Hi We run a number of squid 3.1.0.14 TPROXY caches in an ISP environment. In our access log we are seeing a fair few client IP addresses of 127.0.0.1 and also RFC1918 address ranges. The caches do not have any local users. We do not have any RFC1918 clients accessing caches, all customers have real IP addresses. Is something broken here? Examples : 1259017091.941 413 172.16.212.240 TCP_MISS/200 3172 GET http://s2.bikewalls.com/pictures/Road_Race_125_Misano_SanMarino_2008_11_100x 75.jpg - DIRECT/67.19.13.114 image/jpeg 1259017091.941 413 172.16.212.240 TCP_MISS/200 3335 GET http://s2.bikewalls.com/pictures/Road_Race_125_Misano_SanMarino_2008_12_100x 75.jpg - DIRECT/67.19.13.114 image/jpeg 1259017091.948 0 127.0.0.1 TCP_IMS_HIT/304 360 GET http://resources.news.com.au/cs/heraldsun/images/header-and-footer/nav-drop. gif - NONE/- image/gif 1259017091.953 412 172.16.212.240 TCP_MISS/304 314 GET http://s2.bikewalls.com/pictures/KTM_125_EXC_2009_01_100x75.jpg - DIRECT/67.19.13.114 - 1259017091.954 413 172.16.212.240 TCP_MISS/200 3769 GET http://s2.bikewalls.com/pictures/KTM_400_EXC_01_100.jpg - DIRECT/67.19.13.114 image/jpeg 1259017091.958 0 127.0.0.1 TCP_IMS_HIT/304 360 GET http://resources.news.com.au/cs/heraldsun/images/header-and-footer/nav-carsg uide.gif - NONE/- image/gif 1259017091.960 668 10.130.165.68 TCP_MISS/200 618 GET http://pubs.globalsecurity.org/adlog.php? - DIRECT/130.94.28.117 image/gif 1259017091.967 1964 10.128.145.91 TCP_MISS/200 74379 GET http://wormatlas.psc.edu/male/musclemale/images/MaleMusFIG28.jpg - DIRECT/128.182.66.72 image/jpeg 1259017091.968 0 127.0.0.1 TCP_IMS_HIT/304 359 GET http://resources.news.com.au/cs/heraldsun/images/header-and-footer/nav-caree rone.gif - NONE/- image/gif Let me know if you want me to post configure strings / squid.conf Thanks, Michael.