LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-24-2009, 03:31 AM   #1
snake eyes
LQ Newbie
 
Registered: Nov 2007
Posts: 17

Rep: Reputation: 0
Bypassing Squid for local servers


Hello people



I am running Squid on RedHat 5 server
I have 4 sites in my intranet and all users use proxy to connect to internet.Sometimes when internet line is down, then my internal sites can't be accessed.
I'd like squid to bypass the proxy when users are accessing the local
intranet sites

Right now users explicitly specify proxy options in the browsers .. BYPASS PROXY FOR LOCAL SERVERS

But that doesn't work



I have an internal DNS running on a different subnet. Now the strange thing is, if I put in only the IP address of intranet sites, they open without delay, but when i enter URL it takes a very long time. I analysed the traffic on Wireshark.
Turns out when I enter URL, all the traffic is routed through proxy, making it extremely slow.
Is there any way to bypass proxy for local intranet sites. (2 each on 2 diffenet subnets)
I tried searching everywhere in squid.conf file, but was unable to find anything. Most tutorials on net were for transparent proxies which don't apply to my case.









regards
 
Old 03-24-2009, 03:39 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well I don't see how squid could be actually involved in this, the point is, when squid is dead so is the intranet, so you can't fix that with squid. a "local" address in a browser normally means a non-fqdn e.g. "intranet" rather than "intranget.mycompany.com" so only use the short host name. Alternatively, use a proxy.pac / wpad.dat file to provide more specific control to the browsers. there are plenty of good sites explaining how to craft a proxy.pac file for your browsers to use directly.
 
Old 03-24-2009, 04:12 AM   #3
snake eyes
LQ Newbie
 
Registered: Nov 2007
Posts: 17

Original Poster
Rep: Reputation: 0
Well, even when internet access is fine and I've instructed clients to bypass proxy for all local sites, then why does all the traffic gets routed through proxy? I've checked this through a bandwidth controller (packeteer) and wireshark. When I enter domain name (fqdn) all traffic is routed through proxy. When I put in IP of intranet server, traffic is directly between intranet server and client.

Is there anything to fix that? That is to allow direct data transfer between all the intranet servers and clients?
We have to use FQDN here, not hostname. It's one particular requirement.
Configuring each PC in network is simply not an option either.
 
Old 03-24-2009, 04:22 AM   #4
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
well I've already told you what to do... proxy.pac
 
Old 03-24-2009, 05:03 AM   #5
grizly
Member
 
Registered: Nov 2006
Location: Melbourne Australia
Distribution: Centos, RHEL, Debian, Ubuntu, Mint
Posts: 128

Rep: Reputation: 16
<snip err>

I have only ever setup proxy.pac or wpad.dat files.

Last edited by grizly; 03-24-2009 at 06:29 AM. Reason: agree with ak ;)
 
Old 03-24-2009, 06:17 AM   #6
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
that's not direct though... that's via squid..! always_direct isn't a self referential command, it's about other upstream proxies.
 
Old 03-24-2009, 06:23 AM   #7
grizly
Member
 
Registered: Nov 2006
Location: Melbourne Australia
Distribution: Centos, RHEL, Debian, Ubuntu, Mint
Posts: 128

Rep: Reputation: 16
Ahh.. it sounded too easy.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
bypassing squid for particular ip hariiyer Linux - Networking 4 10-04-2007 02:06 AM
bypassing 'iptables' & 'squid' mbin Linux - Security 4 09-12-2007 08:20 AM
squid acl bypassing shakeeb_linux Linux - Newbie 3 04-01-2007 11:03 AM
Accelerated squid for 2 servers DrNeil Linux - Software 0 09-22-2005 08:37 PM
Configure 2 Squid Servers brains_online Linux - Networking 2 12-25-2004 12:11 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 08:08 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration