Hello.
Any one could tell me where i can download latest binary version of squid
compiled with options to works in transparent mode ? I don't like configure
IE7 in all my clients. :-)
Thanks.
Configuring all your clients is not that bad, there are mechanisms to
do it almost painlessly:
Among the availble options there's DHCP, wpad and if you have a domain
you can also use group policies and logon scrips.
Teharding your question, what OS would you need the binary for? MS Windows?
On
http_access allow accel_hosts
http_access allow manager localhost
http_access deny manager
http_access allow all
The line above permits anyone who can send a packet to your proxy to use
it as a relay for any purpose they like.
The restrictions above it are not
Binarys are for Windows xp professional. We don't use dhcp, domain. All my
network is in a workgroup without servers.
Usually we use Wingate like proxy in a similar environment, working in
transparent mode (NAT) and works fine, but now we want, testing this proxy.
Thanks.
- Original
hello all,
I currently get some sun v210 boxes running solaris 8 and squid-2.6.12
and samba 3.0.20b I will upgrade these proxies into 2.7.4/3.0.32 next
monday but before doing this I would like to ask you your advices and/or
experiences with tuning these kind of boxes.
the service is running
Hello, how can I access to IMAP (gmail IMAP for example)servers trough squid, I
just add imap ports in squid.conf as Safe_port and SSL_port, but it does not
work.
Thanks
julian julian wrote:
Hello, how can I access to IMAP (gmail IMAP for example)servers trough squid, I just add imap ports in squid.conf as Safe_port and SSL_port, but it does not work.
IMAP protocol is not HTTP protocol. Squid cannot handle IMAP requests.
They only way to do this is configure
On 12.11.08 05:57, julian julian wrote:
Hello, how can I access to IMAP (gmail IMAP for example)servers trough
squid, I just add imap ports in squid.conf as Safe_port and SSL_port, but
it does not work.
why would you want to access IMAP through squid ?
--
Matus UHLAR - fantomas, [EMAIL
Ok, I'm using thunderbird and set the proxy manually, but when I try to conect
I get an error, should I make some special config in squid?
--- On Wed, 11/12/08, Amos Jeffries [EMAIL PROTECTED] wrote:
From: Amos Jeffries [EMAIL PROTECTED]
Subject: Re: [squid-users] IMAP support
To: [EMAIL
Because all my traffic to internet is managed by squid. Do you have any
suggestion?
--- On Wed, 11/12/08, Matus UHLAR - fantomas [EMAIL PROTECTED] wrote:
From: Matus UHLAR - fantomas [EMAIL PROTECTED]
Subject: Re: [squid-users] IMAP support
To: squid-users@squid-cache.org
Date:
Hi
I have a client that when he tries to access agentdeal.marvel.com the
web server (IIS) does give a login prompt as it should and instead
returns a 401 error.
squid access logs
1226493177.205 2413 192.168.1.54 TCP_MISS/401 2199 GET
http://agentdeal.marvel.com/clm - DIRECT/65.202.37.147
Hello,
I am using Squid as reverse proxy in front of a web server (Apache).
If my Apache cannot have gzip enabled, is it possible to gzip the page
using Squid before sending to client?
Thanks/
Jose wrote:
Binarys are for Windows xp professional. We don't use dhcp, domain. All
my network is in a workgroup without servers.
Usually we use Wingate like proxy in a similar environment, working in
transparent mode (NAT) and works fine, but now we want, testing this proxy.
Thanks.
IIRC
Ok, I'm using thunderbird and set the proxy manually, but when I try to conect
I get an error, should I make some special config in squid?
--- On Wed, 11/12/08, Amos Jeffries [EMAIL PROTECTED] wrote:
From: Amos Jeffries [EMAIL PROTECTED]
Subject: Re: [squid-users] IMAP support
To: [EMAIL
Because all my traffic to internet is managed by squid. Do you have any
suggestion?
--- On Wed, 11/12/08, Matus UHLAR - fantomas [EMAIL PROTECTED] wrote:
From: Matus UHLAR - fantomas [EMAIL PROTECTED]
Subject: Re: [squid-users] IMAP support
To: squid-users@squid-cache.org
Date: Wednesday,
julian julian wrote:
Ok, I'm using thunderbird and set the proxy manually, but when I try to
conect I get an error, should I make some special config in squid?
squid is not an imap proxy... if you need an imap alg you'll have to
look elsewhere, what it sounds like you need is a nat box...
Hi,
On Wed, Nov 12, julian julian wrote:
Ok, I'm using thunderbird and set the proxy manually, but when I try
to conect I get an error, should I make some special config in squid?
as Amos said, squid is an http proxy. You are looking for an imap proxy
like:
http://www.imapproxy.org/
--
hi, when I change log_ip_on_direct to off in squid.conf, the info change to :
1226524531.343152 10.0.2.110 TCP_MISS/503 2322 GET
http://wiki.squid-cache.org/wiki/squidtheme/img/moin-www.png -
DIRECT/wiki.squid-cache.org text/html
1226524536.129143 10.0.2.110 TCP_MISS/503 2392 GET
zhang yikai wrote:
hi, when I change log_ip_on_direct to off in squid.conf, the info change to :
Sigh. You have said your machine was broken with net access.
