Re: [squid-users] How to clear old cache

2009-04-01 Thread Amos Jeffries
Hi All, How do I remove old squid cache? I have googled for the problem but couldnot get the proper way to delete cache. Every one said to delete the cache folder and rebuild the cache folder again with command squid -z. Our server cache not rebuild from long time, Is there a way to

Re: [squid-users] Anyone Have Large Amounts of Public IP's?? WILL PAY :)

2009-04-01 Thread Amos Jeffries
Hi there On Tue, 31 Mar 2009, Amos Jeffries wrote: Cut Back on topic with a blatant marketing edge: Squid-3.1 is the release which allows you to handle both IPv4 and IPv6 web requests and replies. To solve the issues of HTTP access between each of those spaces. Works like a charm

Re: [squid-users] Problem using ncsa_auth on MacOS X

2009-04-02 Thread Amos Jeffries
, 2009 à 12:48 PM, Amos Jeffries a écrit : Cédric Vuillet wrote: Hello, I am new to squid. I installed it on MacOS X using Fink. It works but I cannot use simple authentification. I tried to use ncsa_auth, but it's not installed on MacOS X (10.4.9 or 10.5.3). So I don't know if I must install

Re: [squid-users] Tracking the Denied messages delivered to user

2009-04-02 Thread Amos Jeffries
Truth Seeker wrote: Any feeds on this regard... it would be fine to know whether this will be possible or not. If possible, can someone shed a light on it I'm wanting to look at this long-term, but short-term its pretty hard. There is a lot of re-working of various systems to get it

Re: [squid-users] Squid sibling/parent configuration Error

2009-04-02 Thread Amos Jeffries
bharathvn wrote: Hi, I am trying to implement 2 squid server with sibling and parent as mentioned below. Scenario INTERNET | | USER(a.a.a.a) -Squid 1(Sibling)(a.a.a.a) Squid

Re: [squid-users] Squid problem servlet IWSS

2009-04-02 Thread Amos Jeffries
projpr...@libero.it wrote: Hi, I have really big problem in setting up squid with IWSS. What I mean, I managed to let work Squid as proxy and Interscan web security suite from Trendmicro as parent proxy in order to scan all the files. Well...everything works and going to download, for example,

Re: [squid-users] TProxy HELP

2009-04-02 Thread Amos Jeffries
Jamie Orzechowski wrote: I have running squid 3.1.0.6 with TProxy on 2.6.28-11 (Ubuntu 64bit) For some reason ALL my traffic shows up as a TCP_MISS ... If I revert back to transparent mode evertything is fine. If I switch to tproxy everything shows as a TCP_MISS. Why is this happening?

Re: [squid-users] ACLs

2009-04-02 Thread Amos Jeffries
Merdouille wrote: Hi i use a transparent squid proxy and i want : - access as manager with squidclient from localhost only == http_access allow manager localhost - allow only computer from localhost to go every where == http_access allow locahost These ACL you ask about are the

Re: [squid-users] Problem using ncsa_auth on MacOS X

2009-04-02 Thread Amos Jeffries
--enable-basic-auth-helpers=NCSA (don't forget to list any others you need too) Amos Le Apr 2, 2009 à 12:05 PM, Amos Jeffries a écrit : Cédric Vuillet wrote: Hello, I used Darwinport to install squid this time. So I have a newer version : squid @2.7.STABLE6_0+darwin_9 But I have same problem

Re: [squid-users] ACLs

2009-04-03 Thread Amos Jeffries
Merdouille wrote: I used : http_access allow manager localhost http_access allow localnet PROTO METHOD http_access deny all !port I try to add deny_info options : deny_infoTCP_RESET !manager !localhost deny_infoTCP_RESET !localnet deny_info

Re: [squid-users] looking for a tutorial for Win2k3 AD integration with Squid

2009-04-03 Thread Amos Jeffries
Abdul Khan wrote: Hi, Can anybody provide me with a good tutorial on how to integrate windows 2003 AD to authenticate Squid using NTLM. My environment is CenOS5 running Squid 2.6 and Windows 2003 R2 Standard (LDAP v3). Thanks in advance A. Khan http://wiki.squid-cache.org/ConfigExamples

Re: [squid-users] understanding how squid disk load scales

2009-04-03 Thread Amos Jeffries
Gavin McCullagh wrote: Hi, our squid system (according to our munin graphs), is suffering rather from high iowait. I'm also seeing warnings of disk i/o overloading. I'm interested to understand how this disk load scales. I know more disks (we only have a single cache disk just now) would be

Re: [squid-users] how can buid this requeriment with squid=

2009-04-03 Thread Amos Jeffries
maximatt wrote: hi i have a squid cache running ok with auth-ldap and all works fine but... i need to permit access to a external ip without ask for authorization... or any other restriccion... so.. i try to make some acl.. without results... i look documentation that it's not

