On 20/11/2015 4:10 a.m., brendan kearney wrote: > So does that mean I can run the DNAT on the firewall/router/load balancer > device and remove the intercept line from my configs, and expect things to > work? I cant say whether it would work or not. That depends on what is going on with HAProxy and DNAT. What I mean is tha the traffic between HAProxy and Squid should be "explicit proxy" aka forward-proxy traffic. No re-interception needed or present. Amos _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users