We looked and found that it was finding the wrong DNS IPs.
If you want it working, that is what you have to fix.
Amos
Not wishing to sound patronising, but my suggestion would be to not
use Squid to manage all your traffic to the internet. Squid is an
http caching proxy that can also handle https and ftp (kind of) there
is a hell of a lot of internet traffic that is not http. You need a
firewall to control
squid is a http/ftp/gopher proxy. It does not support mail protocols
used by Thunderbird, which are the standards SMTP, POP3 and IMAP4.
squid has nothing to do with thunderbird. There's no need for
special configs because it simply wont work through squid.
julian julian escreveu:
julian julian schrieb:
Because all my traffic to internet is managed by squid. Do you have any
suggestion?
As already said, squid is not an internet proxy (there is no such
thing) but an HTTP proxy, meaning that it only understands HTTP (and a
bit of HTTPS).
Your client talks IMAP with the
julian julian escreveu:
Because all my traffic to internet is managed by squid. Do you have any
suggestion?
no, it's not. Only http/https/ftp/gopher can be handled by squid.
and it wont help keep sending messages asking about IMAP support ...
squid can't do that. period.
--
Hi All
I've been trying to get squid to authenticate against Active Directory
as well as deny access to users in a security group. I have not been
able to get this to work reliably. This is what I have done so far.
In squid.conf, I have these entries
auth_param basic program
Words by Leonardo Rodrigues Magalhães [Wed, Nov 12, 2008 at 02:19:05PM -0200]:
squid is a http/ftp/gopher proxy. It does not support mail protocols
used by Thunderbird, which are the standards SMTP, POP3 and IMAP4.
Not completely right, Thunderbird may also need to do some http to
On Wed, Nov 12, 2008 at 3:32 PM, Gregory Machin [EMAIL PROTECTED] wrote:
Hi
Hello Greg,
I have a client that when he tries to access agentdeal.marvel.com the
web server (IIS) does give a login prompt as it should and instead
returns a 401 error.
[...]
I get the same problem with our proxy
Mine is this
auth_param basic program /usr/lib64/squid/squid_ldap_auth -b DC=XXX,DC=XXX -D
[EMAIL PROTECTED] -w Elmasmejor3567 -f sAMAccountName=%s -h XXX.XXX.XXX.XXX.
1 -s sub -p 389 -v 3 -P -O -R
auth_param basic children 25
auth_param basic realm Squid proxy-caching web server
auth_param
I've read stable10 changelog, do you think upgradint to 10 will fix this?
Luis Daniel Lucio Quiroz wrote:
Using squid 3 stable 9, with digest ldap auth, randomly i got this:
assertion failed: ACLProxyAuth.cc:146:
authenticateValidateUser(auth_user_request)
later, squid dies
Any
Hi, Henrik
Thank you for your reply.
- Question.1
If there is no icap_access setting,
The default icap access control is allow or deny ?
It looks allow...
Should be deny.. icap_access selects which icap class to forward the
request via, and without any icap_access directive there is
Ah. Gottcha. You are wanting a reverse proxy.
Darn, sorry, I should have thought about that distinction, like I said, this is
yet another project on my plate so don't have it all down yet :).
http://wiki.squid-cache.org/SquidFaq/ReverseProxy
contains a usable config for accelerating a
On tor, 2008-11-13 at 05:31 +0900, Mikio Kishi wrote:
In ACLChecklist.cc#check()
128 /* deny if no rules present */
129 currentAnswer(ACCESS_DENIED);
..
188
189 checkCallback(currentAnswer() != ACCESS_DENIED ? ACCESS_DENIED :
ACCESS_ALLOWED);
I
On tis, 2008-11-11 at 16:53 -0600, Luis Daniel Lucio Quiroz wrote:
I have a pcap file captured and, traffic is exchanged and then suddenly a RST
from squid to client.
No FIN before?
Regards
Henrik
signature.asc
Description: This is a digitally signed message part
On tis, 2008-11-11 at 18:56 -0600, Luis Daniel Lucio Quiroz wrote:
Using squid 3 stable 9, with digest ldap auth, randomly i got this:
assertion failed: ACLProxyAuth.cc:146:
authenticateValidateUser(auth_user_request)
later, squid dies
Any comment?
File a bug. Don't forget to include
On ons, 2008-11-12 at 10:06 +0100, Jose wrote:
Binarys are for Windows xp professional. We don't use dhcp, domain. All my
network is in a workgroup without servers.
Transparent interception is not yet officially supported on Windows as
far as I know. But may still work reasonably well if you
On ons, 2008-11-12 at 17:34 +, Jose Celestino wrote:
Not completely right, Thunderbird may also need to do some http to
render html e-mails with external references.
Yuck.. will defenitely stay away from Thunderbird then.