Re: [squid-users] hi i need help please, transparent proxy with AUth

2009-04-03 Thread Amos Jeffries
Rodrigo Gliksberg wrote: Hello a ihave mount server OpenBSD 4.4 with squid 2.7, and squidguard, i need to my boos transparent mode with AUTHENTICATION?, was is not posible, from squid, any can help with any idea. i think use a php app, to manage sessions in mysql, and with external acl one

Re: [squid-users] Squid Scalability

2009-04-03 Thread Amos Jeffries
Sunny Bhatheja wrote: Hi, I have the following configuration of my Hardware. So can any one suggest me that how much I can scale my Squid in terms of users. 1) Sun Fire system x4450 2) Quad Cord 3) 64 GB RAM 4) 146x4 GB HDD I am using squid 2.6 STABLE4 that is

Re: [squid-users] acl dstdomains does not block!

2009-04-03 Thread Amos Jeffries
Leslie Jensen wrote: Hello My Proxy, Squid-3.0.13 on FreeBSD 7.1-RELEASE-p4, is running fine but I can't get the folowing to work. # acl blocked_sites dstdomain .aftonbladet.se. acl blocked_sites dstdomain /usr/local/etc/squid/dstdomain deny_info ERR_ACCESS_DENIED blocked_sites

Re: [squid-users] Massive Squid Deployment

2009-04-03 Thread Amos Jeffries
anyone know if this issue is still present in 2.7 code? Henrik knows more, but I believe its the same in all Squid-2 code. IIRC it was an architecture change that fixed it in 3.0. Amos Thanks, -C On Apr 1, 2009, at 12:42 AM, Amos Jeffries wrote: Hello people, I'm having some bottlenecks

Re: [squid-users] Invalid Response/Malformed

2009-04-03 Thread Amos Jeffries
Bruno Guerreiro wrote: Hi Amos, -Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: quarta-feira, 1 de Abril de 2009 2:38 To: Bruno Guerreiro Cc: squid-users@squid-cache.org Subject: Re: [squid-users] Invalid Response/Malformed snip By all appearances you

Re: [squid-users] Squid Scalability

2009-04-03 Thread Amos Jeffries
Excellent thank you. Email the info to squid-...@squdi-cache.org mailing list please. Amos --- On Fri, 4/3/09, Amos Jeffries squ...@treenet.co.nz wrote: From: Amos Jeffries squ...@treenet.co.nz Subject: Re: [squid-users] Squid Scalability To: Sunny Bhatheja opensource.linu...@gmail.com Cc: squid

Re: [squid-users] Squid Scalability

2009-04-03 Thread Amos Jeffries
Gavin McCullagh wrote: On Fri, 03 Apr 2009, Amos Jeffries wrote: Despite many years of asking, few people have ever supplied the squid project with relevant benchmarking info. We depend on volunteers so there are no hard numbers available publicly yet. Is there a doc stating exactly what

Re: [squid-users] Squid Scalability

2009-04-03 Thread Amos Jeffries
, its only a once-off approval for anti-spam measure). Amos Thanks, Quin --- On Fri, 4/3/09, Amos Jeffries squ...@treenet.co.nz wrote: From: Amos Jeffries squ...@treenet.co.nz Subject: Re: [squid-users] Squid Scalability To: Sunny Bhatheja opensource.linu...@gmail.com Cc: squid-users@squid

Re: [squid-users] Multiple reverse proxies for multiple projects

2009-04-03 Thread Amos Jeffries
Frank Helmschrott wrote: Hi all, I'd like to have a setup for 3 or 4 servers with squid (identical configuration) that all work as a reverse proxy for different projects with different domains/URLs on 5-6 productive servers. I've tried several configuration variations to have different

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-03 Thread Amos Jeffries
Riccardo Castellani wrote: I have to install new Linux server, based on ONLY on text console (not X server, not kde, not gnome) to having squid as parent cache. Then I have to configure sendmail which relays messages to 3 perimetral mail servers. I'm thinking to install Debian or Ubuntu

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-03 Thread Amos Jeffries
Riccardo Castellani wrote: I don't understand. The big difference between Debian and Ubuntu is the X server/kde/gnome GUI interface. Once you eliminate that you may as well flip a coin to choose. Amos - Original Message - From: Amos Jeffries squ...@treenet.co.nz To: Riccardo

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-03 Thread Amos Jeffries
Riccardo Castellani wrote: Ok, but about level package updates frequency ? Code gets into Debian, then migrates to Ubuntu from there after a further short delay. About most supported hardware ? same. About stability ? same. - Original Message - From: Amos Jeffries squ

