How to setup proxy server with multiple routes to inet


Recommended Posts

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

pfsense multi wan

http://doc.pfsense.o...N_Version_1.2.x

or cisco rv082 or rv042

http://www.amazon.co...r/dp/B0000ZI1FG

http://www.amazon.co...28239419&sr=1-2

or barracuda link balancer

http://www.barracuda...link_models.php

Not sure if you are going to be able to route specific websites through one link or the other. The barracuda will do ip ranges and subnets, but not specific websites.

thanks for reply's. I had a quick look at them and they seem to offer dual wan or load balancing. I'm more after having a proxy that sits in an office and has a white/allow list. When user A surfs the net the proxy will look at the URL, if it is facebook.com then it will be routed through the local office adsl, if anything else not on the allow list then it gets routed to the main office proxy which is filtered etc.

In theory - you could setup pfSense with squid, and then set the upstream proxy to your office proxy. Once you've got that setup, you can exclude specific IP Addresses from using squid and therefore, making it a direct connection.

I've never tried it and im just guessing...

"I need to route facebook and a few other banned sites to the office ADSL."

Well that could be as simple as telling your browser not to use the proxy for that url/ip

Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

"I need to route facebook and a few other banned sites to the office ADSL." Well that could be as simple as telling your browser not to use the proxy for that url/ip Are you using a explicit browser setup, ie do your browsers point to the proxy at the head office or use a pac file to get pointed to it? Or is it a transparent setup where you default route for internet traffic it to the head office and use the proxy with no setup on your browser?

It's transparent. We need for the manager at each location to be able to setup an exclude list (ie; in 1 office they may want people to go to facebook, youtube. In another office they may want filehippo or torrents to be excluded from the proxy). There are literally 200 + pc's or more combined at several locations.

My situation is I can't know in advance what web sites will or won't be included in the proxy exclude list. There are to many ip's for me to manually to enter into the list. I was hoping there was some easy application that by default passes everything through main proxy but I could enter the web sites I want to go directly to the net.

Who controls the proxy? And what proxy is it? Something like websense is easy to manage like this, you create policies. And base on category vs each site. And just have to deal with exceptions to the categories vs each site url.

What proxy / web filtering solution are using?

So what asking them how to help their users -- your all part of the same corp are you not?? Is too much bother.. But trying to circumvent a policy they have in place for the good of all the users is fine??

Creating a policy for managers vs users, or engineers vs hourly is pretty freaking straight forward and one of the main reasons the correct tools are used by corps. Do you think the VIPs of the corp are not going to want to check their fantasy teams?

So you go to a bad blocked site and what happens?? You get nothing telling you its blocked - just does not work? This block page should tell you what they are using. If NOT ASK THEM!!!

Here is some advice, its much more fun to play in the big corp sandbox then your little tiny sandbox!! You are going to be much better off working with corp vs trying to circumvent their policies.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

I have approval from the higher up to do it, without going into who I work for I'll just say that I work for a giant corp with literally 10,s of thousands of pc's (gov). There is not a snow flakes chance of me getting them to fiddle with their corp proxy which handles a massive gov department just so I can get a few (small) government branches their own ADSL access to circumvent corp proxy. (the place I work in only has 50-100 pc's)

Like I said, I have permission. I just can't involve corp office as they would be pretty busy I imagine.

There are 2 branches I deal with. Each branch has 50-100 pc's. The Government has given me permission to do it lol but they want by default all traffic to go through their corp proxy (makes sense as they after all need to control who is going where and doing what on the net), however, the Government has put in place managers at each branch who have the authority to put on ADSL but I need to control the handful of sites that are put on the allow list.

Like I said, I have permission, it's perfectly legit. However it isn't a fundamental requirement that ADSL be in place, just that these 2 managers have decided and got approval to have their own ADSL as long as the managers supervise usage.

I can't involve corp as I'm sure they have better things to do with managing a massive system and don't have the time to ass about with me and 2 managers so we can add sites like facebook, youtube , and a dozen other such sites to exlude lists. Also, the exclude list is likely to grow at the managers whims and I'm certain corp won't appreciate me emailing them every week with an updated list for them to add to the proxy that only affects my 2 branches.

So you see my predicimate and why I am here.

It would take corporate all of 3 minutes to setup an exclusion for the users. or even the entire subnet range.

In retrospect, its going to take you hours to find a solution, even longer to implement it - and then what happens when you have to support and troubleshoot it? You clearly don't know enough of how routes work to as you've posted here asking how to do it - what happens when it goes down and takes our all internet access? You're in the ****, thats what.

If you're going to do it, do it correctly.

I need to setup a proxy server that has 2 routes to the internet.

by default I want all users to be routed to a proxy server at main office. the main office proxy does all the web filtering etc. On the main office proxy they block facebook etc., but in 1 or 2 branch offices I need to route facebook and a few other banned sites to the office ADSL.

Can ISA or Forefront do this, or do I need a 3rd party program?

You can do it with forefront tmg or isa server. I can help if you want.

It's an assignment. you would think someone would have come up with a program to easily do it. it's not like it's a complex idea.

too hard basket, not going to bother.

Do your homework on your own...

