Hi all,
On Thu, Mar 22, 2012 at 6:08 AM, GarethC gar...@garethcoffey.com wrote:
Hi Carlos,
Yes you can achieve this by using an ACL (Access control list), for
example...
acl allowedsites dstdomain google.com
http_access allow allowedsites
This will allow users to connect to
Hi!
On Wed, Jul 20, 2011 at 12:08 PM, chinner999 chinner...@gmail.com wrote:
Right from the squid.conf file
WARNING: authentication can't be used in a transparently intercepting
# proxy as the client then thinks it is talking to an origin server and
# not the proxy. This is a
Resending to list
-- Forwarded message --
From: Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com
Date: Wed, Jul 20, 2011 at 11:48 AM
Subject: Re: [squid-users] Getting SARG to show usernames instead of IP
To: chinner999 chinner...@gmail.com
On Wed, Jul 20, 2011
Hi!
On Sat, Aug 28, 2010 at 11:11 PM, Andrei funactivit...@gmail.com wrote:
Ooo... the line between Squid and the clients is 1000 MB. My internet
connection is 12MB. Not sure if that changes things. Does it? Would it
make a difference in that situation if clients (from 1000Mb) come on
one
Hi!
On Tue, Aug 24, 2010 at 12:59 AM, Hamza Sani Abubakar Usman
hamza_s...@hotmail.com wrote:
Hi,
Can you please tell me that How much amount of ram will required if we use
100GB partition for squid caching.
I don't remember. A quick google search gave me this:
2010/8/23 Tóth Tibor Péter tibor.peter.t...@mtv.hu:
Hi!
My machine's got 120 GB storage in total.
I am using 10 GB, so I still have 110 GB free Hdd space.
Where can I configure squid to use more of the Hard drive for caching ?
cache_dir on squid.conf
But please, bear in mind that more disk
Hi!
On Fri, Aug 20, 2010 at 4:04 AM, Jean-Baptiste Denis jbde...@pasteur.fr wrote:
On Thu, 19 Aug 2010 09:48:31 -0500, Johnson, S wrote:
The proxy is configured for everyone going
through one of two groups with the ability in the 2nd group to elevate
their privileges to bypass the filter by
Hi!
That's a dansguardian issue: I had something similar, but specially
with SSL sites.
I just got tired of dansguardian (I made it work, but from time to
time the problem would come back), and started to use plain squid ACLs
for small lists, and squidguard.
I hope this helps,
Ildefonso
Hi!
On Tue, Aug 17, 2010 at 11:06 PM, Amos Jeffries squ...@treenet.co.nz wrote:
On Tue, 17 Aug 2010 22:43:33 -0430, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
In my own personal opinion: your hard drive alone is not enough to
handle that much traffic (110MBytes/s
Hi!
In my own personal opinion: your hard drive alone is not enough to
handle that much traffic (110MBytes/s, ~1Gbps). See, most SATA hard
drives (7200rpm) gives around 50~70MB/s *sequential* read speed, your
cache reads are *not* sequential, so, it will be slower. In my
opinion, you need
Hi!
Sorry, had to post some corrections. duh
On Tue, Aug 17, 2010 at 10:43 PM, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
In my own personal opinion: your hard drive alone is not enough to
handle that much traffic (110MBytes/s, ~1Gbps). See, most SATA hard
Hi!
On Thu, Aug 12, 2010 at 8:00 PM, Network Administrator
ad...@sscrmnl.edu.ph wrote:
Hi,
Just wanted to ask what is PINNED on my access.log while using calamaris.
searched for it, haven't found it
1278137619.277 125 192.168.40.106 TCP_MISS/200 2727 GET
On Wed, Aug 11, 2010 at 1:09 AM, Drunkard Zhang gongfan...@gmail.com wrote:
2010/8/11 Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com:
On Tue, Aug 10, 2010 at 10:19 PM, Drunkard Zhang gongfan...@gmail.com
wrote:
2010/8/11 Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com
Hi!
On Tue, Aug 10, 2010 at 12:27 AM, Stand H hstan...@yahoo.com wrote:
--- On Mon, 8/9/10, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
From: Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com
Subject: Re: [squid-users] how much traffic can squid handle
On Tue, Aug 10, 2010 at 10:19 PM, Drunkard Zhang gongfan...@gmail.com wrote:
2010/8/11 Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com:
Hi!
On Tue, Aug 10, 2010 at 12:27 AM, Stand H hstan...@yahoo.com wrote:
--- On Mon, 8/9/10, Jose Ildefonso Camargo Tolosa
ildefonso.cama
Hi!
On Mon, Aug 9, 2010 at 8:18 PM, Drunkard Zhang gongfan...@gmail.com wrote:
BTW, may bonding of multiple NICs helps on too many interrupts.
Or maybe just a good NIC, or a GOOD NIC + bonding :)
Hi!
Ok, just to answer your question, it varies from client to client,
ranging from 256MB to 3GB, also, the number of users ranges from 5 to
1000, and the disk cache size ranges from 1GB to 8GB.
Sincerely,
Ildefonso Camargo
2010/7/28 Tóth Tibor Péter tibor.peter.t...@mtv.hu:
Hi Guys!
How
Greetings!
On Tue, Jul 27, 2010 at 12:39 AM, Amos Jeffries squ...@treenet.co.nz wrote:
On Mon, 26 Jul 2010 15:27:22 -0430, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
On Fri, Jul 23, 2010 at 8:31 PM, Amos Jeffries squ...@treenet.co.nz
wrote:
Etienne Philip
Hi!
On Fri, Jul 23, 2010 at 8:31 PM, Amos Jeffries squ...@treenet.co.nz wrote:
Etienne Philip Pretorius wrote:
Hello List,
I am running Squid Cache: Version 3.1.3. and I wanted to cache windows
updates and applied the suggested settings from
On Mon, Jul 26, 2010 at 3:41 PM, Leonardo Carneiro
chesterma...@gmail.com wrote:
On Mon, Jul 26, 2010 at 4:57 PM, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
On Fri, Jul 23, 2010 at 8:31 PM, Amos Jeffries squ...@treenet.co.nz wrote:
Etienne Philip Pretorius wrote
Hi!
On Mon, Jul 26, 2010 at 2:01 AM, goody goody think...@yahoo.com wrote:
Hi,
In our organization we have restricted access to only limited IPs as per
company
policy, but what some users are doing that they are building their own proxy
servers on any single allowed IP addresses and
Hi!
First, the obvious question: do you intent to have disk cache on
this squid deployment? if so, please evaluate the live of the flash
card, and maybe, think about adapting a SSD instead (or, maybe, a SATA
disk, the soekris net5501 actually have SATA port).
Second: as for using 512MB of RAM,
Hi!
On Wed, Jun 16, 2010 at 1:14 PM, maximatt aza...@gmail.com wrote:
hi...
i try to config squid to authenticate with two ldap servers... but i
have some isues so...
- ¿squid_ldap_auth can resolve via dns the ldap host?
Yes.
- ¿squid_ldap_auth support multiple ldap servers?
I
Posting back to list (forgot to hit reply all):
Hi!
On Wed, Jun 16, 2010 at 11:20 PM, Saurabh Agarwal
saurabh.agar...@citrix.com wrote:
Hi All
Can squid cache HTTP Data going encrypted over IPSec VPN and SSL VPN? If yes
then how it can be done?
It depends, if it is something like this:
Hi!
On Sun, May 16, 2010 at 6:14 PM, Amos Jeffries squ...@treenet.co.nz wrote:
On Sun, 16 May 2010 14:06:55 -0430, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
On Fri, May 14, 2010 at 10:27 AM, a...@gmail adbas...@googlemail.com
wrote:
Hello all
I was wondering
On Sat, May 15, 2010 at 9:50 AM, jondavidf jon.freri...@gmail.com wrote:
I need some help if at all possible. This may be a re-post for some.
This is what I'm trying to accomplish:
Trying to get fast Internet to 50 Soldiers stationed in Afghanistan.
I am completely new to linux and
Hi!
On Sat, May 15, 2010 at 1:54 AM, Amos Jeffries squ...@treenet.co.nz wrote:
Joe wrote:
Am 14.05.2010 14:31, schrieb Peng, Jeff:
Does the src ACL have any help to you?
http://www.squid-cache.org/Doc/config/acl/
Not really as it does not explain. Maybe my explanation was not so good. I
Hi!
On Fri, May 14, 2010 at 10:27 AM, a...@gmail adbas...@googlemail.com wrote:
Hello all
I was wondering if anyone knows how to remove a proxy from a linux system
I haven't added the proy to any files, but everytime I try for instance to
connect it keeps searching for the proxy
I initially
Hi!
There are a couple of tricks to get this, at least on Linux systems.
1. I used to use a fancy trick for this: conntrack.
cat /proc/net/ip_conntrack
With conntrack module loaded, usually, just add a few iptables rules,
maybe just as simple as:
iptables -A INPUT -m state --state
,
and occurred at least three times a day).
It was interesting.
steve
-Original Message-
From: Jose Ildefonso Camargo Tolosa [mailto:ildefonso.cama...@gmail.com]
Sent: Saturday, May 08, 2010 3:17 PM
To: Bradley, Stephen W. Mr.
Cc: mnhas...@usa.net; Squid Users
Subject: Re: [squid
Hi!
On Mon, May 10, 2010 at 3:50 AM, David Touzeau da...@touzeau.eu wrote:
On 10/05/2010 07:50, Jose Ildefonso Camargo Tolosa wrote:
Hi!
On Sun, May 9, 2010 at 5:21 PM, David Touzeauda...@touzeau.eu wrote:
Dear all
Currently i have many HTTP uploads problems using DansGuardiand+Squid
Hi!
On Sun, May 9, 2010 at 5:21 PM, David Touzeau da...@touzeau.eu wrote:
Dear all
Currently i have many HTTP uploads problems using DansGuardiand+Squid.
I have upgraded to Squid 3.1 but problems still occur.
It is not a Squid problem but a Dansguardian problem.
Nice, uploads problems too.
, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Hi!
On Fri, May 7, 2010 at 2:14 PM, Baird, Josh jba...@follett.com wrote:
Ok, perhaps I misunderstood how CONNECT works.
When Squid CONNECT's to a remote webserver via HTTPS, the tunnel is
created between the user
Hi!
Just one thought here:
I believe there is a limit on the number of connections that can be
originated from a single IP (IPv4), so, I guess that you have
*several* external IPs and that you make squid use many of them, look
that file on your system:
cat /proc/sys/net/ipv4/ip_local_port_range
Hi!
On Fri, May 7, 2010 at 2:14 PM, Baird, Josh jba...@follett.com wrote:
Ok, perhaps I misunderstood how CONNECT works.
When Squid CONNECT's to a remote webserver via HTTPS, the tunnel is
created between the user and the remote server.. so is all data sent
over HTTPS (from the remote server
Hi!
On Tue, May 4, 2010 at 1:47 AM, Dave Coventry dgcoven...@gmail.com wrote:
On 4 May 2010 05:21, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Some questions:
1. How is your network currently configured: static IPs, dhcp, if
dhcp, is the dlink router your dhcp server
:
Thanks for the help, Jose.
On 5 May 2010 18:46, Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com wrote:
Ok, so, you could, in theory, add an internal DNS zone, right?
(because is doesn't currently exists). Now, and off-topic question:
do you have a domain on your network, or just
Hi!
On Sun, May 2, 2010 at 7:13 AM, D.Veenker d...@veenker.tk wrote:
My web client is not capable of SSL and definitely no client certificates.
Ok I *have* to ask, I can't help it, it is my nature I have to
ask this: what web client is this, that doesn't support SSL? (https).
Sorry
Hi!
On Mon, May 3, 2010 at 5:11 PM, Dave Coventry dgcoven...@gmail.com wrote:
I need to add a proxy server to our office network.
The router/modem is a DLink G604T and I want all requests for Internet
access to be re rerouted to a Debian box with Squid Installed.
How do I set this up?
Some
Hi!
It have been a long time since the last time I saw a large amount of
users with just one squid proxy (8 years or so). Anyway, from what I
can remember, I had a couple of interesting points: number of opened
files, and number of simultaneous connections. I had to tune: kernel
(proc), system
.
Cheers,
Bruno Santos
- Original Message -
From: Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com
To: Bruno Santos bvsan...@hal.min-saude.pt
Sent: Saturday, February 27, 2010 12:11:24 AM GMT +00:00 GMT Britain,
Ireland, Portugal
Subject: Re: [squid-users] squid + dansguardian
Hi!