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-05 Thread Amos Jeffries
Rob van der Putten wrote: Hi there On Sat, 4 Apr 2009, Amos Jeffries wrote: The big difference between Debian and Ubuntu is the X server/kde/gnome GUI interface. Once you eliminate that you may as well flip a coin to choose. You can choose the desktop / window manager. Ubuntu Gnome

Re: [squid-users] difference between redirect program and rewrite program

2009-04-05 Thread Amos Jeffries
sameer shinde wrote: Hi All, What is the difference between redirect_program and url_rewrite_program in squid3? redirect_program is the obsolete name for url_rewrite_program. Amos -- Please be using Current Stable Squid 2.7.STABLE6 or 3.0.STABLE13 Current Beta Squid 3.1.0.6

Re: [squid-users] Not Anonymous ?

2009-04-05 Thread Amos Jeffries
Julien P. wrote: Hi there, I wasn't able to find any information on a non anoymous proxy server... I'm running one squid server for many people located in different places/countries and I'm running into several issues. For example: Their language is not well recognized on some websites because

Re: [squid-users] Error File size limit exceeded

2009-04-05 Thread Amos Jeffries
Wong wrote: I found error message below and squid unable to run. --snip-- [r...@squid root]# squid -NCDd1 File size limit exceeded maybe logfile is too large. Yes, you're right. After rebuilding directory of log file, squid run well are you running a 32bit squid? I am using 2.6S21.

Re: [squid-users] Can a guru verify my config?

2009-04-05 Thread Amos Jeffries
Hello, I'm placing a few details you may need to be aware of inline to reply to your latest post, followed by the help you asked for in your first post. What the heck kind of reply is this and why did you send it to my email address and not post it in the forums! Sending replies like this are

Re: [squid-users] Can a guru verify my config?

2009-04-05 Thread Amos Jeffries
When you are confidant about this going, we can move on to the HTTPS and failover questions. Amos Hi Guys, Sorry that I am dropping in on this thread, but it reminded me that I need to find this out. I am working on a active-active firewall for a customer. It will be two Linux boxes

Re: [squid-users] Fail-over config

2009-04-05 Thread Amos Jeffries
I am working on a active-active firewall for a customer. It will be two How did my thread remind you of this? :). By the way, my currently is a multi-web server setup with a dual LVS front end. Once I finally get squid working as a reverse, the idea is to put a couple of load balanced

Re: [squid-users] Squid Scalability

2009-04-06 Thread Amos Jeffries
Gavin McCullagh wrote: Hi, On Sat, 04 Apr 2009, Amos Jeffries wrote: For now what we need are the hit/miss ratios and user numbers from Squid under peak load, and a few other details to guide comparisons. http://wiki.squid-cache.org/KnowledgeBase/Benchmarks details what we are looking

Re: [squid-users] Re: Fail-over config

2009-04-06 Thread Amos Jeffries
Heinz Diehl wrote: On 06.04.2009, rightfoot wrote: cache_dir ufs /var/spool/squid 40100 16 256 ^^^ If speed matters, I personally would change this to aufs. Please read the FAQ and manual what this change results in, you simply can't change it in your squid.conf,

Re: [squid-users] Re: Re: Fail-over config

2009-04-06 Thread Amos Jeffries
Heinz Diehl wrote: On 06.04.2009, Amos Jeffries wrote: Only the algorithm to access that storage changes so only a reconfigure is needed to change between these three (if squid is built with them all). ^^^ That was my

Re: [squid-users] Squid Scalability

2009-04-06 Thread Amos Jeffries
Gavin McCullagh wrote: Hi, On Mon, 06 Apr 2009, Amos Jeffries wrote: Thank you. Added. What sort of CPU load does it run under? Very high, but the web still feels reasonably responsive in general. The load average peaked yesterday at 9 but this is since I reduced the cache size. It hit 30

Re: [squid-users] Squid Scalability

2009-04-06 Thread Amos Jeffries
Gavin McCullagh wrote: On Mon, 06 Apr 2009, Amos Jeffries wrote: Ah, sorry I meant CPU load as reported by Squid in %: It can be extracted from the general runtime information or info cachemgr page. It's the value marked CPU Usage I'll hold off until a peak time and check. If it's

[squid-users] Re: cache-peer problem - query string requests

2009-04-06 Thread Amos Jeffries
Vivek wrote: Hi All, I am using squid 2.7 and configured Polipo server as a parent of squid.. cache_peer 172.16.1.40 parent8123 3130 no-query default I think maybe heirarchy_stoplist is set in your Squid. Be aware there are bugs when Squid sends dynamic requests to peers which

