Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > comp.os.linux.networking > #509
| Date | 2011-08-24 12:50 +0200 |
|---|---|
| From | David Brown <david@westcontrol.removethisbit.com> |
| Newsgroups | comp.os.linux.networking |
| Subject | Re: Squid |
| References | <201108230405.UTC.j2v8tc$sh7$1@tioat.net> <877h64y02y.fsf@araminta.anjou.terraraq.org.uk> <201108231605.UTC.j30j4r$9gc$1@tioat.net> <sYadnbzfROjNYM7TnZ2dnUVZ8hCdnZ2d@lyse.net> <201108240506.UTC.j320sd$m43$1@tioat.net> |
| Message-ID | <sfSdnbUSEOwARcnTnZ2dnUVZ8n2dnZ2d@lyse.net> (permalink) |
On 24/08/2011 07:07, woody wrote: >>> >> >> That must have been a particular server or provider that was being >> discontinued - Usenet is very much alive. > > That is good news :) because I find forums to be a pain. There is no > central conact for finding them > and google doesn't always help. >> >> You won't find a newsgroup for squid-on-windows, since very few people > > I was looking for someone to help me get squid configured.. > The main configuration for squid is in a single configuration file, and the default example is reasonably configured. It also has plenty of comments making it simple to change. If you want to set up something more complicated, like a transparent proxy, then you will have a bigger challenge with windows - I have no experience with that. > >> >>> The reason I am stuck with XP Pro among other things, is the fact that >>> the >>> computer I got for the school came with XP PRO and a legal license for >>> it. > > It may not be a good choice. I've been the IT manager for our company (12 > people) since 2005 > and run an all ms network. Vista is so bad that I won't even allow a vista > machine on the network. > The filtering software of choice, Net Nanny does not run under linux, so > even if I were a linux guru, > I'd still have to deal with it under Windows. The only reason I did not > scrub XP and install Windows 2000 server is that part of the school > certification requies that all software on school computers has a legal > license, and the license I have for 2000 server is a dev license. Of all windows versions, XP is the best choice (or W2K if it supports the software you need). I think the main confusion here is that I assumed you were wanting to set up a machine as a router/firewall/gateway and install squid on it as a caching proxy. But now it seems you want to install this on a desktop machine that is otherwise in use by a teacher - contrary to all standard practices for reliable and secure networking. >> > >> Linux users - people here will recommend Linux because it is /better/ for >> jobs like this, not because it is free. >> >>> It is an older Dell. Yes linux is free and all that, but I don't have the >>> time to deal with a learning curve for Linux, get the school set up and >>> keep up with everything I have to. >>> >> >> As I said in my other post, it will be quicker to learn Linux first that >> to figure out how to make XP into a secure router and proxy. > > Well I don't know. I've struggled through several linux installs and > attempts to really work with it > and finally gave up. I've installed mandrake 8.2, redhad 7.7, suse 8.x among > others over the years, but networking is a nightmare on them. When I was > setting the company network up, I tried Trustix for the firewall, > smoothwall, and a couple other distros and never did get them working right, > so I threw up my hands and bought a Servegate which does run a version of > linux. > > We got an internal use license through the microsoft partner program for > windows 2000 and I set the company up on that, later migrating to windows > 2003. > > The learning curve for linux is years literally. Installing a modern Linux distribution takes a few hours for someone who has only a vague idea about Linux, but is willing to try (the Linux world has moved on over the years). Learning to set up a secure network and get the routing, DNS, firewall, etc., etc., in place takes time regardless of the systems you want to use. > >> >> But as another poster suggested, your easiest solution is to install a >> router-oriented Linux distribution such as Smoothwall >> <http://www.smoothwall.org/>. For a simple setup like yours, it really is >> a no-brainer. It's barely more difficult than downloading and installing >> a program in Windows, and it handles all the squid setup for you with a >> simple web interface. > > That would require reformatting and wiping out XP Pro, voiding the warrantee > on the box, > and that is something I don't want to do at this time. > >> >> >> I realise what you are asking - but you are asking for the wrong thing. > > Wrong or no, it is the only path I can go down right now. The internet > protection software we have > to use does not run under linux. I doubt it will run under wine on linux. The "internet protection software" you have there is a client-side program, AFAIK - you run it on the desktop and not on the server/router machine. On the router, you would do your filtering by using OpenDNS as the DNS server with options to block all unwanted sites - it is much simpler, much faster, and much cheaper than Net Nanny, and much harder for enterprising students to work around. You could even install DansGuardian for extra protection. It's a matter of choosing the /right/ software, and putting it in the /right/ place in the network. Of course, if you are obliged by outside forces to use a particular OS on the machine, or particular software, then all I can offer you is my sympathies. > In addition to acting as a > web filter, it has to host several administrative programs and educational > software, none of which runs under linux. Those are client software apps, that don't belong on a router/gateway/proxy. If those apps run on Windows, run them on a Windows desktop - not on part of your network infrastructure. > Not to mention that the teacher > has her hands full and doesn't have the time to > learn openoffice etc. The other wrinkle is that the school is part of the > Seventh-day Adventist school system, and they have a low cost educational > license program for microsoft stuff. > It doesn't matter how low a price you get for MS stuff if there are free alternatives that are better! But again, you don't run office programs on network infrastructure machines. >> >> Note that this is not blind fanaticism (though there are fanatics in this >> newsgroup, as with many such groups). > > Grin. > > I use Windows as well as >> Linux, and there are many area of use where Windows is a better choice. >> But for this sort of use, Linux is far and away the better choice - so >> much so that it is worth it even if you are not very familiar with Linux. > > If this were a dedicated machine just for this purpose, well I'd agree. > But it isn't and I don't have another reliable machine to use, especially > one that is fast enough to > be useful. I have a couple old 600 mhz pavilions, but those are so long in > the teeth that it would be > a nightmare. > 600 MHz is lots more power than you need to run squid and a firewall/gateway/proxy with Linux, unless you have very high bandwidth lines (say 30+ Mbps). At that age, I'd guess you have 256MB ram, which again is plenty (though more would be useful if you can easily add it). When you are only running a few specific non-gui tasks, you don't need a lot of horsepower with Linux. I've set up file servers on old Pentium 90 machines that do a perfectly good job, and I've just recently set up a firewall/router using Linux on a wireless router with 150 MHz cpu and 16 MB ram (no squid, however) - it's fine for a 20 Mbps internet connection. >> gmane mirrors mailing lists as newsgroups. Some are mirrored with posting >> privileges, some just read-only. If you think that mailing list might be >> useful, then join the mailing list rather than using gmane > > I have done that. > >> (though gmane is great for looking at the archives). >> >> >> You don't have to make mount points to access a shared disk if you don't >> want to - Gnome and KDE both give you direct access to Windows shares (or >> samba shares from Linux servers) from within their file managers > > The last time I tried to use Gnome and KDE was either on Fedora core 3 or > suse 8.3 back in 2005 > and the only way to browse the shares on a network and connect to them was > to use linneighborhood, and then you had to go and actually create a mount > point, after browsing > Life has moved on in the last 6 years in the Linux world... If you have the time, I'd recommend trying a copy of Linux Mint (run it from a live CD). >> creating the mount points on the fly. But mount points is the way Linux >> (like all *nix systems) handles multiple file systems. > > and the way Windows does too, just that it is normally so well hidden and > integrated that you > don't even know it. They have another name for them. > Yes, I know how it works on Windows - it's not the same (though I agree there are more similarities if you dig into the hidden details). >> >> Personally, I would much prefer if Windows supported the Linux way of >> dealing with mounting shares. I find it a huge inconvenience in my job >> (which includes being the IT manager of