3 ms·
OP here. This isn't quite my space, but from what I recall there's a couple wrinkles with transparent proxying. It's overall a good idea, but has some edge cas
by c0nsumer 4y ago
OP here.
This isn't quite my space, but from what I recall there's a couple wrinkles with transparent proxying. It's overall a good idea, but has some edge cases:
- Authentication can go sideways in weird ways. A 407 from what looks like the correct site can cause odd things. IIRC there isn't great support from vendors for authenticating transparent proxies, too. Sure, you could auth off the machine instead (X device is on the network, therefore it's allowed), but what about shared machines... Proxy auth as user is better, because it allows requests to be tracked to a user ID and login session, not just a device.
- Client getting load balanced between proxies during a session can trigger reauth (because auth sessions not shared between proxies), this can confuse a client.
- HTTPS sites can get weird.
- Routing in very large private environments can complicate default routing to the public internet. Although this can be handled by doing transparent auth + optional manual config.