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-06 Thread Amos Jeffries
Pandu E Poluan wrote: Anyone care to comment on my email? And another question: Is it possible to use miss_access with a dstdomain acl? Rgds. Pandu E Poluan wrote: Hi, I want to know is there a way to force a URL to be retrieved by only a certain proxy, while ensuring that meshing

Re: [squid-users] Squid Scalability

2009-04-06 Thread Amos Jeffries
Gavin McCullagh wrote: Hi, On Tue, 07 Apr 2009, Amos Jeffries wrote: Gavin McCullagh wrote: Mine too. The operating system is on linux software RAID1 partitions so I Ah, there we probably have the answer as to why there is so much iowait. I'm not convinced of that. The iowait seems

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-06 Thread Amos Jeffries
miss_access allow all siblings must never go direct to the object (always use their parent peer) proxyB/proxyC: never_direct allow objectX Amos Amos Jeffries wrote: Pandu E Poluan wrote: Anyone care to comment on my email? And another question: Is it possible to use miss_access

Re: [squid-users] Squid-tproxy patch for squid 3.0

2009-04-06 Thread Amos Jeffries
Vivek wrote: Hi All, I need squid tproxy patch for squid 3.0. I know squid 3.1 has the built-in code for tproxy support. But i need the patch file. Where can i download the patch( Not kernel patch) squid-tproxy patch?. If anybody knows give the link. The patch I and others were

Re: [squid-users] Squid 3.1.6, zph, shorewall, and tc on debian 5.0 (lenny)

2009-04-06 Thread Amos Jeffries
Jason wrote: Everyone, I have compiled squid 3.1.6 from source on amd64 Debian 5.0 with NP: please use the correct version numbering: 3.1.0.6. there will probably be a 3.1.6 at some point in the future and hopefully this problem will not apply to those users, best not to add confusion.

Re: [squid-users] defaultsite=domainname?

2009-04-07 Thread Amos Jeffries
louis gonzales wrote: Dist, Squid 2.7.Stable6 I'm setting up a reverse proxy, such that the Squid system will be viewed as the originserver to the clients contacting it. Does the defaultsite= attribute get the name of the actual web server or the proxy server? defaultsite= is the public

Re: [squid-users] cache_peer over openvpn

2009-04-07 Thread Amos Jeffries
jonnytabpni wrote: Hi folks, I have an openvpn server which also runs squid. I wish this squid server to use a squid server running on a openvpn client as it's parent cache. It's not working. The connection to to remote openvpn client times out. Access to the openvpn client is OK everwhere

Re: [squid-users] Squid Reverse proxy cache Storage for Vhosts

2009-04-07 Thread Amos Jeffries
Prabhakar, Ramprasad (GE, Corporate, consultant) wrote: For a squid reverse proxy cache, is there a way to set squid to use a single cache storage for all the virtual hosts it hosts ? For example, abc.domain.com, cde.domain.com, fgh.domain.com all point to the same site. Will Squid storage

Re: [squid-users] cache-peer problem - query string requests

2009-04-07 Thread Amos Jeffries
Vivek wrote: Hi All, I am using squid 2.7 and configured Polipo server as a parent of squid.. cache_peer 172.16.1.40 parent8123 3130 no-query default But all the requests go via Polipo except the URLs with query ? string. How do we force the squid to send all the request to

Re: [squid-users] defaultsite=domainname?

2009-04-07 Thread Amos Jeffries
proxy server appear as the origin server. Aha, hopefully my new additions there will reduce that ambiguity a little. Amos On Tue, Apr 7, 2009 at 3:30 AM, Amos Jeffries squ...@treenet.co.nz wrote: louis gonzales wrote: Dist, Squid 2.7.Stable6 I'm setting up a reverse proxy, such that the Squid

Re: [squid-users] acl dstdomains does not block!

2009-04-07 Thread Amos Jeffries
Leslie Jensen wrote: 2009/4/6 Leslie Jensen les...@eskk.nu Leslie Jensen wrote: Hello My Proxy, Squid-3.0.13 on FreeBSD 7.1-RELEASE-p4, is running fine but I can't get the folowing to work. # acl blocked_sites dstdomain .aftonbladet.se. acl blocked_sites dstdomain

Re: [squid-users] Squid-tproxy patch for squid 3.0

2009-04-07 Thread Amos Jeffries
Vivek wrote: Thanks Amos, We want Tproxy v4 support ( 2.6.28 kernel support) for squid 2.7. If we could get squid-3.0-tproxy patch from any achieves it would be very helpful for us to develop a patch for 2.7.. There no single patch just a large collection of incremental changes. The 2.7

Re: [squid-users] defaultsite=domainname?