But somebody has come up with a program to do this...It would already be inplace at your 'location' and the change is trivial.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • BrowserOS 0.46.0 by Razvan Serea BrowserOS is a free, open-source Chromium-based browser that runs AI agents natively, offering a smarter, more productive browsing experience. It supports Chrome extensions and integrates AI agents to automate tasks, fill forms, and streamline workflows. Your data stays on your computer: you can use your own API keys or run local models via Ollama, making it a privacy-first alternative to tools like Perplexity, Comet, or Dia. With built-in productivity tools and app integrations, BrowserOS boosts efficiency while keeping control firmly in your hands. Being Chromium-based, BrowserOS lets you effortlessly import your bookmarks, passwords, and Chrome extensions in just a few clicks. BrowserOS works with OpenAI GPT models, Anthropic Claude, Google Gemini, and local AI models via Ollama or LMStudio. You can use your own API keys and effortlessly switch between providers. BrowserOS Agent Your AI productivity assistant that organizes and manages your browsing effortlessly Quickly list, group, or close tabs Save and resume browsing sessions Search your history and organize bookmarks Switch instantly to the tab you need BrowserOS Navigator – Automate web tasks with ease Navigate websites and search automatically Interact with pages without manual effort Handle repetitive tasks in seconds What makes BrowserOS special Feels like home - same familiar interface as Google Chrome, works with all your extensions AI agents that run on YOUR browser, not in the cloud Privacy first - bring your own keys or use local models with Ollama. Your browsing history stays on your computer Open source and community driven - see exactly what's happening under the hood MCP store to one-click install popular MCPs and use them directly in the browser bar (coming soon) Built-in AI ad blocker that works across more scenarios! BrowserOS 0.46.0 changelog: Run Claude Code & Codex right in your browser — We've extended the agent harness to bring full coding agents into BrowserOS. Claude Code and Codex now come bundled and plug straight into the assistant, so you can drive your browser with the agent — and the subscription — you already use. A brand new experience — A redesigned new tab, a calmer composer, and a rebuilt command center for switching between agents. The whole assistant is cleaner, faster to reach, and easier to live in. New MCP tools — We rebuilt the browser tool surface from the ground up — a tighter, more reliable set of tools for agents to drive the browser. Plus one-click install of BrowserOS as an MCP server into the agents you already run, with automatic URL sync. Chromium 148 — Updated to the latest Chromium base with all recent upstream fixes and security patches. Streamlined — We've pulled back a few features that weren't getting much use — Skills, Soul, and Memory — so we can focus and ship better versions of them soon. Download: BrowserOS 0.46.0 | 181.0 MB (Open Source) Download: BrowserOS for macOS | 485.0 MB Links: BrowserOS Homepage | Github | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Microsoft finally admits its default Windows 11 25H2, 24H2 action broke key legacy component by Sayan Sen Microsoft last week released Windows 11 KB5094126 and KB5093998 as the latest Patch Tuesday updates. Following that the company also published the accompanying dynamic updates under KB5094149, KB5095971, and KB5094156. So far the company has acknowledged two known issues that have popped up after the release which include bugged-out Office apps as well as the Recycle Bin; though there could be more at play too. Speaking of bugs and issues, Microsoft seems to have finally acknowledged a problem that probably has been around for close to a year. That's because back in July of 2025 the company made a default change to the latest Windows 11 versions, wherein it switched to JScript9Legacy on Windows 11 24H2 and later releases. Hence following the release of version 25H2 in October 2025, JScript9Legacy also remained default-enabled. As a result there has been a compatibility issue ever since then. For those wondering, by switching to JScript9Legacy Microsoft intended to improve the security of modern Windows PCs by reducing vulnerabilities tied to legacy scripting like cross-site scripting (XSS), among others. XSS exploits can allow cyber-attackers to attach malicious code onto legitimate websites and use them to execute the code when a potential victim loads such a website. Hence the new JScript9Legacy engine enforced stricter execution policies and improved object handling, which should help mitigate such attacks. Microsoft today has published a new support article detailing the problem. Neowin spotted it while browsing. The company says that JScript global definitions and execution context may fail to persist across scripts, potentially breaking older dependent apps and web-based components that relied on this legacy behavior. In the article Microsoft has confirmed that the issue stems from its move away from the older jscript9.dll engine in favor of jscript9legacy.dll. As mentioned above, while the newer engine was designed to address vulnerabilities and strengthen security it also changes how JScript handles execution context. As a result functions and definitions loaded by one script could no longer remain available to subsequent scripts once execution ended. The company notes that some applications worked correctly on earlier Windows versions because the older JScript engine automatically retained global definitions and execution state between scripts. Under the newer model though that behavior is disabled by default causing certain legacy workloads and polyfill-dependent scripts to fail. Microsoft says it addressed the problem via the KB5077241 update though the fix had not been enabled automatically in the following updates. As such admins must explicitly turn on persistent JScript execution context using a Registry setting that the tech giant shared today. The configuration can be applied to individual processes or system-wide through the FEATURE_ENABLE_PERSISTENCE registry key. The steps have been outlined below: Run the following command to create the feature control registry key: reg add "HKLM\Software\Policies\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_ENABLE_PERSISTENCE" Under this key, create a new DWORD (32-bit) value. Configure the value as follows: To enable persistence for specific processes only: Set the value to 1 for each target process name. To enable persistence for all processes: Add * as the key name and set its value to 1. You can find the official support article here on Microsoft's website.
    • The possibility that milk gathers back into a glass implies that gravity can be 'reversed'.
  • Recent Achievements

    • Week One Done
      Jordan Smith earned a badge
      Week One Done
    • Reacting Well
      BizSAR earned a badge
      Reacting Well
    • First Post
      AndreaB earned a badge
      First Post
    • Week One Done
      Huge Trailer earned a badge
      Week One Done
    • Week One Done
      Classifyskilleducation earned a badge
      Week One Done
  • Popular Contributors

    1. 1
      +primortal
      590
    2. 2
      +Edouard
      186
    3. 3
      PsYcHoKiLLa
      76
    4. 4
      Michael Scrip
      73
    5. 5
      Steven P.
      66
  • Tell a friend

    Love Neowin? Tell a friend!