How to setup proxy server with multiple routes to inet


Recommended Posts

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

pfsense multi wan

http://doc.pfsense.o...N_Version_1.2.x

or cisco rv082 or rv042

http://www.amazon.co...r/dp/B0000ZI1FG

http://www.amazon.co...28239419&sr=1-2

or barracuda link balancer

http://www.barracuda...link_models.php

Not sure if you are going to be able to route specific websites through one link or the other. The barracuda will do ip ranges and subnets, but not specific websites.

thanks for reply's. I had a quick look at them and they seem to offer dual wan or load balancing. I'm more after having a proxy that sits in an office and has a white/allow list. When user A surfs the net the proxy will look at the URL, if it is facebook.com then it will be routed through the local office adsl, if anything else not on the allow list then it gets routed to the main office proxy which is filtered etc.

In theory - you could setup pfSense with squid, and then set the upstream proxy to your office proxy. Once you've got that setup, you can exclude specific IP Addresses from using squid and therefore, making it a direct connection.

I've never tried it and im just guessing...

"I need to route facebook and a few other banned sites to the office ADSL."

Well that could be as simple as telling your browser not to use the proxy for that url/ip

Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

"I need to route facebook and a few other banned sites to the office ADSL." Well that could be as simple as telling your browser not to use the proxy for that url/ip Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

It's transparent. We need for the manager at each location to be able to setup an exclude list (ie; in 1 office they may want people to go to facebook, youtube. In another office they may want filehippo or torrents to be excluded from the proxy). There are literally 200 + pc's or more combined at several locations.

My situation is I can't know in advance what web sites will or won't be included in the proxy exclude list. There are to many ip's for me to manually to enter into the list. I was hoping there was some easy application that by default passes everything through main proxy but I could enter the web sites I want to go directly to the net.

Who controls the proxy? And what proxy is it? Something like websense is easy to manage like this, you create policies. And base on category vs each site. And just have to deal with exceptions to the categories vs each site url.

What proxy / web filtering solution are using?

So what asking them how to help their users -- your all part of the same corp are you not?? Is too much bother.. But trying to circumvent a policy they have in place for the good of all the users is fine??

Creating a policy for managers vs users, or engineers vs hourly is pretty freaking straight forward and one of the main reasons the correct tools are used by corps. Do you think the VIPs of the corp are not going to want to check their fantasy teams?

So you go to a bad blocked site and what happens?? You get nothing telling you its blocked - just does not work? This block page should tell you what they are using. If NOT ASK THEM!!!

Here is some advice, its much more fun to play in the big corp sandbox then your little tiny sandbox!! You are going to be much better off working with corp vs trying to circumvent their policies.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

It would take corporate all of 3 minutes to setup an exclusion for the users. or even the entire subnet range.

In retrospect, its going to take you hours to find a solution, even longer to implement it - and then what happens when you have to support and troubleshoot it? You clearly don't know enough of how routes work to as you've posted here asking how to do it - what happens when it goes down and takes our all internet access? You're in the ****, thats what.

If you're going to do it, do it correctly.

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

You can do it with forefront tmg or isa server. I can help if you want.

It's an assignment. you would think someone would have come up with a program to easily do it. it's not like it's a complex idea.

too hard basket, not going to bother.

Do your homework on your own...