2009-04-07 Thread Amos Jeffries
louis gonzales wrote: Amos, Here's a challenge, I can't find the reason why the Header rewrite is not happening? My configuration has only 1 web server(unified1.abstract.net, IP:192.168.0.10) behind the reverse proxy server(proxy1.abstract.net, IP: 192.168.0.20) What I want the reverse proxy

Re: [squid-users] ...Memory-only Squid questions

2009-04-07 Thread Amos Jeffries
Gregori Parker wrote: Glad to help David, please let us know how it progresses. Dont know if you saw this in the archives: http://www.mail-archive.com/squid-users@squid-cache.org/msg19824.html but it might help guide you on your SO_FAIL issue. It might be worth moving to LRU and establishing

Re: [squid-users] defaultsite=domainname?

2009-04-07 Thread Amos Jeffries
be anything the squid box can resolve. Amos On Tue, Apr 7, 2009 at 4:05 AM, Amos Jeffries squ...@treenet.co.nz wrote: louis gonzales wrote: Amos, Yes did seen these. My specific question, results from the fact that the information provided for defaultsite=mysite.domain.com (not origin

Re: [squid-users] Question on Strange network setup with 2 Squid servers.

2009-04-07 Thread Amos Jeffries
Michael D. Setzer II wrote: My College has two 10Mb connections to two ISPs. The campus has 4 Class C networks from the one ISP. 202.128.71.x 202.128.72.x 202.128.73.x 202.128.79.x The Router has the .1 on all 4 networks. The second ISP connects to the same router, but links via the IP address

Re: [squid-users] Strange problem accessing http://Bloomberg.com

2009-04-07 Thread Amos Jeffries
Hello, I ma having a very bizarre problem and I am wondering if anyone here can shed some light on it. Our internal users are accessing the Internet via a squid v2.6-STABLE9 proxy using a proxy.pac file. Their browsers (corporate dictates Internet Explorer) are configured to Automatically

Re: [squid-users] Problem with acl helper

2009-04-07 Thread Amos Jeffries
Hello, i have proxy server transparent running in OpenBSD 4.4 with Mysql cautive portal i create acl helper, to lookup mysql database, this return ej squid put 192.168.35.121 OK user=$usuerofdb\n this is work fine, but my problem is when i need loggin other user from 192.168.35.121 ,

Re: [squid-users] Strange problem accessing http://Bloomberg.com

2009-04-07 Thread Amos Jeffries
So I think the client's proxy.pac script might be having trouble digesting the malformed URL below: 1239113823.055 0 xxx.yyy.zzz.aaa TCP_DENIED/400 1614 GET http://'wbetest2.bloomberg.com/jscommon/0/s_code.js' - NONE/- text/html The single quote is making the proxy.pac freeze which in

Re: [squid-users] Getting error msgs when trying to start squid

2009-04-07 Thread Amos Jeffries
I'm trying to run squid but I'm getting a few error msgs: * Starting Squid HTTP proxy squid 2009/04/07 13:25:53| parseConfigFile: squid.conf:67 unrecognized: 'wais_relay_port' 2009/04/07 13:25:53| parseConfigFile: squid.conf:100 unrecognized: 'incoming_icp_average' 2009/04/07 13:25:53|

Re: [squid-users] Reverse Proxy + Multiple Webservers woes

2009-04-07 Thread Amos Jeffries
Hello, I am new to squid but not new to reverse proxies. I am trying to implement a proxy that would work like this: www.example.com - server 1 example.com - server 1 dev.example.com - server 2 I have read the wiki here: wiki.squid-cache.org/SquidFaq/ReverseProxy But I cant get

Re: [squid-users] Reverse Proxy + Multiple Webservers woes

2009-04-07 Thread Amos Jeffries
Karol Maginnis wrote: Hello, I am new to squid but not new to reverse proxies. I am trying to implement a proxy that would work like this: www.example.com - server 1 example.com - server 1 dev.example.com - server 2 I have read the wiki here:

Re: [squid-users] Re: Re: why RELEASE?

2009-04-07 Thread Amos Jeffries
On Thu, 2009-04-02 at 11:35 +1200, Amos Jeffries wrote: IIRC, non-cachable objects larger than max_object_size_in_memory get a disk object saved for the transition buffer then released when completed whether they need it or not. One of the inefficiencies we are working towards killing. OK

Re: [squid-users] ...Memory-only Squid questions

2009-04-07 Thread Amos Jeffries
David Tosoff wrote: Thanks Chris. I had already read both of the wiki post and the thread you directed me to before I posted this to the group. Excellent. I already had compiled heap into my squid before this issue happened. I am using heap GDSF. And, I wasn't able to find

