View Full Version : OpenBSD 4.2 behind NAT and Squid
mfaridi
05-06-2008, 01:47 PM
In our company our NAT server is FreeBSD and we have Squid server , me and all employer get our internet from NAT server and Squid server so everything we do and everywhere we go can record in squid server and they can understand where we go and what we do .
I want find way they can not record what I am do
Is this possible ???
marcolino
05-06-2008, 06:14 PM
So, let me get this straight; you want us to help you violate your employer's acceptable use policy.;)
Anyway, if they have it locked down, and if they're thorough, there will not be any way to do it. If you have access to the squid server, then you will need to change the configuration files to let you through and not log your activity. See the Squid project site (http://www.squid-cache.org/) for more info.
mfaridi
05-06-2008, 06:41 PM
Thanks
but I do not have access to squid server and I can change configure file
I want only do something and squid server can not log me.
lvlamb
05-06-2008, 07:11 PM
In some countries, it is legitimate for users -just plain right to information- to try to by-pass government or corporations fileters or activity logs.
It is, IMVHO, not fair to use a corporate structure which pays the costs and not abide to that corporation rules. Although, in Europe, an employer is not allowed to control an employee's use of corporate Internet, with all abuses it generates.
OTOH, as a private user paying his own bandwith, trying to by-pass governement regulations can be, in many cases, considered as pure freedom of speech. (With all abuses it might cause :p )
Don't want your employer register what you are doing? Get your own ISP contract.
marcolino
05-06-2008, 07:38 PM
mfaridi,
If your employer has configured all Internet traffic to go through the squid server, and only traffic from the squid server is allowed to access the Internet, then I'm afraid you have no choice but to access the Internet through the squid server.
Actually, there is one alternative: use a different Internet connection.
Sorry if this is not too helpful for your situation, but those are your options.
mfaridi
05-07-2008, 07:04 AM
thanks
Is this possible
I do something , my invalid IP is 192.168.0.104
and when I use internet everything log by this IP with Squid Server.
Can I do something all thing I do log with another IP , without change my IP. ???
marcolino
05-07-2008, 08:31 PM
mfaridi,
Can you have other people call you by a different name, if you do not tell anyone that name? What if they call you by that different name, but they still know you by your face? Will it make a difference?
This is similar to what you are asking. (OK, not a perfect analogy, but it suffices.) You will have to change your IP address in order for squid to log a different IP address. Even in that case, I believe squid logs your MAC address as well, which will be the same no matter what your IP address is. Now, there is a possibility that you could change your NIC's MAC address as well, but then you are looking at something else entirely.
windependence
05-19-2008, 01:56 PM
What if he tunnels through port 443 to his home server and then goes out to the net? They wouldn't be able to see what was going on inside the tunnel.
-Tim
marcolino
05-19-2008, 04:49 PM
What if he tunnels through port 443 to his home server and then goes out to the net? They wouldn't be able to see what was going on inside the tunnel.
-TimQuite true, although if they look through the logs and see a significant amount of traffic going from his work IP to his home IP, they might get suspicious and block traffic to that IP. At least, they would do this if they were monitoring it. I did the same when I administered a Squid/Squidguard filtering proxy.
Note that doing this, if prohibited by the company's fair use policy, could result in severe consequences.
vBulletin® v3.7.2, Copyright ©2000-2009, Jelsoft Enterprises Ltd.