Thanks for the confirmation Henrik. -- Thanks, Bryan Shoebottom Network & Systems Specialist Network Services & Computer Operations Fanshawe College Phone: (519) 452-4430 x4904 Fax: (519) 453-3231 BShoebottom@xxxxxxxxxxxx -----Original Message----- From: Henrik NordstrÃm [mailto:henrik@xxxxxxxxxxxxxxxxxxx] Sent: Thursday, September 23, 2010 4:20 AM To: Shoebottom, Bryan Cc: squid-users@xxxxxxxxxxxxxxx Subject: Re: client identifier in squid logs ons 2010-09-22 klockan 09:03 -0400 skrev Shoebottom, Bryan: > I have an interception proxy configuration using WCCP and a Cisco > router. PAT/NAT happens on a device before the proxy, so my logs show > only the public IPs. That's because your firewall throws away the source IP without recording it anywhere outside of the firewall logs.. > Without changing the placement of the proxy or moving away from > the interception configuration, am I able to get the internal IP of the > clients added to my logs? No. You need to change how traffic gets directed to the proxy so that the traffic is NOT NAT:ed. Regards Henrik