Skip to main content

Install SafeSquid on the Right Platform

Installation quality determines whether SafeSquid can inspect traffic safely under production load. Pick the deployment method that matches your ownership model, then verify service health before routing users.

Choose the install path

1

Choose SafeSquid Appliance Builder

SafeSquid Appliance Builder

Build a new VM or hardware appliance from the standard ISO. Use this when the target disk can be dedicated to SafeSquid.
Confirm the VM or hardware can be rebuilt and the selected disk is disposable.If existing data must be preserved, do not use Appliance Builder.
2

Choose cloud deployment

Cloud Deployment

Place SafeSquid near cloud workloads, remote sites, or hybrid egress with restricted security groups and route-table ownership.
Confirm route tables and security groups restrict proxy access to approved clients.If the proxy is public, tighten source networks before rollout.
3

Choose Linux Server Install

Linux Server Install

Install on an existing supported Linux host when your team owns OS hardening, monitoring, dependency lifecycle, and rollback.
Confirm host lifecycle, packages, monitoring, and rollback are already owned.If dependencies fail, correct the baseline or rebuild with Appliance Builder.
If the environment is not listed, choose by ownership rather than by platform: Appliance Builder when SafeSquid can own the whole host, Linux Server when something else already does.

Installation sequence

1

Validate prerequisites

Confirm host resources, static addressing, DNS, NTP, firewall rules, and activation key readiness in Deployment Checklist.Confirm prerequisite evidence is attached to the deployment record.If a prerequisite is missing, block installation until the owner corrects it.
2

Install using the selected path

Build the appliance, launch the cloud instance, or install on the managed Linux host according to the selected deployment model.Confirm the installed host matches the approved deployment model and asset record.If installation assumptions differ from the plan, stop and select the correct install path.
3

Verify service and listener state

Confirm SafeSquid service health and the approved proxy listener before any managed rollout.Confirm service status and listener output show SafeSquid is ready for activation.If listener state is missing, inspect service logs and network binding configuration.
4

Route one pilot client

Send one browser or test client through SafeSquid and prove that traffic appears in /var/log/safesquid/access/extended.log.Confirm the access log records source, destination, timestamp, and action.If no log appears, recheck proxy settings and bypass rules before adding users.
5

Open the interface and activate

Open http://safesquid.cfg/ through the proxy path, then complete Activate Your License.Confirm the Configuration Portal loads and activation evidence is captured.If the portal fails, confirm the pilot browser uses SafeSquid as proxy.

Evidence to capture

Store:
  • Install method and version source.
  • Hostname, IP address, and deployment environment.
  • CPU, RAM, disk, and NIC allocation.
  • Service status output.
  • Listener check for the approved proxy port.
  • Pilot client test and first access-log entry.
  • Rollback or rebuild procedure.

Troubleshoot install choice

Next steps