How to setup proxy server with multiple routes to inet


Recommended Posts

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

pfsense multi wan

http://doc.pfsense.o...N_Version_1.2.x

or cisco rv082 or rv042

http://www.amazon.co...r/dp/B0000ZI1FG

http://www.amazon.co...28239419&sr=1-2

or barracuda link balancer

http://www.barracuda...link_models.php

Not sure if you are going to be able to route specific websites through one link or the other. The barracuda will do ip ranges and subnets, but not specific websites.

thanks for reply's. I had a quick look at them and they seem to offer dual wan or load balancing. I'm more after having a proxy that sits in an office and has a white/allow list. When user A surfs the net the proxy will look at the URL, if it is facebook.com then it will be routed through the local office adsl, if anything else not on the allow list then it gets routed to the main office proxy which is filtered etc.

In theory - you could setup pfSense with squid, and then set the upstream proxy to your office proxy. Once you've got that setup, you can exclude specific IP Addresses from using squid and therefore, making it a direct connection.

I've never tried it and im just guessing...

"I need to route facebook and a few other banned sites to the office ADSL."

Well that could be as simple as telling your browser not to use the proxy for that url/ip

Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

"I need to route facebook and a few other banned sites to the office ADSL." Well that could be as simple as telling your browser not to use the proxy for that url/ip Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

It's transparent. We need for the manager at each location to be able to setup an exclude list (ie; in 1 office they may want people to go to facebook, youtube. In another office they may want filehippo or torrents to be excluded from the proxy). There are literally 200 + pc's or more combined at several locations.

My situation is I can't know in advance what web sites will or won't be included in the proxy exclude list. There are to many ip's for me to manually to enter into the list. I was hoping there was some easy application that by default passes everything through main proxy but I could enter the web sites I want to go directly to the net.

Who controls the proxy? And what proxy is it? Something like websense is easy to manage like this, you create policies. And base on category vs each site. And just have to deal with exceptions to the categories vs each site url.

What proxy / web filtering solution are using?

So what asking them how to help their users -- your all part of the same corp are you not?? Is too much bother.. But trying to circumvent a policy they have in place for the good of all the users is fine??

Creating a policy for managers vs users, or engineers vs hourly is pretty freaking straight forward and one of the main reasons the correct tools are used by corps. Do you think the VIPs of the corp are not going to want to check their fantasy teams?

So you go to a bad blocked site and what happens?? You get nothing telling you its blocked - just does not work? This block page should tell you what they are using. If NOT ASK THEM!!!

Here is some advice, its much more fun to play in the big corp sandbox then your little tiny sandbox!! You are going to be much better off working with corp vs trying to circumvent their policies.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

It would take corporate all of 3 minutes to setup an exclusion for the users. or even the entire subnet range.

In retrospect, its going to take you hours to find a solution, even longer to implement it - and then what happens when you have to support and troubleshoot it? You clearly don't know enough of how routes work to as you've posted here asking how to do it - what happens when it goes down and takes our all internet access? You're in the ****, thats what.

If you're going to do it, do it correctly.

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

You can do it with forefront tmg or isa server. I can help if you want.

It's an assignment. you would think someone would have come up with a program to easily do it. it's not like it's a complex idea.

too hard basket, not going to bother.

Do your homework on your own...

