Re: [squid-users] New Squid prefers IPv4

2024-02-06 Thread Antony Stone
On Tuesday 06 February 2024 at 16:16:24, Rob van der Putten wrote: > Hi there > > On 05/02/2024 18:32, Antony Stone wrote: > > > > I believe ping (ICMP) timings are irrelevant. The client (squid in this > > case) does a DNS lookup for the hostname's A and record

Re: [squid-users] New Squid prefers IPv4

2024-02-05 Thread Antony Stone
On Monday 05 February 2024 at 17:32:51, Rob van der Putten wrote: > Hi there > > On 05/02/2024 17:16, Dieter Bloms wrote: > > On Mon, Feb 05, Rob van der Putten wrote: > >> After upgrading Squid from 3 to 5 the percentage of IPv6 reduced from > >> 61% to less then 1%. > >> Any ideas? > > > >

Re: [squid-users] Squid: blocking all requests to plain ip addresses

2023-11-06 Thread Antony Stone
On Monday 06 November 2023 at 12:35:33, Francesco Chemolli wrote: > Hi Christian, > What you're aiming to do should be easily doable via an url_regex ACL https://wiki.squid-cache.org/ConfigExamples/Chat/Skype contains an example of a regex to match IP addresses which may also point you in a

Re: [squid-users] Vey slow navigation

2023-10-12 Thread Antony Stone
On Thursday 12 October 2023 at 13:42:41, Andre Bolinhas wrote: > Hi > > I'm using Squid and sometimes my users are unable to access to internet > or the internet access is very slow. Have you tried accessing the same sites (preferably at the same time) from a machine which does not use Squid?

Re: [squid-users] compile error in squid v6.1

2023-07-31 Thread Antony Stone
On Monday 31 July 2023 at 17:26:38, botp wrote: > Hi All, > > ' been compiling It might help to tell us what sort of system you're compiling it on: - operating system - version - compiler name - compiler version Antony. -- "I estimate there's a world market for about five computers."

Re: [squid-users] Help with squid Proxy

2023-07-12 Thread Antony Stone
On Wednesday 12 July 2023 at 18:11:08, Andrés Leandro Regalado wrote: > I implemented squid proxy in a small office to filter the internet and now it > blocks the communication of the mail client with the mail server, I need to > know how I can allow outlook or thunderbird to work through squid.

Re: [squid-users] acl follow_x_forwarded_for

2023-07-03 Thread Antony Stone
On Monday 03 July 2023 at 11:46:20, robert k Wild wrote: > hi all, > > im reading this acl > > http://www.squid-cache.org/Doc/config/follow_x_forwarded_for/ > > is this to fool the dst server to think its coming from the client pc > instead of squid proxy No; it tells Squid to accept

Re: [squid-users] Getting ping to work via proxy

2023-07-01 Thread Antony Stone
ers, and whether the replies are routed back to the clients. This routing could be quite different from the routing of HTTP/S requests, which is what Squid is (mostly) used for, > On Sat, 1 Jul 2023, 23:10 Antony Stone wrote: > > > On Saturday 01 July 2023 at 22:59:43, rober

Re: [squid-users] Getting ping to work via proxy

2023-07-01 Thread Antony Stone
On Saturday 01 July 2023 at 22:59:43, robert k Wild wrote: > Hi all, > > Is there a way to get ping to work via the proxy. There is no such thing as an ICMP proxy. Antony. -- "Can you keep a secret?" "Well, I shouldn't really tell you this, but... no."

Re: [squid-users] Disable IPV6 for certain destinations only?

2023-04-18 Thread Antony Stone
On Tuesday 18 April 2023 at 14:53:31, Alex Rousskov wrote: > On 4/18/23 03:38, Ralf Hildebrandt wrote: > > We're using squid-6, currently v4 only. The use case for us is mostly > > our users using our proxy to retrieve full text publications of > > several thousand medical journals... via IPv4. >

Re: [squid-users] Is there any squid 4.x tested with Delay pools to work and limit well ?

2023-04-17 Thread Antony Stone
On Monday 17 April 2023 at 20:52:41, Dr.X wrote: > Could you please explain why the developers are upgrading Squid from > version 4 to 5 and 6, while ignoring a critical built-in feature like > Delay Pools that has been reported as a bug since Squid 4.x? I am not a Squid developer, and I do not

Re: [squid-users] Squid proxy errors - support

2023-04-07 Thread Antony Stone
On Friday 07 April 2023 at 13:00:09, Alessio Ballarini (External) wrote: > Hi Squid Support, > we are facing a problem with Squid proxy Which version of Squid, and running on which version of which operating system? Antony. -- Normal people think "If it ain't broke, don't fix it". Engineers

Re: [squid-users] ACL based DNS server list

2022-11-02 Thread Antony Stone
On Wednesday 26 October 2022 at 03:27:01, Sneaker Space LTD wrote: > Hello, > > Is there a way to use specific DNS servers based on the user or connecting > IP address that is making the connection by using acls or any other method? > If so, can someone send an example. What problem are you

Re: [squid-users] regex for normal websites

2022-08-02 Thread Antony Stone
On Tuesday 02 August 2022 at 17:23:51, robert k Wild wrote: > mmm... so i just want to know and really sorry for the dumb question, so > > adobe\.com$ > > works but then again if a website was eg > > hackadobe\.com$ > > that would work as well probably, so i want to do something like this >

Re: [squid-users] regex for normal websites

2022-08-02 Thread Antony Stone
On Tuesday 02 August 2022 at 14:14:58, robert k Wild wrote: > ok i have tested and this works > > adobe\.com$ > > i found it weird this didnt work > > \.adobe\.com > > just curious thats all Please define "works" and "didn't work" - I've pretty much lost track of exactly what you want to

Re: [squid-users] regex for normal websites

2022-07-27 Thread Antony Stone
On Wednesday 27 July 2022 at 19:25:46, robert k Wild wrote: > nice one thanks Amos > > i dont understand as in regex the terms > > ^ - start of line > . - any single character > * - repetition of character before Correction: zero or more instances of the character before > $ - end of line >

Re: [squid-users] pros/cons squid vs next generation firewall

2022-07-25 Thread Antony Stone
On Monday 25 July 2022 at 13:22:23, Dieter Bloms wrote: > Hello, > > I run some Squid proxy servers in conjunction with ICAP virus scanners > and I'm very happy with them. Our company now wants to replace them with > a checkpoint next generation firewall. Do you have some arguments that > speak

Re: [squid-users] fool windows into thinking it has internet access

2022-07-20 Thread Antony Stone
On Wednesday 20 July 2022 at 19:19:22, robert k Wild wrote: > ok i have realised something, my client cant resolve this address > > C:\Users\rkw>ping dns.msftncsi.com > Ping request could not find host dns.msftncsi.com. Please check the name > and try again. > > is there anyway i can enable

Re: [squid-users] Logrotate question

2022-06-16 Thread Antony Stone
On Thursday 16 June 2022 at 11:26:37, robert k Wild wrote: > Cool, so I will rotate daily and delete after 91 days, thanks guys Why did you change the recommended 92 days into 91? Consider June, July and August: June has 30 days July has 31 days August has 31 days So,

Re: [squid-users] Logrotate question

2022-06-16 Thread Antony Stone
On Thursday 16 June 2022 at 09:53:02, robert k Wild wrote: > Hi Antony, > > All I know is I need to keep a record of up to 3 months, worth of logs, due > to gdpr, how would you say I go about this Here's the standard logrotate file for Squid3 which is installed on Debian (I doubt that CentOS

Re: [squid-users] Logrotate question

2022-06-16 Thread Antony Stone
On Thursday 16 June 2022 at 09:27:32, robert k Wild wrote: > Thanks Eliezer > > I have centos 7 and I want it to rotate every 3 months as we need to keep > logs for every 3 months. Do you really mean you "need to keep logs for every 3 months"? Or do you mean that you need to keep "the most

Re: [squid-users] acl question

2022-05-05 Thread Antony Stone
On Thursday 05 May 2022 at 11:28:13, Frank Urban wrote: > Hi, > > We created an acl list with workstation names instead of IP addresses. > > e.g. acl our_networks src workstaion1. > > This works as long as the hostname is resolvable over DNS. If it is > not, the restart of squid fails. > > Is

Re: [squid-users] SQUID refuses to listen on any TCP Port

2022-03-14 Thread Antony Stone
On Monday 14 March 2022 at 05:42:35, ben wrote: > Hi Eliezer, > > SQUID started listening only after I run "ip6tables -P INPUT ACCEPT". Without seeing the rest of your iptables rules, it's not clear whether this really does apply to every interface and every protocol, or whether there are

