Hi There, I am currently using a Squid external helper auth to authenticate users to Novell eDirectory (squid_ip_user.pl). I have a script kindly provided by http://www.novell.com/coolsolutions/feature/17777.html which allows users to authenticate to eDirectory. eDirectory remembers their IP address, and Squid will determine the owner of the IP address and use their username for access to the Internet. If the user is not logged into eDirectory, Squid will prompt the user for authentication via LDAP. Regardless of squid_ip_user.pl or LDAP auth, the usernames are logged in the access log files. I would like to introduce ICAP web filtering (with Trend IWSVA as we are already licensed for this product in our environment). When I use ICAP using the external helper squid_ip_user.pl, Squid does not forward the username of the users to the ICAP server, only the IP address. If I use a traditional LDAP authenticator, Squid does forward the username to the ICAP server. Has anyone experienced something similar? The external authenticator is simply outputting OK User=xxxx. Is there something else the authenticator needs to do to allow this form of auth to work with ICAP? If anyone could help me out I'd be very happy. The code for the squid_ip_user.pl is located at the link posted above. Thanks for your help Aaron Aaron Le Saux Network Systems Manager | Group Information Services | St John of God Health Care 10, 454 Scarborough Beach Road, Osborne Park WA 6017 | PO Box 1845, Osborne Park WA 6916 T: +61 8 6103 5556 | M: +61 432 758 417 | F: +61 8 9444 5609 | E: Aaron.LeSaux@xxxxxxxxxxx > Aaron Le Saux Technical Director Alite Networks Pty Ltd 1 / 7 Wyatt Road BAYSWATER WA 6053 Phone: 0412 121 145 Web: www.alite.com.au > Aaron Le Saux Technical Director Alite Networks Pty Ltd 1 / 7 Wyatt Road BAYSWATER WA 6053 Phone: 0412 121 145 Web: www.alite.com.au Alite Networks Pty Ltd - Enterprise Technology Solutions eMail: sales@xxxxxxxxxxxx Web: www.alite.com.au