You maybe can try rules like this: ipfw add 150 fwd 127.0.0.1,squid_listen_port tcp from any to any dst-port 80 in ipfw add 160 allow tcp from me to any dst-port 80