Re: [squid-users] transparent or intercept keyword stops the service

2022-01-12 Thread Antony Stone
On Wednesday 12 January 2022 at 11:29:15, Daniel Sanchidrian wrote: > First of all I'm and new to squid, recently installed it to use in my > company network. I want to configure it as a transparent proxy. Out of interest - why? What is your objective here - what are you trying to achieve by

Re: [squid-users] RES: Squid 4.13 does not access Facebook

2022-01-07 Thread Antony Stone
On Friday 07 January 2022 at 22:39:41, Graminsta wrote: > Now I have to change the pw of about 200 VPSs, hell. I have to question the wisdom of using the same root PW on multiple servers, even when that PW has not been posted on a public mailing list. Antony. -- I bought a book on memory

Re: [squid-users] MITM the MITM

2022-01-03 Thread Antony Stone
On Tuesday 04 January 2022 at 01:19:28, Will BMD wrote: > Hey all, > > I currently have the following network topology, it's emulating a real > world environment. The proxy is running ssl_bump. > > LAN <-> Squid Proxy <-> Firewall <-> Internet > > From the Firewall's perspective all client

Re: [squid-users] Squid is active but not working

2021-08-18 Thread Antony Stone
On Wednesday 18 August 2021 at 16:50:20, Peter Thesing wrote: > Because I have a multi port modem/router that connects to the internet. Sorry, I'm not sure I follow which question that is an answer to. But anyway, why don't you just plug your two machines (the "client" and the "server") each

Re: [squid-users] Squid is active but not working

2021-08-16 Thread Antony Stone
On Monday 16 August 2021 at 19:28:55, Peter Thesing wrote: > Because I have a multi port modem/router > a fritz.box 7581 I have a Fritz.Box 6360, not so different. > My ISP does not support samba on their network > > Samba can be used for remote printer support among others Yes, I am familiar

Re: [squid-users] Squid is active but not working

2021-08-16 Thread Antony Stone
On Monday 16 August 2021 at 18:09:12, Peter Thesing wrote: > Hi, > > English is not my native tongue so I am sorry for any mistakes that I've > made or will make in the future. That's not problem - I just wanted to make sure I understood your meaning (which I did). > Both apache and squid are

Re: [squid-users] Squid is active but not working

2021-08-16 Thread Antony Stone
On Monday 16 August 2021 at 17:03:57, Peter Thesing wrote: > Hi, > > If there is a a need for additional information please let me know?! Some additional information would be good, and a lot less HTML would be good too :) Just a comment "I got the expected content" is sufficient... > I am

Re: [squid-users] about logformat

2021-08-15 Thread Antony Stone
On Monday 16 August 2021 at 00:25:45, Pavel Serrat wrote: > I'm trying to customize my squid log format and I have the following > question: See http://www.squid-cache.org/Doc/config/logformat/ % [encoding] [-] [[0]width] [{arg}] formatcode [{arg}] width minimum and/or maximum field

Re: [squid-users] Proxy Authentication optional

2021-07-24 Thread Antony Stone
On Saturday 24 July 2021 at 09:23:52, Dieter Bloms wrote: > Hello, > > I want to implement user authentication (kerberos) on an already existing > proxysystem without user authenticaion. But I know that there are clients, > which can't do any authentication. Can you identify these clients in

Re: [squid-users] Problems with HTTPS on Squid

2021-07-12 Thread Antony Stone
On Monday 12 July 2021 at 20:12:03, Marcio B. wrote: > I have the following problem on my Squid 4.6 on Debian 10. > > Squid does not redirect the user to the error page when blocking an HTTPS > url. On HTTP it works correctly. Short answer - it can't. Longer answer - browser requests

Re: [squid-users] issues with old version of TLS/SSL certificate

2021-07-12 Thread Antony Stone
On Monday 12 July 2021 at 18:58:43, Alex Irmel Oviedo Solis wrote: > Hello all, I'm trying to download a file from > https://prodcont.seace.gob.pe > SSLLabs review shows that server supports only TLS 1.0 > Any solution please? If you're trying to download a specific file from a specific

