Solved

Setup Squid as a second gateway for internet traffic

Posted on 2013-06-09
7
869 Views
Last Modified: 2013-06-18
I have a need to separate one VLAN 150 internet traffic from the rest of our network.
It will still need normal traffic for login to the domain and receive updates, etc.
We will apply ACL on the CORE to only let it talk to the Domain Controller's network.

I will setup Squid running on a CentOS box.
The Squid server will have 2NIC, one NIC will be on the WAN side and one NIC will be on VLAN 150 to intercept HTTP, HTTPS,FTP traffic.

I need help setting up Squid to
    1. Intercept HTTP, HTTPS, FTP traffic for VLAN 150
    2. Restrict access to only 2-3 external domains.
I need help in CentOS
    1. To route HTTP, HTTPS, FTP traffic IN/OUT of the server.
    2. Tips on securing the Server from attack.

I think I got it all.
Thank you Experts !!!
Gilbert
HTTP-Separation.jpg
0
Comment
Question by:chfong98
  • 4
  • 3
7 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 39233490
If you use a router/switch via WCCP, the squid setup should be in transparent mode.
https should not be redirected since it will be seen as a man in the middle attack warning to the user.

Not sure from whom you want to protect the centos box.

Adding squidGuard to your squid setup you can then define rules to restrict what sites users can access.
0
 

Author Comment

by:chfong98
ID: 39233592
I was able to get this to work as a test (somewhat).
-------------------------------------------------
in /etc/squid/squid.conf
-------------------------------------------------
acl vlan150 src 192.168.150.0/24
acl goodsites dstdomain .google.com .amazon.com .nba.com
(they are only allowed a few sites)
#
#http_access allow localnet
#http_access allow localhost
#
http_access allow vlan150 goodsites
I CAN INCLUDE THE WHOLE FILE IF YOU NEED TO SEE IT.
-------------------------------------------------
On the client I set the proxy on the browser
We will push a policy to the users on that VLAN to have proxy stick
from the client browser I can hit amazon and can login (skip the HTTPS part)
-------------------------------------------------
I will still need the Routing and NAT for IN/OUT traffic of the SquidBox.
I what to lock down CentOS from the outside.

Thanks
Gilbert
0
 
LVL 77

Expert Comment

by:arnold
ID: 39233712
I'm not sure on what you mean by lockdown.  You can get bastille which is a good tool to lockdown linux/unix based servers.

http://bastille-linux.sourceforge.net/
0
New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

 

Author Comment

by:chfong98
ID: 39233729
I am just looking for confirmation/fix on my Squid config and some Routing and NAT help.
WILL MY DESIGN WORK??  I AM DIGGING WHILE WAITING.
I am not a Linux expert I can follow along on the Routing, Nating and Squid config.
I can turn off ports that are not needed on the CentOS.

WCCP and recompile the kernel with GRE tunnel support is something that I am not too comfortable with and I don't have too much time to research Bastille time. I will definitely
look into it ones I have more time.


So much fun and so little time.
Much appreciated
Gilbert
0
 
LVL 77

Expert Comment

by:arnold
ID: 39233845
There is no need to recompile the kernel, the GRE should already be present.
modprobe -l | grep -i gre
which version of IOS do you have?

Your Centos/Squid box will function as a proxy and not as a router.  This is what puzzled me.
If you want all VLAN 150 traffic to stream through the centos/squid box that it is an entirely different matter.
0
 

Author Comment

by:chfong98
ID: 39251420
Sorry,

lets just work on setting up Squid as a forwarding proxy.
we will not have this host on the main network at all.
can you help me with the iptable part?

Thanks
Gilbert
0
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 39251449
There is missing information,

Are you using tagged vlans?

Your proxy must be setup in transparent mode.
Your iptables rules on the LAN side
First allow port 80 traffic from the squid proxy to pass.
Second divert any port 80 request to the squid proxy.
Look at
http://askubuntu.com/questions/4010/iptables-issue-with-squid-as-transparent-proxy
http://stackoverflow.com/questions/10595575/iptables-configuration-for-transparent-proxy
0

Featured Post

Complete VMware vSphere® ESX(i) & Hyper-V Backup

Capture your entire system, including the host, with patented disk imaging integrated with VMware VADP / Microsoft VSS and RCT. RTOs is as low as 15 seconds with Acronis Active Restore™. You can enjoy unlimited P2V/V2V migrations from any source (even from a different hypervisor)

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Fine Tune your automatic Updates for Ubuntu / Debian
Learn how to find files with the shell using the find and locate commands. Use locate to find a needle in a haystack.: With locate, check if the file still exists.: Use find to get the actual location of the file.:
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now