> > request_header_access is a fast ACL so it can't do DNS lookups to > find > the dst IP address itself. > It also only has access to details in the HTTP request headers and > src > IP address. > > Using dstdomain ACL on the requested domain name it should work. > > NP: using the server connection details should be technically > possible > at that point however. Please file an enhancement bug request > (preferrably with patch) if it is important. > > Ok thanks > PS. I really, really hope Via is not the header you are actually > forging. It is depended on by servers and clients to be an accurate > representation of the protocol feature support along the transfer > path > and a list of servers to test when things go wrong. No it's just a test, actually I removed the Via header