RE: Re: [squid-users] Squid 2.7 + SquidGuard + Squidclamav

2011-04-14 Thread childrenofchaos
Hey, The Servertraffic is less then 300KB/s. In this Company working 20 Peoples and some guys listening to internet Radio. Is there a Command for getting Squid status Stats like Usage of Redirectors and Dns request or something like that? If Squid tells cans lookup hostname - dns error and i

[squid-users] squid to pass http digest

2011-04-14 Thread Or Gerson
Hello, I have two web servers running apache behind squid. The application on the apache is php written and requests authentication which is passed by http digest. When I try to get to the web servers directly the application works. But through squid I find that squid removes the http digest

Re: [squid-users] squid to pass http digest

2011-04-14 Thread Amos Jeffries
On 14/04/11 21:08, Or Gerson wrote: Hello, I have two web servers running apache behind squid. The application on the apache is php written and requests authentication which is passed by http digest. When I try to get to the web servers directly the application works. But through squid I

Re: [squid-users] problem to configure reverse proxy

2011-04-14 Thread Pascal Bourdais
Le Fri, 25 Mar 2011 22:44:54 +1300, Amos Jeffries squ...@treenet.co.nz a écrit : Hi, Thank you for your answer, and sorry for the very late answer, i've been out for a very long time. On 25/03/11 22:09, Pascal Bourdais wrote: I follow the doc at :

[squid-users] logging skype

2011-04-14 Thread Helmut Hullen
Hallo, squid-users, can I log skype transfer from clients in a LAN to the wide world? My server installation: iptables: $IPTABLES_BIN -t filter -A INPUT -p tcp --dport 80 -j ACCEPT $IPTABLES_BIN -t filter -A INPUT -p tcp --dport 443 -j ACCEPT $IPTABLES_BIN -t filter -A FORWARD -p tcp

RE: [squid-users] The system returned: (111) Connection refused

2011-04-14 Thread Kauffman, Derek E (SA-1)
Yes but when I hit those sites on firefox(which isn't going through squid) those sites work no problem. If I take the proxy out of IE and then try to hit say rush.com it works, but once the proxy is back in I get that error. Derek -Original Message- From: Amos Jeffries

Re: [squid-users] The system returned: (111) Connection refused

2011-04-14 Thread Amos Jeffries
On 14/04/11 22:55, Kauffman, Derek E (SA-1) wrote: Yes but when I hit those sites on firefox(which isn't going through squid) those sites work no problem. If I take the proxy out of IE and then try to hit say rush.com it works, but once the proxy is back in I get that error. Derek Were

[squid-users] diff 2.5.STABLE5 to 2.7.STABLE4

2011-04-14 Thread alois blasbichler
Hello list I have a strange behaviour with my squid ( 2.7.STABLE4) : When i open acertain website (site with webservices) with a browser all works fine. But wenn i open the same site with a special program i get an error and in the log of my squid i see only : TCP_MISS:none we configured :

RE: [squid-users] The system returned: (111) Connection refused

2011-04-14 Thread Kauffman, Derek E (SA-1)
Yes I have been testing from my machine. I have IE setup with proxy and firefox not. Everything works on firefox and IE works correctly with DansGuardian, but for some reason like rush.com get that error below with the squid picture in it. If I take out proxy of IE and restart IE it works

RE: [squid-users] squid to pass http digest

2011-04-14 Thread Or Gerson
Thanks for quick reply. i have added the PASSTHRU only after I have had the problem. Without it (I removed the entire login directive), it seems that squid strips away the entire Authorization digest: 4sG^GET./xadmin/ mk.php.HTTP/1.0. .Host:xx..User- Agent:.Mozilla/5 .0.(Windows;.U;.

