LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Software
User Name
Password
Linux - Software This forum is for Software issues.
Having a problem installing a new program? Want to know which application is best for the job? Post your question in this forum.

Notices


Reply
  Search this Thread
Old 05-03-2005, 12:37 AM   #1
ivanatora
Member
 
Registered: Sep 2003
Location: Bulgaria
Distribution: Ubuntu 9.10, FreeBSD 7.2
Posts: 459

Rep: Reputation: 32
SQUID strange security issue


We have s small network, the internet connection is provided by a gateway, which SNATs every of the inside PCs (everyone by its IP, not the entire subnet). So If a new PC comes with another IP it shouldn't have internet access. On that gateway we have squid-cache running. I tried to change my IP to another one, which isn't SNATed and can't open web pages. BUT! If I configure as proxy for the browser the squid server, the squid fetches me web pages! I'm not sure what makes squid acting like this, and if it is normaly behavior.. In it's acl's is defined our network as 'http_access allow" and everything other is denied. I don't want squid fetching web pages for PCs that doesn't have to have internet access... Do I have to list all of my PCs in squid's acls, or the salvation is much simplier?
 
Old 05-03-2005, 06:32 PM   #2
Matir
LQ Guru
 
Registered: Nov 2004
Location: San Jose, CA
Distribution: Debian, Arch
Posts: 8,507

Rep: Reputation: 128Reputation: 128
Well, I don't think that's so much a security issue with squid as a network-level issue. You could look into a proxy that forces authentication or some such. How do you want to determine who gets through?
 
Old 05-06-2005, 12:55 PM   #3
ivanatora
Member
 
Registered: Sep 2003
Location: Bulgaria
Distribution: Ubuntu 9.10, FreeBSD 7.2
Posts: 459

Original Poster
Rep: Reputation: 32
Authentication based on the host's IP should be simple enough. I tried to restrict a range of acceptable IPs but can't make the acl... I made that thread trying to set that range.
But I'm sure there could be easier way...
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to maximize the security in SQUID depam Linux - Software 1 10-07-2005 09:46 AM
webmin issue, poss security issue bejiita Slackware 3 11-03-2004 06:07 AM
squid strange behavior hlozo Linux - Networking 1 09-20-2004 02:58 PM
Strange SQUID+IPTABLES question yuzuohong Linux - Networking 0 06-09-2002 01:14 AM
Strange Security Log.... bfloeagle Linux - Security 2 05-14-2002 12:37 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Software

All times are GMT -5. The time now is 05:48 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration