(in this case clamav via c-icap and squidclamav plugin for c-icap). This readme also has pointers to configure squid proxy as ICAP client and talk to to a DLP for content scanning. This patch will make squid to not change the source port number so that uses the same five tuple as incoming connection and it can work with the decryption broker feature of Palo Alto Networks Firewalls. Squid Proxy patch to run tproxy preserve the 5 tuple of client trafficīy default squid proxy changes the source port number of the client traffic while handling connections in tproxy mode.