I
I
ivanusevanton2019-12-21 10:48:48
linux
ivanusevanton, 2019-12-21 10:48:48

How to distribute proxy internet through NAT?

The organization has 2 providers: one without a filter, the second with a filter. The Internet from the first is distributed by standard means of windows server 2008 through NAT. Actually a question on the second. Since Internet access with a filter works through a proxy + crt certificate, the question arises how to distribute it in the same way as the first one? After reading various manuals, I assume that this cannot be implemented using windows tools. It is possible to implement it more precisely, but with crutches (you will need to install a certificate on each user's computer + specify a proxy in the settings), which is quite difficult to do with a large number of computers. I think in the direction of vbox + linux, but is there a possibility of distributing this connection in this idea? There may be other ways that I don't know about. Thanks in advance for your help.

Answer the question

In order to leave comments, you need to log in

3 answer(s)
A
akelsey, 2019-12-23
@ivanusevanton

Your question is from the "transparent proxy" area, i.e. joint work is required - a network piece of iron and a proxy server.
The logic is as follows (omitting the nuances of authentication), if the user's computer initiated a request to port 80, then the network piece of hardware should redirect such requests to your proxy, which supports the "transparent" mode and filtering traffic allows it to pass through. The "transparent proxy" functionality is supported by Squid-proxy, there is also an assembly for Win32, but you will have to deal with the rest yourself.
Or you have already been told about ways to configure everything on the client side through AD, if it exists.
You choose.

R
Ruslan Fedoseev, 2019-12-21
@martin74ua

To automatically configure a large number of computers in an organization, they came up with all sorts of Active Directory and the like ....

V
Vadim Priluzkiy, 2019-12-21
@Oxyd

Use a GPO and distribute these certificates and proxy settings to the entire domain...

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question