But somebody has come up with a program to do this...It would already be inplace at your 'location' and the change is trivial.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Waymo recalls self-driving software after cars enter closed freeway work zones by Paul Hill Waymo, the self-driving car maker owned by Alphabet – the parent company of Google –, has recalled some of its fifth-generation Automated Driving Systems (ADS). It did so after some of its cars drove through closed construction zones. According to the National Highway Traffic Safety Administration (NHTSA), the affected vehicles were capable of driving through a closed freeway construction zone and continuing to drive at speed. The listing on the NHTSA website says that Waymo is currently developing a solution to fix this issue, but in the meantime, freeway driving is being restricted. Waymo will update its ADS software so that vehicles can detect when they can avoid entering construction zones. According to the Safety Recall Report, on April 20, 2026, Waymo’s Field Safety Committee began meetings reviewing an event from April 11, 2026, and five events from April 19, 2026, where Waymo’s autonomous vehicles didn’t recognize and drove past ramp closure signs into the pre-planned freeway construction zones. This took place in Phoenix, Arizona. Separately, on May 18, 2026, seven Waymo vehicles entered freeway lanes with active construction in the San Francisco Bay Area by driving between cones that were placed to show the lane was closed. On the back of both of these events, Waymo restricted freeway driving until it could address the issue. In June, Waymo’s Safety Board reviewed the issue and additional information related to ADS performances around construction zones; then, as a result, it decided to conduct a recall. This development is not good for Waymo as it adds to a growing list of technical hiccups its cars have experienced. Ultimately, it will lead to more scrutiny from lawmakers around the world who will be more cautious about letting autonomous vehicles on their roads without tighter regulation. For readers in areas where Waymo operates, does this news make you more wary about stepping into one of these vehicles?
    • I'm still on Windows 10 22H2 because I didn't want to deal with all the issues in Windows 11, so I waited almost a week before installing the latest Patch Tuesday update (KB5094127), I went ahead and did it, and it was a huge mistake—ever since then, my File Explorer has seen a performance drop of about 30% when transferring large files... Once again, Microsoft has outdone itself! This update cannot be uninstalled, either through the Control Panel (via Settings) or by accessing Advanced Startup Options. The only possible alternative would be to use system restore points, but I’d have to reinstall all app and driver updates (and there’s no guarantee it would work). Or there’s the “nuclear option” of a in-place repair without losing files or apps, but even then, all my customizations would be lost! Microsoft just can’t help but mess everything up! Way to go, Microsoft! But I still don’t want your c****y Windows 11!
    • Microsoft: Windows 11 could finally solve a major issue across AMD, Nvidia, and Intel GPUs by Sayan Sen While Microsoft has been trying to improve it, Windows 11 is definitely not flawless, as even today some issues are taking a year to publicly acknowledge. However, one area of trouble that may finally see much better results soon is graphics driver crashes. Work on graphics driver timeouts, also called Timeout and Detection Recovery (TDR), is not new as the latest WDDM 3.2 also has specific improvements regarding it. Windows Display Driver Model (WDDM) version 3.2 is supported on Windows 11 24H2 and 25H2. However, with the upcoming version 26H2, TDR crash diagnosis could go to the next level as Microsoft is introducing a new DirectX 12 API feature called "DirectX Dump Files". Similar to how system memory dump files work when a system crashes or freezes or encounters any such major issue, DirectX Dump Files (DDF) will essentially record a snapshot of the GPU execution right at the moment a graphics-related crash or hang or freeze occurs, so that developers can better understand and diagnoze these TDR and timeout detection errors. The dump will be available as a .dxdmp file for analysis and it will be a comprehensive dump file generated with detailed insights about the hardware, drivers, Windows, as well as the affected application. This should be another welcome change in this department. Earlier at GDC 2026, when the technology was first debuted, Microsoft had shared more details regarding it. The company had explained how DDF is designed to gather data from every layer of the graphics stack into a single file, eliminating the need for developers to manually correlate logs from multiple tools. As mentioned above, the dump can contain a lot of useful details like GPU hardware state information such as register values, shader program counters, page fault virtual addresses, shader memory data, and command buffers. Alongside that, it also captures DirectX runtime and kernel information, including D3D objects, pipeline state objects, device error data, adapter details, and CPU call stacks. Microsoft says the feature has been built around two primary use cases: retail device removals and local device removals. The former allows developers to collect crash information from end users' systems in the field, while the latter helps QA teams and developers investigate issues on test machines. Developers will also be able to include up to 2 MB of custom application data through new D3D12 APIs, providing additional context for troubleshooting. In addition, Microsoft is introducing three dump collection modes ranging from zero-overhead capture, which has no runtime performance impact on supported hardware, to higher-detail modes that collect more vendor-specific debugging data. On compatible Tier 2 hardware, zero-overhead dumps will be enabled by default, meaning developers may begin receiving useful crash diagnostics without making any code changes. The table below explains the three tiers: Tier Description NO_OVERHEAD Enables crash capture with no runtime cost and is suitable for broad deployment MEDIUM_OVERHEAD Provides a balance, capturing additional diagnostic data with moderate impact HIGH_OVERHEAD Collects the most detailed GPU and driver state available, enabling deeper investigation at the cost of higher runtime overhead In terms of availability, the company expects broader release to be around the fall of 2026, which should be right around the time when Windows 11 version 26H2 lands. Right now, DirectX Dump Files are available as a preview and currently, only AMD has the compatible AgilitySDK Developer Preview driver version 26.10.07.02. You can find the official announcement post here on Microsoft's website.
    • And with SO much better perf than the laggy mess that is Files.
  • Recent Achievements

    • First Post
      BizSAR earned a badge
      First Post
    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      598
    2. 2
      +Edouard
      190
    3. 3
      PsYcHoKiLLa
      80
    4. 4
      Michael Scrip
      76
    5. 5
      Steven P.
      69
  • Tell a friend

    Love Neowin? Tell a friend!