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-07 Thread Amos Jeffries
suspicious all along that the solution uses miss_access and never_direct ... but never saw an example anywhere. Again, much thanks! ** rushes to his proxies to configure them ** Rgds. [p] Amos Jeffries wrote: Pandu E Poluan wrote: The URL is allowed to be accessed by everyone, ProxyA-users

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-07 Thread Amos Jeffries
to configure them ** Rgds. [p] Amos Jeffries wrote: Pandu E Poluan wrote: The URL is allowed to be accessed by everyone, ProxyA-users, and ProxyB/C-users alike. I just want the URL to be retrieved by ProxyA, because accessing that certain URL through ProxyB/C is too damn slow (pardon

Re: [squid-users] transparent proxy for CONNECT method

2009-04-07 Thread Amos Jeffries
nyoman karna wrote: dear squid-users, it's been long I've accepted the fact that transparent proxy will not work for CONNECT method because of security issues (considered as man-in-the-middle attack). but perhaps there's a way to get around this problem? because everyone will stuck with using

Re: [squid-users] Getting error msgs when trying to start squid

2009-04-07 Thread Amos Jeffries
Henrique M. wrote: twinturbo-2 wrote: Also what version are you running? is this a hand crafted config or one borrowed from somwhere else? Post up the confg from lines 66 to 106 Rob I was running the default squid for ubuntu server 8.10 which is the version 2.7 stable. I'm using the

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-07 Thread Amos Jeffries
and ProxyC? Rgds. Pandu E Poluan wrote: Aha! Thanks a lot, Amos :-) I have been suspicious all along that the solution uses miss_access and never_direct ... but never saw an example anywhere. Again, much thanks! ** rushes to his proxies to configure them ** Rgds. [p] Amos Jeffries

Re: [squid-users] Re: Want to create SQUID mesh, but force certain URLs to be retrieved by only one Proxy

2009-04-08 Thread Amos Jeffries
[p] Amos Jeffries wrote: Pandu E Poluan wrote: Okay, some experimentations I made: I added the following lines on ProxyB: # lines from Amos' tip acl fastsites dstdomain .need-fast-inet.com acl fastsites dstdomain .another-need-fast-inet.com never_direct allow fastsites Changes on ProxyA

Re: [squid-users] CONNECT method support(for https) using squid3.1.0.6 + tproxy4

2009-04-08 Thread Amos Jeffries
Hi, all Now, I evaluate the squid3.1.0.6 + tproxy4 environment like the following network. (1) (2) | | +--+ | ++|+-+ |WWW +---+ ||++ WWW |

RE: [squid-users] Custom error page based on IP.

2009-04-08 Thread Amos Jeffries
Sorry for the somewhat large delay in replying to you, I have been on longish term sick. However I've just returned and have sussed this out. Firstly I added the following rules to squid.conf. acl swan src 123.45.0.0/16 # The campus subnet, which was already defined in squid.conf

Re: [squid-users] squid authentication and redirection

2009-04-08 Thread Amos Jeffries
Dear Squid users, I was wondering if the following can be accomplished in squid: Say, a user starts using the proxy 1 he is not logged, so he gets redirected to a webpage over https 2 the webpage authenticates him, and sets a cookie in his browser 3 he is then redirected to the original

Re: [squid-users] Getting error msgs when trying to start squid

2009-04-08 Thread Amos Jeffries
Amos Jeffries-2 wrote: 'error messages' in web terminology means something completely different which can be 'kept'. I assume you mean where doe sit send the startup error output? That is usually sent to syslog by Debian/Ubuntu during init process and then when squid is going to the /var

Re: [squid-users] SSL on Squid Reverse Proxy

2009-04-08 Thread Amos Jeffries
Using latest stable squid2.7.6 Using Squid as a reverse proxy. Got a setup of Squid -- web server -- java site works fine in normal HTTP port 80. Need to enable SSL for the site also. so I added https_port x.x.x.x:443 cert=/site_name.com.cert key=/site_name.com.key vhost and

Re: [squid-users] Squid 2.7.STABLE6 - peerDigestFetchAbort peer 192.168.0.1 Bad Request

2009-04-09 Thread Amos Jeffries
louis gonzales wrote: I need help understanding what the following cache.log information means? Please. 2009/04/09 00:35:08| The request GET http://unified1.abstract.net:80/tc/fms/513901874/mygroup/FSC_unified1_Administrator is ALLOWED, because it matched 'FMS' 2009/04/09 00:35:08|

Re: [squid-users] CONNECT method support(for https) using squid3.1.0.6 + tproxy4

2009-04-09 Thread Amos Jeffries
Mikio Kishi wrote: Hi, Amos HTTPS encrypted traffic cannot be intercepted. Yes, I know that. but, in this case, not transparent. (1) (2) | | +--+ | ++|+-+ |WWW +---+ |

