Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Adding squid to a hotspot setup

Posted on 2014-01-27
1
Medium Priority
?
1,449 Views
Last Modified: 2014-02-03
Hi
 
I have a client who is situated too far way from the
closest ADSL DSLAM. There isn't any 3G or 4G coverage
either. His ADSL bandwidth is: 1.1Mbps/0.6Mbps.

I suggested we take the satellite route and they are now
using NordNet/TooWay (Orange) 12Mbps/4Mbps.

Unfortunately the latency and frequent link disruptions
are not making this option very attractive to their clients.

I am contemplating adding Squid to a small Debian box which
is already collecting log data (MySQL).

Because of the limited number of connectors on the Mikrotik
RB450, I have had to connect this linux box as shown below
squidThough on different subnets the linux box and Zyxel can see
each other.

I have set the linux box's default gateway as the RB450
(192.168.150.5).

From what I understand, I must enable the Web proxy on the
RB450 and specify the linux box as 'parent' proxy.

I also read somewhere that I could use the NAT masquerade
rule on the RB450 to redirect http traffic to the squid.

I guess I'll have to setup a mangle rule to redirect the returning
http squid traffic in order to have it sent via the SAT link.

Any ideas, suggestions caveats ?

thanks

yann
0
Comment
Question by:Yann Shukor
1 Comment
 

Accepted Solution

by:
Yann Shukor earned 0 total points
ID: 39830095
Answered on the Mikrotik forum by:
aacable
you can redirect http traffic from your rb450 box to squid using dst-nat rule,
squid can be configured with single lan interface too, just define default gateway of Squid pointing to Mikrotik. and in mikrotik create a NAT rule rule to allow traffic from the squid to be masqueraded.
and kilrathi
I have an external proxy for my users as well. In this post I listed a few things i manged to do in order to redirect my users to the proxy server transparently. You do not have to use the build in web proxy on the mikrotik device. In my case I didn't want to spend the extra CPU power on my mikrotik for proxy services plus the redirect to a parent proxy. I just tag all the port 80 traffic with mangle and route it directly to the external squid proxy server (mikrotik web proxy is disabled).
0

Featured Post

NFR key for Veeam Backup for Microsoft Office 365

Veeam is happy to provide a free NFR license (for 1 year, up to 10 users). This license allows for the non‑production use of Veeam Backup for Microsoft Office 365 in your home lab without any feature limitations.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question