Re: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-15 Thread Amos Jeffries
On 15/11/2012 9:53 p.m., Vincent Miszczak wrote: Hi, Thank you for your answer. I understand I cannot redirect SSL web traffic to intercepting Squid using NAT from another box, as Squid won't be able to figure out the destination address, right ? Yes. That is one of the side effects of NAT

Re: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-15 Thread Eliezer Croitoru
On 11/15/2012 10:53 AM, Vincent Miszczak wrote: Hi, Thank you for your answer. I understand I cannot redirect SSL web traffic to intercepting Squid using NAT from another box, as Squid won't be able to figure out the destination address, right ? Vincent yes, but you can use --set-mark with i

RE: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-15 Thread Vincent Miszczak
actory.com] Envoyé : mercredi 14 novembre 2012 19:34 À : Vincent Miszczak Cc : squid-dev@squid-cache.org Objet : Re: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection On 11/14/2012 11:17 AM, Vincent Miszczak wrote: > I'd like to know how Squid resolves th

Re: Squid HEAD : intercept SSLBump server first + out of Squid box NAT redirection

2012-11-14 Thread Alex Rousskov
On 11/14/2012 11:17 AM, Vincent Miszczak wrote: > I’d like to know how Squid resolves the remote host when handling an > intercepted server-first bumped connection, so I’ll be able to setup my > network accordingly. Using the destination address of the intercepted TCP connection, Squid securely c