Security
Security How To
How To Securely Browse from Anywhere using Hamachi and Squid | How To Securely Browse from Anywhere using Hamachi and Squid |
|
|
| Joseph Dabbs | |
| May 06, 2008 | |
Install & Configure SquidHamachi can provide a secure path to a trusted network, but as shown in Figure 2, it is only part of the safe browsing solution. Squid is a free, widely-used web cache/proxy server. Although very configurable (almost to the point of intimidation), Squid can be up and running with only a few minutes of tweaking. Follow these steps: 1) Download Squid (the Windows binaries can be found here). There is no installer, only a zip file, so Squid requires manual extraction. I recommend (and will make the assumption) that Squid be copied to C:\squid. 2) Rename the three configuration files, located in C:\squid\etc\, removing the .default extension. 3) The squid.conf file will have to be customized for your needs. This can be done inserting the following lines (line placement specified in the squid.conf comments): acl Hamachi src 5.0.0.0/255.0.0.0 (adds a Hamachi group, defined by the 5.x.x.x network) Alternately, you can use the squid.conf I’ve tailored for Hamachi usage, available for download here. 4) To verify that everything works, open command prompt as an Administrator and type the following: cd\squid\sbin If everything works, it should say “Creating Swap Directories”, pause for a moment, then terminate. Now run squid again, this time without the –z parameter (Figure 7). Leave the command prompt window open and begin the next step, client configuration.
Figure 7: Starting squid
Client ConfigurationAfter the previous installs, this section should seem like a cakewalk. Now that we have a connection established between two peers in Hamachi, and a proxy server operational, the non-proxy system (the one we'll use to actually browse the web) must be configured to forward HTTP requests to the proxy. All web browsers can be configured to use a proxy. I'll show you how to configure Internet Explorer 7 as an example. First, navigate to Tools, Internet Options, select the Connections Tab, and click the Lan Settings button.
Figure 8: Windows Internet Options Connections propertiesThe window shown in Figure 9 should be displayed:
Figure 9: Setting the proxyMake sure the bottom two boxes are checked. The Hamachi IP of the system running Squid goes in the Address box, and the port should be 3128 (Squid’s port by default, provided it hasn’t been modified in squid.conf) Hit OK and close the Internet Options window. Now test your configuration by visiting www.google.com. More than likely, there will be a long delay as Squid fetches the page. Wait times will decrease for repeated viewings (as early as the second visit) as Squid builds up its cache. To verify that the proxy isn’t being bypassed, go to www.dnsstuff.com. If your proxy is operational, the “Your IP field” (top left of page, Figure 10) should list the IP of the proxy server (or your WAN IP if you rely on NAT) followed by the Hamachi IP of the client in brackets.
Figure 10: Finding your WAN IPIf everything works, that’s all you need to do to use the proxy. There are measures that can additionally be taken to improve the resiliency of the network, which are covered in the “Improvements & Conclusion” section. Related Articles:How To Securely Web Browse via an SSH TunnelHow To: Fixing DNS problems Anthology Solutions Yellow Machine TeraByte Storage Appliance SmoothWall Express 2.0 A DIY SSL VPN with SSL-Explorer - Part 1 |
|
New firmware 2.1.0
Your thoughts about QNAP TS-109 II
OpenWRT not working as wireless repeater bridge on Netgear WGR614L
OpenWRT working as wireless client bridge on Netgear WGR614L
DIY or buy used?
|
|
|
|
|
|
|
|
More |
|
You could win a Trendnet TEW-633GR Wireless N Gigabit Router and two TEW-621PC 300Mbps Wireless N-Draft PC Cards |
| Wireless Performance Charts: Belkin N+ Wireless Router |
| Router Performance Charts: Belkin N+ Wireless Router |
|
Windows market share drops to 15-year low Black Friday shopping results not entirely negative Power.com aims to become a one-stop social networking portal |
Nokia Plans to Launch Z-Wave Home Control Center in 2009