my company) that Windows won't >> allow you to connect multiple times to the same server with different >> usernames, as Linux allows. > > You mean from the same machine to multiple shares on the server. No, I mean multiple connections from the same machine to the same share on the server, but with different user names and passwords. For example, when someone complains they can't access the files they need on the server, I have to be able to log into that share on the server using their username to confirm the problem. I also have different usernames for myself on the servers - one "normal" username with everyday privileges, and one "super" username with access to lots more, which I only use if needed (to avoid risking accidents). > > That is a huge headache and security hole for certain Why microslut did it > that was is beyond me. To get around that I had to violate my own security > protocol and install batch files that mapped with the administrator password > for the server. > Fortuantly the people in the company are clueless about that, and are > explicityly trusted, so it has worked o.k., but gives me the willies..... > > The workaround, to get good access to >> windows shares on a windows computer, is to use a port of the Linux >> smbclient program running on Windows. > tell me more about this... > You can get it from here (there are probably other builds lying around the net) : <http://leecutsco.de/lpackham/smbclient/> It's a command line program, similar to ftp. >> >> And of course there are always different ways to do this sort of thing on >> Linux. In particular, you can use "autofs" to make a single mount point >> that you can then use for all your windows share mounts - they will be >> mounted automatically when you try to use them. >> >> >> . I am simply recommending you switch to Linux for your caching proxy >> server and router. It won't be accessing any windows shares, so you have >> no problem there. > > It would absolutely have to access windows shares. > The box has to eventualy scan the laptops, backing them up. > That's the wrong box - backup is not part of your network routing infrastructure. Of course, using Linux as a backup server is also possible (and normally a good choice) - accessing windows shares from Linux is not hard. > Do I have to have a resident router to use squid on the same box? The > router is a firewall router for the internet. > > The ultimate goal, is that the administrator can set down at the xp box and > brows the 0.1 network and internet un filtered, and uncached. But the > students have to go through the cache and filter, and cannot get the the > internet filter/router directly because it is on a different subnet. Give the teacher a desktop PC connected to the main network, which has your current internet firewall/router. Setup a /dedicated/ box (such as one of your old 600 MHz machines) to act as a gateway between the student's network and the main network. > XP PRO can be made to act as a router. Yes, in the same way that Paris Hilton can be made to act. > I found this newgroup echoed over in > www.network-builders.com/squid-t109049.html and attempted to sign up for > that forum, but got tagged as a spammer during the sign up. > > So if you know anyone who can help me configure squid under XP I would like > a pointer to the person or resource. > > I would be happe to post the config file with all the comments stripped. > I wish you luck on your task. It sounds like you are fixed (partly by choice, partly by outside forces) on a solution that will be hard to implement and will not work reliably or securely. I'm sorry I can't give you any specific help with squid on windows.
Back to comp.os.linux.networking | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Squid "woody" <tossit1@Use-Author-Supplied-Address.invalid> - 2011-08-22 23:06 -0500
Re: Squid Dan C <youmustbejoking@lan.invalid> - 2011-08-23 04:24 +0000
Re: Squid David Brown <david@westcontrol.removethisbit.com> - 2011-08-23 08:45 +0200
Re: Squid Richard Kettlewell <rjk@greenend.org.uk> - 2011-08-23 10:00 +0100
Re: Squid "woody" <tossit1@Use-Author-Supplied-Address.invalid> - 2011-08-23 11:06 -0500
Re: Squid David Brown <david.brown@removethis.hesbynett.no> - 2011-08-23 21:19 +0200
Re: Squid "woody" <tossit1@Use-Author-Supplied-Address.invalid> - 2011-08-24 00:07 -0500
Re: Squid David Brown <david@westcontrol.removethisbit.com> - 2011-08-24 12:50 +0200
Re: Squid KR <kristian.rasmussen@broadpark.no.spam.com> - 2011-08-25 03:28 +0200
Re: Squid David Brown <david@westcontrol.removethisbit.com> - 2011-08-25 07:37 +0200
csiph-web