1
16.7 Legacy Series / Re: Opnsense Bridge with Squid transparent problem
« on: December 12, 2016, 10:35:16 am »
What "other products" can achieve this?
Now, only additional IPFW rules on the proxy and the server can achieve this: the server see the real clien ip address.
It seems the “divert-reply" option of pf can work for transparent proxy, but it does not work , maybe the kernel does not implement it.
Now, only additional IPFW rules on the proxy and the server can achieve this: the server see the real clien ip address.
It seems the “divert-reply" option of pf can work for transparent proxy, but it does not work , maybe the kernel does not implement it.
You said "Squid works in transparent mode." Then you said "client transparency". That's the same.
If you mean server transparency, you need to put your proxy behind NAT.
If you want your servers to see the clients and still do proxying, there are other products for this we cannot possibly support...
Cheers,
Franco