I've created this item for the discussion of some of the ramifications of using squid to filter outgoing web traffic from Grex. The last BoD meeting minutes talk about using a seperate system as a sort of bastion host for grex...and then running squid on that system. Theoretically, all outgoing connections would have to be through that system's squid program.14 responses total.
My first thought is this: Who will decide what gets filtered? I would be concerned if there was not at least a written policy regarding only filtering malicious attacks, and not say, "inappropriate" websites.
I'm sure your second thought is how your brain is still reeling from that thought #1.
When Grex was in its previous location, we ran squid. I wasn't involved in either the setup or maintenance of it, so I can't speak from first-hand knowledge, but I believe that it was used to prevent HTTP exploits. That's a reasonable and responsible thing for Grex to do. I'd oppose using it for content filtering.
I wonder why it has to be run on a separate machine.
Steve wants a seperate machine that can act like a firewall. Which would put Grex into its own DMZ. And then if we also ran squid to prevent HTTP exploits, I suppose it would not HAVE TO run on Grex, but could be run on the other machine to free up resources on Grex.
It's not clear to me that grex is resource constrained anymore; at least not as far as things like squid go. What's more, we've already got pf; any firewall configuration *could* be done on a single machine. Whether that's the *best* way to go is debatable, but it is possible.
fwiw - i favor separate b0xen .. always have; always will. live with it.
Boxen? Is that plural for box? Kinda like oxen is plural for Ox? Boss! :)
:) Actually, Boxen is the imaginary country created by C.S. Lewis and his brother as children, combining Animal-Land and India.
re#8 No....it's an english dialect called scripkidiot.
HAHAHAH
re #8 ...yes, plural ... re #10 ... you appear as such a t{xtd0|t .../sigh
/unlucky
TROGG IS DAVID BLAINE
You have several choices: