As described in iptables docs. I want to get real LAN IP in my squid proxy instead of Gateway IP. That means I have to use internal DNS, right ? The Internal DNS has run, but the LAN PCs still can not go out to internet without the gateway POSTROUTING it to squid cache. ( IP being logged in squid is still Gateway's IP only. ) LAN's network : 10.11.0.0/16 Gateway : 10.11.6.1 / 1.2.3.4 squid IP : 10.11.6.2 / 1.2.3.5 Are my settings correct ?