Squid: Internet Forwarding to Remote VM
Your VM in the cloud has no public IP or internet access is blocked via NAT, but the deployment needs wget/curl from inside. Squid on an intermediate host with a decent uplink solves this in ten minutes.
Why This Is Needed
I forward internet through Squid when a VM sits in an isolated network segment. An intermediate host with a public IP and network access becomes the proxy server. The application on the remote machine routes traffic through the tunnel.
Real-world cases: test environments without external connectivity, CI/CD agents in a private subnet, temporary traffic routing for debugging.
Installing and Basic Squid Setup
Install on the intermediate host (Ubuntu/Debian):
The default config lives in /etc/squid/squid.conf. Minimum working config:
Enable and start:
Verify the port is listening:
ACL and Port Configuration
If access should be only via SSH tunnel from a specific address, replace localnet with the exact IP:
To change the port:
After config changes, reload without restarting:
If Squid fails to start after changes, check the log: journalctl -u squid -n 50.
SSH Tunnel to VM
On the remote machine, establish a tunnel to the intermediate host:
-N — don’t open a shell, forwarding only. -L binds local port 3128 to localhost:3128 on the remote host.
For background:
Or via a systemd user service:
Client Proxy Setup
On the remote VM, set environment variables for applications that respect http_proxy:
Or permanently in /etc/environment:
For curl/wget, variables suffice. For apt — additionally:
Test:
If it returns the intermediate host IP — it’s working.
Verification and Logging
Squid access log:
Format: time client/status code size method URL
Sample entry:
Response codes: TCP_HIT — served from cache, TCP_MISS — fetched from network, TCP_DENIED — access denied by ACL.
To clear the cache before testing:
| Flag | Description |
|---|---|
http_port | Listening port |
acl name src IP/mask | Access rule by IP |
http_access allow|deny | Permit or deny ACL |
-k reconfigure | Reload config |
-k shutdown | Graceful stop |
-z | Initialize cache directories |
Squid caches responses by default. For debugging, disable caching: add cache deny all to the config, then run squid -k reconfigure.
Nine minutes of setup — and the isolated VM has internet via proxy. If you need HTTPS transparent mode with certificate substitution — that’s a different story involving SSL-bump and CA generation.