6.5.6. Configuring nontransparent rules with inband destination selection

When using inband destination selection, Zorp extracts the address of the destination server from the traffic. Note the following points:

  • For HTTP connections, create a firewall rule that uses a nontransparent HTTP proxy and inband destination selection. Also, set the web browsers of the clients to use Zorp as a web proxy.

  • If the clients use a caching web proxy for HTTP traffic, for example, Squid, and Zorp is located between the clients and the web proxy, then:

    • Create a firewall rule that uses a nontransparent HTTP proxy.

    • Set the parent_proxy and parent_proxy_port attributes of the proxy to the address of the caching proxy.

    • Use a DirectedRouter in the service to redirect the connections to the caching proxy, or use inband destination selection.