Maybe a simple solution: autoconfiguration script (wpad.dat), you can
make the stations conditionally use any proxy depending on the URL (or
part of it), also, other fields. From squid, I would need to analyze
the case, I have never done anything like that, but it should be
possible.
Hi!
Remember ACLs are used up to down, and the first one to hit will
be used, so, just add an allow for the IPs you want whitelisted,
before the ACL that blocks the pages.
I hope this helps,
Ildefonso Camargo
On Mon, Feb 15, 2010 at 12:34 AM, Martin Connell
mconn...@richmondfc.com.au wrote:
Hi!
I really don't understand why are you, people, so insistent on the
x-forwarded-for thing. it has nothing to do with authentication,
unless you use IP as part of your ACLs, off course.
Now, I repeat:
authplugin = '/etc/dansguardian/authplugins/proxy-basic.conf'
authplugin =
Hi!
Why not use Coova Chilli?
http://coova.org/wiki/index.php/CoovaChilli
or something like that.
I hope this helps,
Ildefonso Camargo
On Fri, Feb 12, 2010 at 2:04 PM, Bruno de Oliveira Bastos
kid...@brturbo.com.br wrote:
No, i try to mount a captive portal for free access where user can
Hi!
On Wed, Feb 10, 2010 at 9:35 AM, Bruno Ricardo Santos
bvsan...@hal.min-saude.pt wrote:
X-Copyrighted-Material
Hi all!
I'm having some trouble configuring squid with auth + dansguardian content
filter.
It's all configured, but when i try to browse, i get an error:
Dansguardian 400
Hi!
Please, read:
http://wiki.squid-cache.org/Features/Authentication?action=showredirect=SquidFaq/ProxyAuthentication#Authentication_in_interception_and_transparent_modes
You just can't authenticate in transparent mode.
If you have an AD (or samba), you could centrally configure the proxy
on
Hi!
On Sat, Jan 2, 2010 at 1:49 PM, ml ml mliebher...@googlemail.com wrote:
Hi,
thanks for the reply.
However, i cant get the proof-of-concept working on the command line:
echo mo | squid_ldap_group -b dc=my-domain,dc=com -f cn=mo -F
cn=mo -h localhost -D cn=Manager,dc=my-domain,dc=com
Hi!
Sure: the DN syntax that squid is sending to the LDAP is invalid.
without your config, there is nothing more I can say (for me: it just
worked!).
I hope this helps,
Ildefonso Camargo
On Wed, Dec 9, 2009 at 8:57 AM, Dominguez, Gaston Matias
gdoming...@eling.com.ar wrote:
Hi people
I
Hi!
This could come a little off-topic, but: which VPN are you using? if
you happen to be using OpenVPN, try adding the option persist-tun,
also, there is a chance that you can make squid actually restart when
the VPN goes down and up again (by using the down and up options,
that calls down and
Hi!
But... such scripts are already part of squid, I don't have the names
at hand, but really: squid works really well with LDAP, you can even
create ACLs by-ldap-groups.
And, squid will produce something like this in the logs:
1258978126.154 5238 192.168.12.34 TCP_REFRESH_MISS/200 776 GET
:
There is only scripts for performing LDAP based authenitication based on
login+password, there is not scripts to query some LDAP on what user is
logged in at ip X.
tis 2009-11-24 klockan 15:23 +1930 skrev Jose Ildefonso Camargo Tolosa:
Hi!
But... such scripts are already part of squid, I
Hi!
I use to create custom error pages, and trigger them, something like this:
acl internethorario time MTWHF 08:30-11:30
acl internethorario time MTWHF 14:00-17:00
deny_info ERR_ACCESS_DENIED_Horario internethorario
http_access deny internethorario
http_access allow !internethorario
In this
Hi!
On 6/14/09, Yan Seiner y...@seiner.com wrote:
This is not really a squid question, but it is related and I can't find any
info on this.
How does one go about configuring firefox to autoconfig a proxy when at
home and not when on the road?
In other words, for a laptop, how do I use a
Hi!
On 5/21/09, Dror Galron dror.gal...@gmail.com wrote:
Hi,
I am considering implementing Squid as my web cache for Video streams
(YouTube etc).
I am going to configure Squid over SAN centralized storage.
