Monday, September 29, 2014

Transpararent Proxy squid with Juniper SRX

it's working for me

 routing-instances {
squid-vr {
        instance-type forwarding;
        routing-options {
            static {
                route 0.0.0.0/0 next-hop 10.1.2.100;
            }
        }
    }
}
 routing-options {
    interface-routes {
        rib-group inet squid-vr;
    }
    static {
        route 0.0.0.0/0 next-hop 203.161.25.1;

}
    rib-groups {
        squid-vr {
            import-rib [ inet.0 squid-vr.inet.0 ];
        }



Apply to interface


filter tes {
            term squid {
                from {
                    source-address {
                        192.168.103.64/26;
                        192.168.103.128/26;
                        192.168.103.192/26;
                        192.168.104.0/24;
                        192.168.102.0/24;
                        192.168.101.0/24;
                    }
                    destination-address {
                        0.0.0.0/0;
                        192.168.0.0/16 except;
                        10.1.0.0/16 except;
                    }
                    destination-port [ http https ];
                }
                then {
                    routing-instance squid-vr;
                }
            }
            term bypass {
                then accept;
            }
        }
    }

No comments:

Post a Comment