA2004 to be dismissed). After hours of googling I found this nice article
http://www.thedailyadmin.com/2009/04/how-to-install-virtual-machine-with.html
I'll mix the papercut solution provide by you and I'll probably end this in to a realable cache proxy server based on linux OS. i'll keep you posted! ciao
0
 
LVL 1

Author Comment

by:ITDataCenter
ID: 24867695
hi!i
i have just installed the squid+dansguardian.
how can i temporarely route the www traffic made by this new squid box to another proxy? in this staging I do not have corporate firewall ports open for the new squid server so I would first have a proxy chaning than move it as normal (if works ;))

staging:
new squid > proxy > firewall > internet
future:
new squid > firewall > internet


thanks
ciao
0
 
LVL 40

Expert Comment

by:mrjoltcola
ID: 24871434
You'll get better help if you phrase a new question with that specific intent in mind. I do not work hands-on with squid or any other proxy server in the last 7 years or more. My experience is quite dated. I knew enough to recommend squid but not hands-on to config.
0
 
LVL 1

Accepted Solution

by:
ITDataCenter earned 0 total points
ID: 24913963
hi,
i'm lost, i used papercut guidine but i'm not able to authenticate agaist active directory domain
http://www.papercut.com/kb/Main/ConfiguringSquidProxyToAuthenticateWithActiveDirectory

I used microsoft ldp to test the ldap bind and group CN path and all is okay.
when i open the browser i get the user name/password request. even if the user and password is typed manually the popup back again, no way to go further.
I don't understand what is wrong, pleasee help!!

0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Replace Ubuntu Desktop with Ubuntu Server 7 89
ipsec tunnel comme not up 10 71
Sonicwall TZ 205- Dropping Incoming E-mail as IP Spoof 13 87
Video Streaming 6 52
These are on the increase and getting more common these days. Users who use the Google search engine may complain of having their search redirected to unwanted sites, regardless of what browser is used. This happens when the system is infected with…
Little introduction about CP: CP is a command on linux that use to copy files and folder from one location to another location. Example usage of CP as follow: cp /myfoder /pathto/destination/folder/ cp abc.tar.gz /pathto/destination/folder/ab…
Learn how to get help with Linux/Unix bash shell commands. Use help to read help documents for built in bash shell commands.: Use man to interface with the online reference manuals for shell commands.: Use man to search man pages for unknown command…
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:

930 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

13 Experts available now in Live!

Get 1:1 Help Now