Solved

Setup Squid as a second gateway for internet traffic

Posted on 2013-06-09
7
870 Views
Last Modified: 2013-06-18
I have a need to separate one VLAN 150 internet traffic from the rest of our network.
It will still need normal traffic for login to the domain and receive updates, etc.
We will apply ACL on the CORE to only let it talk to the Domain Controller's network.

I will setup Squid running on a CentOS box.
The Squid server will have 2NIC, one NIC will be on the WAN side and one NIC will be on VLAN 150 to intercept HTTP, HTTPS,FTP traffic.

I need help setting up Squid to
    1. Intercept HTTP, HTTPS, FTP traffic for VLAN 150
    2. Restrict access to only 2-3 external domains.
I need help in CentOS
    1. To route HTTP, HTTPS, FTP traffic IN/OUT of the server.
    2. Tips on securing the Server from attack.

I think I got it all.
Thank you Experts !!!
Gilbert
HTTP-Separation.jpg
0
Comment
Question by:chfong98
  • 4
  • 3
7 Comments
 
LVL 77

Expert Comment

by:arnold
ID: 39233490
If you use a router/switch via WCCP, the squid setup should be in transparent mode.
https should not be redirected since it will be seen as a man in the middle attack warning to the user.

Not sure from whom you want to protect the centos box.

Adding squidGuard to your squid setup you can then define rules to restrict what sites users can access.
0
 

Author Comment

by:chfong98
ID: 39233592
I was able to get this to work as a test (somewhat).
-------------------------------------------------
in /etc/squid/squid.conf
-------------------------------------------------
acl vlan150 src 192.168.150.0/24
acl goodsites dstdomain .google.com .amazon.com .nba.com
(they are only allowed a few sites)
#
#http_access allow localnet
#http_access allow localhost
#
http_access allow vlan150 goodsites
I CAN INCLUDE THE WHOLE FILE IF YOU NEED TO SEE IT.
-------------------------------------------------
On the client I set the proxy on the browser
We will push a policy to the users on that VLAN to have proxy stick
from the client browser I can hit amazon and can login (skip the HTTPS part)
-------------------------------------------------
I will still need the Routing and NAT for IN/OUT traffic of the SquidBox.
I what to lock down CentOS from the outside.

Thanks
Gilbert
0
 
LVL 77

Expert Comment

by:arnold
ID: 39233712
I'm not sure on what you mean by lockdown.  You can get bastille which is a good tool to lockdown linux/unix based servers.

http://bastille-linux.sourceforge.net/
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 

Author Comment

by:chfong98
ID: 39233729
I am just looking for confirmation/fix on my Squid config and some Routing and NAT help.
WILL MY DESIGN WORK??  I AM DIGGING WHILE WAITING.
I am not a Linux expert I can follow along on the Routing, Nating and Squid config.
I can turn off ports that are not needed on the CentOS.

WCCP and recompile the kernel with GRE tunnel support is something that I am not too comfortable with and I don't have too much time to research Bastille time. I will definitely
look into it ones I have more time.


So much fun and so little time.
Much appreciated
Gilbert
0
 
LVL 77

Expert Comment

by:arnold
ID: 39233845
There is no need to recompile the kernel, the GRE should already be present.
modprobe -l | grep -i gre
which version of IOS do you have?

Your Centos/Squid box will function as a proxy and not as a router.  This is what puzzled me.
If you want all VLAN 150 traffic to stream through the centos/squid box that it is an entirely different matter.
0
 

Author Comment

by:chfong98
ID: 39251420
Sorry,

lets just work on setting up Squid as a forwarding proxy.
we will not have this host on the main network at all.
can you help me with the iptable part?

Thanks
Gilbert
0
 
LVL 77

Accepted Solution

by:
arnold earned 500 total points
ID: 39251449
There is missing information,

Are you using tagged vlans?

Your proxy must be setup in transparent mode.
Your iptables rules on the LAN side
First allow port 80 traffic from the squid proxy to pass.
Second divert any port 80 request to the squid proxy.
Look at
http://askubuntu.com/questions/4010/iptables-issue-with-squid-as-transparent-proxy
http://stackoverflow.com/questions/10595575/iptables-configuration-for-transparent-proxy
0

Featured Post

Enterprise Mobility and BYOD For Dummies

Like “For Dummies” books, you can read this in whatever order you choose and learn about mobility and BYOD; and how to put a competitive mobile infrastructure in place. Developed for SMBs and large enterprises alike, you will find helpful use cases, planning, and implementation.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

SHARE your personal details only on a NEED to basis. Take CHARGE and SECURE your IDENTITY. How do I then PROTECT myself and stay in charge of my own Personal details (and) - MY own WAY...
Our Group Policy work started with Small Business Server in 2000. Microsoft gave us an excellent OU and GPO model in subsequent SBS editions that utilized WMI filters, OU linking, and VBS scripts. These are some of experiences plus our spending a lo…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question