But somebody has come up with a program to do this...It would already be inplace at your 'location' and the change is trivial.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Build your own business with a Sellful lifetime plan now at 76% off by Steven Parker Today's deal from our Apps + Software section of the Neowin Deals store, lets you save 76% off Sellful: ERP Agency Plan lifetime deal. AI-Powered Software and Website Builder for Agencies Ever feel like a client’s needs simply can’t be met on a single platform? With Sellful, it’s all here, and all white labeled. Build anything from simple websites to complex workflows to automate your business in a few clicks. Manage everything from email & social media marketing, to payroll & invoicing. It’s got a white label website builder, online shop, CRM, ERP, marketing, memberships, invoicing, appointments, online courses, project manager, and point of sale functions. Sellful is the only white label platform in the world that is truly all in one, combining all aspects of your business in one place no matter the industry. What can you do with Sellful? Automatically generate amazing websites, funnels, & landing pages in seconds using AI Sell physical & digital products online Keep track of customers with native CRM Automate communication & outreach using AI Manage all aspects of your business in one place Collect emails & phone numbers via forms on your website, then send newsletters to customers with important updates, sales, and discounts Build membership programs with various levels of access for your customers Receive payments from your clients using any number of payment gateways including Paypal, Stripe, Authorize.net, Square & more Have your clients book appointments for services & meetings quickly Build powerful & robust online courses to sell to or instruct people Build communities on Sellful social networking sites with activity feeds, private messaging, & groups See & adjust a visual version of everything going on within your client projects Sync your online shop’s inventory with multiple offline store locations & registers Manage inventory, coupons, & sales through Sellful’s native POS app on your computer Manage employee recruitment, time clocks, payroll & leave requests Automate help desk tasks such as support ticket creation Communicate with your team on multiple chat channels Keep an accounting of your income & expenses Automate billing & website creation for your marketing agency What's in the ERP Agency Plan: White Label Unlimited 10 Sites/Sub Accounts Included 100% White Label For Your Brand Or Your Client's Brand Website Builder Sales Funnel Builder Online Shop Automation Builder CRM & Pipeline Management Email Marketing SMS Marketing Reputation Management 2 Way Communication (Email, SMS & Phone) Appointment Scheduler Memberships Subscriptions Forms, Surveys & Polls Client Portal AI Assistant & Chatbot Social Media Automation Legally Binding Contract Signing Project Management System Online Courses (LMS) Invoicing External CRM Connect Class Attendance & Event Booking Restaurant Builder Support Ticket System Team Chat AliExpress Drop Shipping Accounting Advanced Affiliate Program Community Builder Point Of Sale HR Suite (HR, Time Clock, Payroll & ATS) 5000+ App Integrations 20+ Payment Gateways (No Fees From Us) Custom Mobile App Agency Billing System Setup Wizard Builder Content Cloner Tool Digital Marketing Courses Actionable Marketing PDF Guides Unlimited Contacts Per Site/Sub Account Unlimited Pages Per Site/Sub Account Unlimited Blog Posts Per Site/Sub Account Unlimited Users Per Site/Sub Account Unlimited Products Per Site/Sub Account Unlimited Visitors Per Site/Sub Account 100 Gigs Of File Storage 50,000 Free Email Sends* Unlimited Domain Names Per Site/Sub Account *Email sending can be purchased in packs of 10,000 for $10/Month. You can also add your own external sending service to send without limits. Email sends are shared in a pool throughout all websites and email addresses on the account. System emails are always free. Good to know Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Updates included Sellful: ERP Agency Plan (Lifetime) normally costs $1,497 but it can be yours for only $349.97, that's a saving of $1,147.03 (76%) off! For terms, and more details click the link below. Get a lifetime plan to Sellful at 76% off (was $1,497) Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
    • No its not, there are ton of Youtube videos to get you started, what do you think people did before AI existed?
    • Read this in Humor Simpson 's voice, "Out of my way Moe".
  • Recent Achievements

    • One Year In
      B4dM1k3 earned a badge
      One Year In
    • One Year In
      DarkWun earned a badge
      One Year In
    • Dedicated
      Almohandis earned a badge
      Dedicated
    • Dedicated
      JuvenileDelinquent earned a badge
      Dedicated
    • First Post
      DrWankel earned a badge
      First Post
  • Popular Contributors

    1. 1
      +primortal
      506
    2. 2
      +Edouard
      181
    3. 3
      PsYcHoKiLLa
      86
    4. 4
      Michael Scrip
      78
    5. 5
      Steven P.
      76
  • Tell a friend

    Love Neowin? Tell a friend!