I am aware of the additional plug-in required to normalize YouTube URL's.
I
Hi!
On Tue, Apr 28, 2009 at 7:54 AM, Wilson Hernandez - MSD, S. A.
w...@msdrd.com wrote:
Hello everybody.
I am somewhat confused on how squid helps to save bandwidth. I know it
saves visited websites to cache and when someone else request the same
site it will serve it from the cache. Please
Hi!
On Fri, Apr 3, 2009 at 4:10 PM, Rodrigo Gliksberg
rgliksb...@dedicado.com wrote:
Hello a ihave mount server OpenBSD 4.4 with squid 2.7, and squidguard, i
need to my boos transparent mode with AUTHENTICATION?, was is not
posible, from squid, any can help with any idea.
The short answer:
, 82, 443, 3128, 8080.
3. Block all other packets.
Thank you once again for your comments / suggestions.
Regards
HASSAN
- Original Message - From: Amos Jeffries squ...@treenet.co.nz
To: Jose Ildefonso Camargo Tolosa ildefonso.cama...@gmail.com
Cc: Nyamul Hassan mnhas...@usa.net
other network
service.
Regards
HASSAN
- Original Message - From: Jose Ildefonso Camargo Tolosa
ildefonso.cama...@gmail.com
To: Nyamul Hassan mnhas...@usa.net
Cc: Squid Users squid-users@squid-cache.org
Sent: Saturday, February 28, 2009 18:38
Subject: Re: [squid-users] Firewalling
Hi!
On Sat, Feb 28, 2009 at 4:43 PM, Nyamul Hassan mnhas...@usa.net wrote:
Hi,
I was checking the requests to and from my proxy servers, and I noticed
that, while most src-port were TCP 80, 53, 443, some were very high TCP
ports. These high port packets would usually also be accompanied by
Hi!
On Thu, Feb 5, 2009 at 10:02 PM, jjrowan squid_u...@rownetco.com wrote:
A customer has a problematic employee that spends excessive time on
Facebook, Myspace and FoxSports. They are willing to let him access these
sites before and after work and during lunch but during office hours they
Hi!
On Fri, Jul 11, 2008 at 4:17 PM, Joseph Piché [EMAIL PROTECTED] wrote:
I have a setup with Squid 3.0 stable 7 and DansGuardian 2.9.9.4. I
have been trying to set up authentication using ntlm_auth connecting
to Active Directory. Everything works fine except I get prompted for a
username
Hi!
On Sun, Jun 22, 2008 at 11:29 PM, howard chen [EMAIL PROTECTED] wrote:
Hi,
On Sun, Jun 22, 2008 at 1:23 AM, Jose Ildefonso Camargo Tolosa
for 1: maybe iptables + l7filter ( http://l7-filter.sourceforge.net/ ).
for 2: iptables, yup, plain iptables.
for 3. not sure... but maybe iptables
, 2008 at 7:22 PM, Jose Ildefonso Camargo Tolosa
[EMAIL PROTECTED] wrote:
Hi!
I'm trying to use group names that include white spaces (such as
Group Name) with external auths.
I got some ACLs defined like this:
external_acl_type ldap_group %LOGIN /usr/lib/squid/squid_ldap_group -W
/etc/squid
Hi!
On Sun, Jun 22, 2008 at 10:26 AM, howard chen [EMAIL PROTECTED] wrote:
Hi all,
I am not sure if anyone think about this before.
Consider a traditional setup for today web applications:
User == Squid(s) == Apache(s) == MySQL / Memcached / NFS
Currently I have mod_security installed
Hi!
I'm trying to use group names that include white spaces (such as
Group Name) with external auths.
I got some ACLs defined like this:
external_acl_type ldap_group %LOGIN /usr/lib/squid/squid_ldap_group -W
/etc/squid/squid_ldap.secret -D cn=Manager,dc=test,dc=local -b
Hi!
Sorry, I forgot to give this info:
squid version: 2.6stable5 (debian etch).
I also tried: 2.6stable20 (from backports).
On Sat, Jun 21, 2008 at 7:22 PM, Jose Ildefonso Camargo Tolosa
[EMAIL PROTECTED] wrote:
Hi!
I'm trying to use group names that include white spaces (such as
Group
67 matches
Mail list logo