What are the benefits of having Squid on the LAN? Our firewall (Sonicwall NSA) explicitly forbids proxies on the LAN for some reason. The firewall will forward all traffic to Squid only if its on public IP address. This is how we are setup right now: (LAN) -> (Sonicwall firewall, NAT, DPI, DHCP) -> (Squid) -> WWW WAN routing is done by the ISP's router that's on site. Latency from LAN to Squid box is <1ms.