Regards
Henrik
signature.asc
Description: This is a digitally
On ons, 2008-11-12 at 22:33 +0800, howard chen wrote:
If my Apache cannot have gzip enabled, is it possible to gzip the page
using Squid before sending to client?
No. squid requires the web server to do the compression, and also
requires the web server to do it correctly (which most versions
So, do I need to file a bug report, so that this can get addressed? Or
are the devs already aware?
-Original Message-
From: Amos Jeffries [mailto:[EMAIL PROTECTED]
Sent: Tuesday, November 11, 2008 5:56 PM
To: Gregori Parker
Cc: Amos Jeffries; squid-users@squid-cache.org
Subject: RE:
Any chance someone could give me a working config to get me started?
-The server has 2GB of memory and 1TB of space which is can use. There is
nothing else running on it, this is all it will do, be a reverse proxy.
-1 public IP to a named based web server hosting a dozen sites.
-Squid used as
No, no FIN, but RST
On tis, 2008-11-11 at 16:53 -0600, Luis Daniel Lucio Quiroz wrote:
I have a pcap file captured and, traffic is exchanged and then suddenly a
RST from squid to client.
No FIN before?
Regards
Henrik
On Wednesday 12 November 2008 14:58:27 Henrik Nordstrom wrote:
Henrik Nordstrom wrote:
On ons, 2008-11-12 at 17:34 +, Jose Celestino wrote:
Not completely right, Thunderbird may also need to do some http to
render html e-mails with external references.
Yuck.. will defenitely stay away from Thunderbird then.
Regards
Henrik
Don't worry...
After debugin ate level 3
I realize this error happens when analizin http_reply_access with user acl.
Luis Daniel Lucio Quiroz wrote:
Using squid 3 stable 9, with digest ldap auth, randomly i got this:
assertion failed: ACLProxyAuth.cc:146:
authenticateValidateUser(auth_user_request)
Hello,
I am using Squid as reverse proxy in front of a web server (Apache).
If my Apache cannot have gzip enabled, is it possible to gzip the page
using Squid before sending to client?
Not at present. Content encoding is on my worklist, but the bugs and prep
for 3.1 releases are delaying
On ons, 2008-11-12 at 13:51 -0800, Gregori Parker wrote:
So, do I need to file a bug report, so that this can get addressed? Or
are the devs already aware?
The devs are aware (or at least both me and Amos), but please file a bug
report anyway. Much easier for us to track the issue then.
On ons, 2008-11-12 at 16:18 -0600, [EMAIL PROTECTED] wrote:
Any chance someone could give me a working config to get me started?
-The server has 2GB of memory and 1TB of space which is can use. There is
nothing else running on it, this is all it will do, be a reverse proxy.
-1 public IP
On 12-Nov-08 My Secret NSA Wiretap Overheard Amos Jeffries Saying :
Nicole wrote:
On 11-Nov-08 My Secret NSA Wiretap Overheard Nicole Saying :
Hello all
I have started to receive complains from people trying to get video's from
msnbc.com that use a # character in the URL.
Such as:
Ah. Gottcha. You are wanting a reverse proxy.
Darn, sorry, I should have thought about that distinction, like I said,
this is yet another project on my plate so don't have it all down yet :).
http://wiki.squid-cache.org/SquidFaq/ReverseProxy
contains a usable config for accelerating a
I've read stable10 changelog, do you think upgradint to 10 will fix this?
I don't know of anything that might do it thats not already in s9.
Always worth a shot though just in case and to get the current assert
location.
Amos
Luis Daniel Lucio Quiroz wrote:
Using squid 3 stable 9, with
I've read stable10 changelog, do you think upgradint to 10 will fix this?
I don't know of anything that might do it thats not already in s9.
Always worth a shot though just in case and to get the current assert
location.
Our bugzilla is at http;//bugs.squid-cache.org/
Amos
Luis Daniel
Hi, Henrik
I think it may be ACCESS_ALLOWED if currentAnswer is ACCESS_DENIED, right ?
Hmm.. that indeed looks wrong..
It should be initialized to ACCESS_ALLOWED.
And affects every access list without a default.. not just icap_access.
That's right! I think so, too
Please file a bug
I'm trying to get the squid_radius_auth working and have tried to manually
connect to my Microsoft radius server. I cannot get an ok for a response when
manually testing the connection. Although, I can see the attempts in my
Microsoft radius server log so I know I'm hitting it. I have a
Hi All,
Most of the requests served by squid has expire time of 1 hour because
of this we are not seeing expected HIT ratio. What would be
refresh_pattern rule we should apply to get higher HIT ratio ?
Cache_mem is 2 GB and cache_dir is 6 GB.
Currently we are using following refresh pattern
Hi,
I am about to take ownership of a new 2CPU, 4 core server with 32GB of
RAM - I intend to add the server to my squid reverse proxy farm. My
site is approximately 300GB including archives and I think 32GB of
memory alone will suffice as cache for small, hot objects without
necessitating any
52 matches
Mail list logo