Re: [squid-users] TCP Flooding attack and DNS Poisioning attack

2011-04-14 Thread squid
Good day, Thanks all for concern. The network topology is as follow: Workstations are installed with Windows 7 Pro with spyware terminator with integrated ClamAV all link to a Cisco 2950 switch and a multihome server with Windows 7 Ultimate with ESET AV and Squid has one NIC connected to the Cisco

[squid-users] Block Facebook message page

2011-04-14 Thread Mohammad Fattahian
Hi folks, I want to block message page within facebook. Any body can help me? Is there any way to block some pages inside a certaine sites? Thanks, Mohammad

Re: [squid-users] Block Facebook message page

2011-04-14 Thread Helmut Hullen
Hallo, Mohammad, Du meintest am 14.04.11: I want to block message page within facebook. Any body can help me? Is there any way to block some pages inside a certaine sites? I presume that's an end user problem, no squid problem (for all users). With firefox I use adblock+ for such

[squid-users] Squid uses all cpu

2011-04-14 Thread Tóth Tibor Péter
Hi! What could cause squid to use the CPU on 100%? Until now, it worked fine, but for some reasons since this morning, it allways runs on 100% squid version is 3.19 Memory is 8GB, cpu is quad core intel. It shouldn't be a proble to handle all the incoming requests. Thanks for the help! Tibby

RE: [squid-users] Squid uses all cpu

2011-04-14 Thread Tóth Tibor Péter
No I don't think so! Disks seems to be fine. anything else? From: ahmilli...@gmail.com [mailto:ahmilli...@gmail.com] Sent: Thursday, April 14, 2011 6:07 PM To: Tóth Tibor Péter Subject: Re: [squid-users] Squid uses all cpu check I/O operation times of ur server's the disk per second,Maybe it

[squid-users] msktutil on Debian Squeeze

2011-04-14 Thread Rafal Zawierta
Hello, I'm trying to setup squid_kerb_auth but I'm stuck on problem with msktutil. I've downloaded msktutil_0.3.16-7_amd64.deb and installed with dependencies: libsasl2-modules-gssapi-mit, libgssapi-krb5-2, libkrb53. Then, I try to run msktutil from Squid website examples: root@proxy:~# kinit

RE: [squid-users] Block Facebook message page

2011-04-14 Thread Mohammad Fattahian
I found the message composer address. How can I block : https://www.facebook.com/ajax/gigaboxx/endpoint/MessageComposerEndpoint.php I just put bellow configuration to block messaging page (http) acl fb1 url_regex -i ^http://www.facebook.com/ajax/gigaboxx/endpoint/MessageComposerEndpoint.php

[squid-users] cache keeping downloaded files

2011-04-14 Thread Jason Greene
Can some one tell me if it is possible to make squid not cache a single domain? We have a service that downloads a file and squid seems to be keeping the old file in cache so we are not getting the updates. How do I set squid to not cache a domain and/or how do I clear that domain's cache and/or

Re: [squid-users] msktutil on Debian Squeeze

2011-04-14 Thread Rafal Zawierta
2011/4/14 Bobby bmatzn...@pbandt.com: I can tell you that it is extremely critical that your clocks are within 4 minutes or so of each other. I only bring it up because I ran into a similar problem and daylight savings time recently passed... BMatz Clocks are OK. All hosts

[squid-users] cache keeping downloaded files

2011-04-14 Thread Jason Greene
I found the answer # Deny cache for shavlik acl shavlik-nocache dstdomain .shavlik.com cache deny shavlik-nocache Jason

RE: [squid-users] Block Facebook message page

2011-04-14 Thread Joseph L. Casale
acl fb1 url_regex -i ^http://www.facebook.com/ajax/gigaboxx/endpoint/MessageComposerEndpoint.php http_access deny fb1 but it does not work for HTTPS Did you match for https?

Re: [squid-users] msktutil on Debian Squeeze

2011-04-14 Thread Rafal Zawierta
I hate Windows. AD server wasn't present in rev-dns zone (well, I thought that it will add itself without my support). Now msktutil worked fine. After 4 days of fighting with Linux - as usual problem was on MS side :( Regards R.

