> I currently have a set of rules such that a certain range > of IP addresses have ZERO internet access. > > However, I would like to use the Failure URL feature to > send a customized > message to the users at these denied IP addresses. > > The problem seems to be, since they have no access they > can't get to the failure URL. Something of an infinite loop. Do you mean no access to the internet or to the proxy? If you mean no access to the internet you could use WCCP on a router that sits somewhere along the default route path to intercept the request and send it to squid where you would have an ACL that captures the requests and presents the failure page. I think we need more info - are you using interception/proxy.pac etc