I feel like a little bit of an idiot now. :-)
I went back to
http://wiki.squid-cache.org/ConfigExamples/Intercept/OpenBsdPf. I was
getting "connection refused" errors, and assumed that this was because
the target interfaces were rejecting connections for IPs not in their
subnet. (I should know better...) All it actually was is that "http_port
3129 intercept" should be "http_port 127.0.0.1:3129 intercept"
(http://wiki.squid-cache.org/ConfigExamples/Intercept/OpenBsdPf#NAT_Interception_proxy).
This appears to work on any interface, not just lo0.
Sorry for the extra noise.
- R.
--
[__ Robert Sheldon
[__ No Problem
[__ Information technology support and services
[__ (530) 575-0278