So your saying the K12LTSP box is also the gateway?  *me shivers* 
Generally speaking (in my experience) if you're doing transparent proxying
the proxy server needs to be at the "choke" point of the network....in
other words right behind the router or acting as the router.

>> >1) It does not seem possible to use transparent proxying without using
>> >second machine for the proxy server.
>> Not only possible...I'm doing it.  I run an SME server with proxy,
>> transparent proxying....running DansGuardian.  Works fantastic!
>Errr, isn't that a 2nd machine?  I think the question was about
>running it on the k12ltsp server which also happens to be where
>the client browsers run.

