From owner-freebsd-pf@FreeBSD.ORG Wed Jun 21 10:01:54 2006 Return-Path: X-Original-To: freebsd-pf@freebsd.org Delivered-To: freebsd-pf@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 64CAB16A4A7 for ; Wed, 21 Jun 2006 10:01:54 +0000 (UTC) (envelope-from mv@thebeastie.org) Received: from p4.roq.com (ns1.ecoms.com [207.44.130.137]) by mx1.FreeBSD.org (Postfix) with ESMTP id 97C6B43DCB for ; Wed, 21 Jun 2006 10:01:03 +0000 (GMT) (envelope-from mv@thebeastie.org) Received: from p4.roq.com (localhost.roq.com [127.0.0.1]) by p4.roq.com (Postfix) with ESMTP id E355F4CD35 for ; Wed, 21 Jun 2006 10:01:21 +0000 (GMT) Received: from vaulte.jumbuck.com (ppp166-27.static.internode.on.net [150.101.166.27]) by p4.roq.com (Postfix) with ESMTP id 8795B4C973 for ; Wed, 21 Jun 2006 10:01:21 +0000 (GMT) Received: from vaulte.jumbuck.com (localhost [127.0.0.1]) by vaulte.jumbuck.com (Postfix) with ESMTP id 0BCE78A029; Wed, 21 Jun 2006 20:00:59 +1000 (EST) Received: from [192.168.46.102] (unknown [192.168.46.250]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by vaulte.jumbuck.com (Postfix) with ESMTP id F38CC8A023; Wed, 21 Jun 2006 20:00:58 +1000 (EST) Message-ID: <449918DA.1060308@thebeastie.org> Date: Wed, 21 Jun 2006 20:00:58 +1000 From: Michael Vince User-Agent: Mozilla/5.0 (X11; U; FreeBSD amd64; en-US; rv:1.7.12) Gecko/20060404 X-Accept-Language: en-us, en MIME-Version: 1.0 To: "roma.a.g" References: <1559453030.20060621131054@gmail.com> In-Reply-To: <1559453030.20060621131054@gmail.com> Content-Type: text/plain; charset=us-ascii; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: ClamAV using ClamSMTP X-Virus-Scanned: ClamAV using ClamSMTP Cc: freebsd-pf@freebsd.org Subject: Re: transparent proxy on bridge X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 21 Jun 2006 10:01:54 -0000 Roman Gorohov. wrote: >Hello list. >I'm planning to configure pf in bridged environment(using if_bridge on 6.1), >so I have question if transparent proxy will work? >Is the any working config, or some known issues? > >TIA, Roman Gorohov. > >_______________________________________________ > > What kind of transparent proxy are we talking here, web? I guess most people would recommend squid, Out of interest I tested out the new proxy modules for Apache 2.0 and 2.2 as a proxy and it does work quite well, has a fair amount of options for cache size and what types to cache and expire. My main aim for it was just to run it in the office for a while and have a strict rule to just cache stuff over 1 meg or larger. To me it seems silly and a waste of cpu / hd / io on the proxy server if you bother caching 10k files while everyone in the office is downloading open office and firefox all day. I would of liked to try it in production if I could figure out how to run it transparently let alone for a bridge, but I couldn't quite get there. Mike