Re: [squid-users] Block Facebook message page

2011-04-14 Thread 叶雨飞
You can't do it, since HTTPS traffic is tunneled through squid, can't be filtered or cached. In order to filter HTTPS you will need proxy your HTTPS traffic (ssl bumping), isntead. I'm not sure you want to do that. On Thu, Apr 14, 2011 at 10:07 AM, Mohammad Fattahian mfattah...@monexgroup.com

[squid-users] Space in Username

2011-04-14 Thread Durward Holt
I found a couple patches for 2.2 and 2.4 that allow for a space in the username. Is a space not allowed in any of the versions? Is it something that can be allowed easily? What is the reason behind not providing for a space? I have other web auth apps that connect with LDAP and AD, which

RE: [squid-users] Block Facebook message page

2011-04-14 Thread Mohammad Fattahian
Does HHTPS traffic go through squid or not? Do you mean we have no control over HTTPS with Squid? -Original Message- From: Yucong Sun (叶雨飞) [mailto:sunyuc...@gmail.com] Sent: April-14-11 2:25 PM To: Mohammad Fattahian Cc: squid-users@squid-cache.org Subject: Re: [squid-users] Block

RE: [squid-users] Block Facebook message page

2011-04-14 Thread Joseph L. Casale
You can't do it, since HTTPS traffic is tunneled through squid, can't be filtered or cached. If you followed what he was doing, you would have seen his error and known you can very much do what he was trying to do but he failed as a result of the regex. You're match might change to just

[squid-users] squid in sneakernet/Delay-tolerant network

2011-04-14 Thread Tom Sparks
I have a computer that has not network or internet connection Can I use squid in a sneakernet/Delay-tolerant network? tom_a_sparks It's a nerdy thing I like to do

Re: [squid-users] logging skype

2011-04-14 Thread Marcus Kool
Helmut, It is not easy detecting Skype. When PCs of end users are blocked by the firewall, Skype will use the Squid proxy to go the internet. Squid only sees a CONNECT on the HTTPS port 443 and does not know what goes through. You will see a IP:443 in the access.log file. ufdbGuard is a URL

[squid-users] Can squid Transparent Proxy listen to the http port directly? And without IPtables

2011-04-14 Thread Henry Yuan
Hi, I'm wondering whether you can set the http_port to be 80 in the squid.conf file to make squid work as a transparent proxy without IPtable. In other words, is configuring the squid machine as an NAT router an requirement for it to work? ( I'm doing a squid experiment for a course project. The

Re: [squid-users] diff 2.5.STABLE5 to 2.7.STABLE4

2011-04-14 Thread Amos Jeffries
On 15/04/11 01:39, alois blasbichler wrote: Hello list I have a strange behaviour with my squid ( 2.7.STABLE4) : When i open acertain website (site with webservices) with a browser all works fine. But wenn i open the same site with a special program i get an error and in the log of my squid i

Re: [squid-users] Can squid Transparent Proxy listen to the http port directly? And without IPtables

2011-04-14 Thread Amos Jeffries
On 15/04/11 13:36, Henry Yuan wrote: Hi, I'm wondering whether you can set the http_port to be 80 in the squid.conf file to make squid work as a transparent proxy without IPtable. In other words, is configuring the squid machine as an NAT router an requirement for it to work? For NAT

Re: [squid-users] squid in sneakernet/Delay-tolerant network

2011-04-14 Thread Amos Jeffries
On 15/04/11 09:40, Tom Sparks wrote: I have a computer that has not network or internet connection Can I use squid in a sneakernet/Delay-tolerant network? Squid is usually limited by Human delay tolerance. Which is somewhere between 5 seconds and 15 minutes. The particular network actions

Re: Res: [squid-users] squid 3.2.0.5 smp scaling issues

2011-04-14 Thread david
Ok, I finally got a chance to test 2.7STABLE9 it performs about the same as squid 3.0, possibly a little better. with my somewhat stripped down config (smaller regex patterns, replacing CIDR blocks and names that would need to be looked up in /etc/hosts with individual IP addresses) 2.7