Re: [squid-users] Squid Host header rewriting

2009-04-09 Thread Amos Jeffries
Juha Luoma wrote: Hi, Squid rewrites the host header as follows: GET http://194.137.237.63/uutiset/ HTTP/1.1\r\n Host: www.hs.fi\r\n - GET /uutiset/ HTTP/1.0\r\n Host: 194.137.237.63\r\n Why is that? Because mismatch between Host: header and real destination wanted is how

Re: [squid-users] Complex Reverse Proxy setup

2009-04-09 Thread Amos Jeffries
schwermie wrote: At our company we have a complex setup. external URL internal URL www.example.com/ - www.example.com www.example.com/subdir - www.example2.com www.webserver.com - www.example.com/webserver www.server.com:1800 - www.server.com:1800 Could

Re: [squid-users] Squid 3.1.0.6, zph, shorewall, and tc on debian 5.0 (lenny)

2009-04-09 Thread Amos Jeffries
Jason wrote: Jason wrote: Amos, Thanks for answering. Amos Jeffries wrote: Jason wrote: Everyone, I have compiled squid 3.1.6 from source on amd64 Debian 5.0 with NP: please use the correct version numbering: 3.1.0.6. there will probably be a 3.1.6 at some point in the future

[squid-users] Squid 3.1.0.7 beta is available

2009-04-09 Thread Amos Jeffries
-mirrors.dyn http://www.squid-cache.org/Download/mirrors.dyn If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

Re: [squid-users] Getting error msgs when trying to start squid

2009-04-09 Thread Amos Jeffries
Henrique M. wrote: Amos Jeffries-2 wrote: httpd_accel has been obsolete for more than 3 years now. Where did you get that config? I know it does not come with the packaged squid/squid3 on any current Ubuntu. Considering that you have on apparently brand new installs encountered two sets

Re: [squid-users] Getting error msgs when trying to start squid

2009-04-09 Thread Amos Jeffries
Amos Jeffries wrote: Henrique M. wrote: Amos Jeffries-2 wrote: httpd_accel has been obsolete for more than 3 years now. Where did you get that config? I know it does not come with the packaged squid/squid3 on any current Ubuntu. Considering that you have on apparently brand new installs

Re: [squid-users] TCP_MISS/600 Squid 2.6S6 and Dansguardin

2009-04-09 Thread Amos Jeffries
Marco Leone wrote: Hi, I haven't been able to solve this issue on my own so I'm writing here hoping to receive some feedback. I use a same host squid/dansguardian combination for 5/6.000 active users. Some of the users are complaining they can't reach a particular web page. I can reach the

Re: [squid-users] Config for multiplexing non-caching proxy

2009-04-09 Thread Amos Jeffries
Chris Woodfield wrote: Hi, I've noticed that either by design or as a side-effect of squid's caching that if I request the same object from multiple clients at the same time, squid will effectively multiplex the transfer - that is, use a single transfer from origin to feed the object to each

Re: [squid-users] FW: timeouts when proxying youtube

2009-04-09 Thread Amos Jeffries
Harvey Dueck wrote: I am running squid 3 on Fedora 10. Something is causing an unreasonable number of timeouts when clients access high definition videos on youtube through the proxy. I am not trying to cache or otherwise manipulate the youtube content. The symptom is that the video always

Re: [squid-users] Cannot get ncsa_auth to work

2009-04-09 Thread Amos Jeffries
MisterWolfe wrote: What follows is my squid.conf - can you please help me figure out why ncsa auth is not working? is my conf file screwed up somehow? thanks!!! ###Specifies the NCSA user Authentication auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd auth_param basic

Re: [squid-users] Squid 3.1.0.7 beta is available

2009-04-09 Thread Amos Jeffries
Guy Helmer wrote: Amos Jeffries wrote: The Squid HTTP Proxy team is very pleased to announce the availability of the Squid-3.1.0.7 beta release! The last two months have seen a lot of code being polished up and shuffled around. This release is purely a testing bundle for those changes

Re: [squid-users] 3.1.0.7 and langpack

2009-04-10 Thread Amos Jeffries
Florian wrote: Hello List, i installed squid 3.1.0.7. Squid missed the german langfiles and so i added the actual langpack: squid-3.HEAD-20090410-langpack.tar.gz Now the squid complains about missing langfiles for de-de. Now i copied the the .../errors/de directory to .../errors/de-de and

Re: [squid-users] -D obsolete?

