Mikrotik with external proxy
BETA Testing and Feature Suggestions for the next RouterOS release (ROS v7)

8 posts   •   Page 1 of 1
alessio
newbie
 
Posts: 36
Joined: Fri Jan 11, 2008 2:30 pm

Mikrotik with external proxy

by alessio » Tue Jan 22, 2008 8:36 pm

Good evening,
I'm trying to setup my hotspot to use an external proxy server because of I need to log every single internet connection for every single user and than I'm using squid proxy server to do this.

The problem is that if I set the Webproxy feature on MTbox what I get is that every request made by any user is passed to squid with the MTbox address and it is not ok for me.
The hotspot is not masquerading any addresses, but even if I set just the parent-proxy address and the trasparent proxy feature, I get the same behaviour.

Is there a way to redirect every connection to an external proxy server maintaining the original IP address?

Regards,
Alessio

User avatar
janisk
MikroTik Support
MikroTik Support
 
Posts: 5925
Joined: Tue Feb 14, 2006 10:46 am
Location: Riga, Latvia

Re: Mikrotik with external proxy

by janisk » Wed Jan 23, 2008 10:29 am

you can set up dstnat rule that will forward requests to your proxy without parent proxy feature.

the rule will look like this

Code: Select all
add action=dst-nat chain=dstnat comment="" disabled=no dst-port=80 protocol=tcp to-addresses=<proxy address> to-ports=<proxy port>


if proxy can reach client then client will have "transparent proxy" and will see who is requesting pages.

alessio
newbie
 
Posts: 36
Joined: Fri Jan 11, 2008 2:30 pm

Re: Mikrotik with external proxy

by alessio » Wed Jan 23, 2008 2:05 pm

Hello Janisk,
thanks for your answer.
I already had tried with that configuration without success, but today I discovered that there was a configuration problem on my squid proxy server, because of upgrading it from version 2.5 to version 2.6 it changed the syntax on squid.conf file about the transparent proxy feature.

With squid proxy port=8080, and squid 2.5 version we need the following configuration:
http_port 8080
httpd_accel_host virtual
httpd_accel_port 80
httpd_accel_with_proxy on
httpd_accel_uses_host_header on

in squid 2.6 version the following command is enough:
http_port 8080 transparent

and the other commands are not recognized.

Thanks,
Alessio

User avatar
normis
MikroTik Support
MikroTik Support
 
Posts: 19325
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Mikrotik with external proxy

by normis » Wed Jan 23, 2008 2:09 pm

so now it works?
No answer to your question? How to write posts

alessio
newbie
 
Posts: 36
Joined: Fri Jan 11, 2008 2:30 pm

Re: Mikrotik with external proxy

by alessio » Wed Jan 23, 2008 11:43 pm

Hello Normis,
I confirm, now it's working and I can log every connection made everywhere in the network.

To optimize the network, instead of setting the nat rule on every Mikrotik router we set it just on the firewall of all our network.

Regards,
Alessio

alex998r
Frequent Visitor
Frequent Visitor
 
Posts: 91
Joined: Sun Jan 07, 2007 11:54 pm

Re: Mikrotik with external proxy

by alex998r » Sat Mar 01, 2008 3:56 pm

Hi Alessio, I am interested in your setup to track all sites. Please can you draw your setup here or explain in more depth your scenario?
Ciao
Alessandro - Roma
p.s if you want you can send a pm alex998r at tiscali.it

zerocool86
just joined
 
Posts: 22
Joined: Thu May 25, 2006 2:35 pm

Re: Mikrotik with external proxy

by zerocool86 » Sun Mar 02, 2008 3:13 pm

here interested too... daloia@mobida.it

Francesco

onowojemma
Member Candidate
Member Candidate
 
Posts: 129
Joined: Sun Sep 11, 2005 5:27 pm
Location: Nigeria

Re: Mikrotik with external proxy

by onowojemma » Sat Mar 22, 2008 11:23 pm

Hi Alessio,
i enjoy reading ur post pls can i have a simple diagram of how it look like and the needed config on ur squid box.
better still u could mail it to my mailbox onowojemma[at]yahoo.com.
Thanks for the nice post
Mikrotik! making networking easy

8 posts   •   Page 1 of 1

Who is online

Users browsing this forum: Google Feedfetcher and 15 guests

It is currently Thu Dec 18, 2014 5:21 am