Re: [squid-users] Block Facebook message page

2011-04-14 Thread 叶雨飞
Joseph, there's no point of matching https because when your browser using SQUID as a proxy, it sends CONNECT request and then exchange SSL traffic which squid can't/won't touch at all. so the acls, they can't be applied. On Thu, Apr 14, 2011 at 2:23 PM, Joseph L. Casale

Re: [squid-users] Space in Username

2011-04-14 Thread Amos Jeffries
On 15/04/11 06:30, Durward Holt wrote: I found a couple patches for 2.2 and 2.4 that allow for a space in the username. Is a space not allowed in any of the versions? Space is allowed. In the 2.5 series or later. Is it something that can be allowed easily? Yes. Via upgrading the proxy

Re: [squid-users] Squid uses all cpu

2011-04-14 Thread Amos Jeffries
On 15/04/11 04:34, Tóth Tibor Péter wrote: No I don't think so! Disks seems to be fine. anything else? One of several memory leaks and pseudo-leaks that got fixed in the following versions release? http://www.squid-cache.org/Versions/v3/3.1/ChangeLog.txt Amos -- Please be using Current

RE: [squid-users] Block Facebook message page

2011-04-14 Thread Joseph L. Casale
Joseph, there's no point of matching https because when your browser using SQUID as a proxy, it sends CONNECT request and then exchange SSL traffic which squid can't/won't touch at all. so the acls, they can't be applied. Good point, I match on facebook.com as a whole here and it works fine.

Re: [squid-users] squid to pass http digest

2011-04-14 Thread Amos Jeffries
On 15/04/11 01:57, Or Gerson wrote: Thanks for quick reply. i have added the PASSTHRU only after I have had the problem. Without it (I removed the entire login directive), it seems that squid strips away the entire Authorization digest: Okay, so what you want is likely login=PASS (instead

Re: [squid-users] TCP Flooding attack and DNS Poisioning attack

2011-04-14 Thread Amos Jeffries
On 15/04/11 02:05, sq...@sourcesystemsonline.com wrote: Good day, Thanks all for concern. The network topology is as follow: Workstations are installed with Windows 7 Pro with spyware terminator with integrated ClamAV all link to a Cisco 2950 switch and a multihome server with Windows 7 Ultimate

[squid-users] Squid 2.7STABLE8 for windows hang.

2011-04-14 Thread Outofwall.com
Hi, I'm trying to use SQUID 2.7STABLE8 for windows, but however it hangs on several machines. As far as I can tell, they all hanged after Referer logging is disabled. Here's the log: [2] Launched. [2]:/dev/null [2]:: No such file or directory [2]:WARNING: Cannot write log file: /dev/null [2]:

Re: [squid-users] problem to configure reverse proxy

2011-04-14 Thread Amos Jeffries
On 14/04/11 22:28, Pascal Bourdais wrote: Le Fri, 25 Mar 2011 22:44:54 +1300, Amos Jeffriessqu...@treenet.co.nz a écrit : Hi, Thank you for your answer, and sorry for the very late answer, i've been out for a very long time. On 25/03/11 22:09, Pascal Bourdais wrote: I follow the doc at

Re: [squid-users] Squid 2.7STABLE8 for windows hang.

2011-04-14 Thread Amos Jeffries
On 15/04/11 16:08, Outofwall.com wrote: Hi, I'm trying to use SQUID 2.7STABLE8 for windows, but however it hangs on several machines. As far as I can tell, they all hanged after Referer logging is disabled. Here's the log: [2] Launched. [2]:/dev/null [2]:: No such file or directory

Re: [squid-users] TCP Flooding attack and DNS Poisioning attack

2011-04-14 Thread Eliezer Croitoru
On 15/04/2011 07:05, Amos Jeffries wrote: On 15/04/11 02:05, sq...@sourcesystemsonline.com wrote: Good day, Thanks all for concern. The network topology is as follow: Workstations are installed with Windows 7 Pro with spyware terminator with integrated ClamAV all link to a Cisco 2950 switch