2009-04-10 Thread Amos Jeffries
Florian wrote: Hello List, i installed squid 3.1.0.7. When i start the squid it writes to the screen: Starting squid: 2009/04/10 22:21:12| WARNING: -D command-line option is obsolete. The manpage for squid_3.1.0.7 knows the -D Option. How to disable the initial DNS-Tests? Is the manpage

Re: [squid-users] Config for multiplexing non-caching proxy

2009-04-10 Thread Amos Jeffries
in reverse proxies and the setting is to explicitly turn it on for forward proxies as well. Amos -C On Apr 10, 2009, at 12:26 AM, Amos Jeffries wrote: Chris Woodfield wrote: Hi, I've noticed that either by design or as a side-effect of squid's caching that if I request the same object from

Re: [squid-users] Squid detects open redirect vulnerability ?

2009-04-11 Thread Amos Jeffries
of the really nice stuff in ubuntu is around the GUI. --Yan - Original Message - From: Amos Jeffries squ...@treenet.co.nz To: Riccardo Castellani ric.castell...@alice.it Cc: squid-users@squid-cache.org Sent: Friday, April 03, 2009 10:59 PM Subject: Re: [squid-users] Squid : better on Debian

Re: [squid-users] TCP_DENIED on youtube

2009-04-11 Thread Amos Jeffries
Stefan Jensen wrote: Hi,... i got some TCP_DENIED on youtube.com: TCP_DENIED/403 3446 GET http://googleads.g.doubleclick.net/pagead/ads? - NONE/- text/html It is an embedded ad page on youtube in the upper right. (e.g: http://www.youtube.com/browse) I have this in my squid.conf: acl

Re: [squid-users] Initial webpage before surfing on squid

2009-04-11 Thread Amos Jeffries
Jorge Bastos wrote: Chris, I was doing some tests to see the value that is passed by the %s variable, and the value that goes to the output is: --- http://195.23.114.74/inicial.php?url=http%3A%2F%2F195.23.114.74%2Finicial.ph

Re: [squid-users] Cache directory size decreased

2009-04-11 Thread Amos Jeffries
Wilson Hernandez - MSD, S. A. wrote: Hello.. I've noticed that my server's /var/log/squid/cache decreased from 37G to 35G. I just need to know if this is normal. thanks. From only that info, I'd say its normal. Cache grows all the time, and when garbage collection happens or files are

[squid-users] Squid 3.0.STABLE14 is available

2009-04-11 Thread Amos Jeffries
of mirror sites see http://www.squid-cache.org/Download/http-mirrors.dyn http://www.squid-cache.org/Download/mirrors.dyn If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

Re: [squid-users] CONNECT method support(for https) using squid3.1.0.6 + tproxy4

2009-04-11 Thread Amos Jeffries
On Thu, Apr 9, 2009 at 4:54 PM, Amos Jeffries squ...@treenet.co.nz wrote: Mikio Kishi wrote: Hi, Amos HTTPS encrypted traffic cannot be intercepted. Yes, I know that. but, in this case, not transparent. (1) (2

Re: [squid-users] Initial webpage before surfing on squid

2009-04-12 Thread Amos Jeffries
Jorge Bastos wrote: Try this: echo rawurldecode($_GET['url']); Its a little weird that the redirect URL is being added as the sub-URI. Are you sure your http_access are permitting access to the splash URI before checking the session handler? Amos Hi Amos, Well, the rawurldecode()

Re: [squid-users] Initial webpage before surfing on squid

2009-04-12 Thread Amos Jeffries
Jorge Bastos wrote: That passes a 302:http://195.23.114.74/inicial.php?url=... back to the client. If the client then requests from Squid: http://195.23.114.74/inicial.php?url=... and if squid is not configured to unconditionally accept the http://195.23.114.74/inicial.php; requests this

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-12 Thread Amos Jeffries
. And about kernel ? they use same version ? same, though Deb is usually newer by a few months to a year. Amos - Original Message - From: Amos Jeffries squ...@treenet.co.nz To: Riccardo Castellani ric.castell...@alice.it Cc: squid-users@squid-cache.org Sent: Friday, April 03, 2009 11

Re: [squid-users] Squid : better on Debian or Ubunto server ?

2009-04-12 Thread Amos Jeffries
the Debian packages, apply some patches to integrate some stuff with their GUI and rebuild. * ubuntu users get updates Amos - Original Message - From: Amos Jeffries squ...@treenet.co.nz To: Riccardo Castellani ric.castell...@alice.it Cc: squid-users@squid-cache.org Sent: Friday, April 03, 2009

[squid-users] Re: Just delete, had problems with SPF rules, testing!!!!

2009-04-12 Thread Amos Jeffries
Leslie Jensen wrote: Sorry to disturb, mails to the list and to amos has been bouncing for me. /Leslie FYI: my email is IPv6-enabled. It contains an '' to let me send outbound past the SPF. People using the recommended policy-spf.pl need to ensure their perl package Net::DNS is up to

<    4   5   6   7   8   9   10   11   12   13   >