Re: [squid-users] TPROXY Error

2021-06-30 Thread Antony Stone
On Wednesday 30 June 2021 at 14:16:09, Ben Goz wrote: > I'm trying to configure squid as a transparent proxy using TPROXY. > The machine I'm using has 2 NICs, one for input and the other one for > output traffic. > The TPROXY iptables rules are configured on the input NIC. 1. Which version of

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
ent of websites as they pass through their systems. Anyway, just for the sake of technical discussion, let me repeat my original questions: On Tuesday 22 June 2021 at 21:41:22, Antony Stone wrote: > On Tuesday 22 June 2021 at 21:32:10, Arctic5824 wrote: > > Hello, Recently I setup my

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Wednesday 23 June 2021 at 00:06:21, Coenraad Loubser wrote: > I'm sure there are many other ways to do this too... again, what's your > real use case here? My _guess_ now that I know Arctic 5824 is deliberately running an open web proxy on the Internet (with co-operation from the hosting

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 23:13:19, Antony Stone wrote: > On Tuesday 22 June 2021 at 23:05:20, Arctic5824 wrote: > > On Tuesday, June 22nd, 2021 at 1:56 PM, Antony Stone wrote: > > > Please do not test and report problems with one configuration, and then > > > tell

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 23:05:20, Arctic5824 wrote: > On Tuesday, June 22nd, 2021 at 1:56 PM, Antony Stone wrote: > > > > Please do not test and report problems with one configuration, and then > > tell us you have a different one. > > Sorry, I shouldnt

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 22:53:08, Arctic5824 wrote: > Hey, yes this is actually the case, for testing instead of > > > http_access allow localhost > > im running with > > > http_access allow all Please do not test and report problems with one configuration, and then tell us you have a

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 22:54:42, Arctic5824 wrote: > On Tuesday, June 22nd, 2021 at 1:44 PM, Antony Stone wrote: > > > > #http_access deny !Safe_ports > > > > Has that been consciously and deliberately commented-out? > > > > #http_access allow localn

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 22:37:16, Alex Rousskov wrote: > On 6/22/21 4:28 PM, Arctic5824 wrote: > > > > Hey! thanks for the info, I just tried that but it seems https is still > > being allowed, and I can see it in the logs as well "TCP_TUNNEL/200 717 > > CONNECT s.youtube.com:443 -" > > my

Re: [squid-users] Newbie question, How to fully disable/disallow https?

2021-06-22 Thread Antony Stone
On Tuesday 22 June 2021 at 21:32:10, Arctic5824 wrote: > Hello, Recently I setup my first squid proxy, > > I want it when users try to acces a website via https, they get redirected > to the http version 1. What makes you believe that sites *have* an HTTP version? 2. What do you think should

Re: [squid-users] Testing eCap module

2021-06-06 Thread Antony Stone
On Sunday 06 June 2021 at 16:09:24, Ben Goz wrote: > I have an eCap module code that should block traffic on certain cases > and passthru traffic on other cases. > What is the most easy and efficient way to test that module's code is > working as expected? 1a. Test some of the cases where

Re: [squid-users] manual proxy configuration ...

2021-05-29 Thread Antony Stone
On Saturday 29 May 2021 at 11:45:07, Albretch Mueller wrote: > cat "/etc/squid/squid.conf" | grep http_port | grep --invert-match "^#" > http_port 3128 That could more briefly be done as "grep ^http_port /etc/squid/squid.conf" > The value 3128 you enter on your network browser settings > >

Re: [squid-users] (possibly dynamic?) multiple port forwarding in the same internal Network ...

2021-05-25 Thread Antony Stone
On Tuesday 25 May 2021 at 07:51:21, Albretch Mueller wrote: > As part of a teaching and learning (TaL)/school software, I need squid: > > a) to detect one of the connected computers in an internal network > comprising wirelessly connected and wired computers as the "master" > (operated by the

Re: [squid-users] (possibly dynamic?) multiple port forwarding in the same internal Network ...

2021-05-25 Thread Antony Stone
On Tuesday 25 May 2021 at 14:36:09, Albretch Mueller wrote: > On 5/25/21, Antony Stone wrote: > > On Tuesday 25 May 2021 at 07:51:21, Albretch Mueller wrote: > >> As part of a teaching and learning (TaL)/school software, I need squid: > >> > >> a) to d

Re: [squid-users] (possibly dynamic?) multiple port forwarding in the same internal Network ...

2021-05-25 Thread Antony Stone
On Tuesday 25 May 2021 at 07:51:21, Albretch Mueller wrote: > As part of a teaching and learning (TaL)/school software, I need squid: > > a) to detect one of the connected computers in an internal network > comprising wirelessly connected and wired computers as the "master" > (operated by the

Re: [squid-users] squid ftp list files problem

2021-03-25 Thread Antony Stone
On Thursday 25 March 2021 at 12:53:09, maurizio wrote: > Hello > I have a squid 4.14 version installed recently. I have a problem when we use > that like ftp proxy(via port 21): when a client use that and try to use the > ftp command ls(list) in a directory with a lot files (in my test 250 files)

Re: [squid-users] How to automatically Restart Squid on Ubuntu?

2021-03-22 Thread Antony Stone
On Monday 22 March 2021 at 15:59:37, Angelo Wang wrote: > Hi, > > I have a /22 subnet on a server and sometimes Squid crashes when there are > too many connections. Can someone help me create a script/command to > automatically restart squid if this happens? I would use

Re: [squid-users] Protecting squid

2021-03-11 Thread Antony Stone
On Thursday 11 March 2021 at 14:41:11, Ben Goz wrote: > I tried to open squid with some special port other than the default 3128 > port. Obscurity is not equivalent to security. > But after a while I saw that my squid was being abused by unknown IP > addresses I'm assuming this means your

Re: [squid-users] Setting up a transparent http and https proxy server using squid 4.6

2020-12-31 Thread Antony Stone
On Thursday 31 December 2020 at 10:10:11, jean francois hasson wrote: > If I set up on a device connected to the access point a proxy manually > ie 10.3.141.1 on port 8080, I can access the internet. If I put the > following rules for iptables to use in files rules.v4 : > > *nat > -A PREROUTING

Re: [squid-users] squid writes to /var/log/messages

2020-12-24 Thread Antony Stone
On Thursday 24 December 2020 at 18:44:21, Song & Movie wrote: > Can any one help me to create http proxy ? 1. Please do not hijack an unrelated thread on the list. Please start a new thread by posting to squid-users@lists.squid-cache.org with an appropriate subject. 2. Please give us at

Re: [squid-users] authorized by pcname

2020-12-12 Thread Antony Stone
On Saturday 12 December 2020 at 14:03:23, sampe...@tiscali.it wrote: > What Squid mechanism do you suggest me to identify the “computer name” ? > What solution/corretion can I make to my environment to apply my idea? A few suggestions: 1. Why not get your DHCP server to allocate IP addresses

Re: [squid-users] Squid with more than 128 ports?

2020-12-10 Thread Antony Stone
On Thursday 10 December 2020 at 13:02:19, roee klinger wrote: > Hello, > > We have a few Squid proxy servers with a total of around 400 ports What do you mean by that? What are you using 400 ports for? > We have decided that we want to add a cloud instance in the middle of the > connections,

Re: [squid-users] Sqlite3 with Squid

2020-12-10 Thread Antony Stone
On Thursday 10 December 2020 at 12:49:48, Eliezer Croitor wrote: > Hey, > > I am wondering what can I use Sqlite3 with squid? > > I was thinking about holding some of the config dynamic parts inside sqlite > db (in a specific setup) Can you give some examples of such "config dynamic parts"? >

Re: [squid-users] FTP proxy

2020-12-06 Thread Antony Stone
On Sunday 06 December 2020 at 16:56:10, Andrea Venturoli wrote: > On 12/6/20 4:44 PM, Antony Stone wrote: > > Where is the firewall, compared to your Squid proxy, in the network? > > Squid runs on the firewall itself. > > > I'm just wondering how you plan to use

Re: [squid-users] FTP proxy

2020-12-06 Thread Antony Stone
On Sunday 06 December 2020 at 16:26:26, Andrea Venturoli wrote: > Hello. > > I'm trying to evaulate FTP proxying with squid and I have a couple of > questions. > To be clear, I'm not talking about FTP through HTTP, but about the > ftp_port option. > I've used frox (http://frox.sourceforge.net/)

Re: [squid-users] Is there a worker option in the source build?

2020-10-14 Thread Antony Stone
On Wednesday 14 October 2020 at 11:29:58, m k wrote: > hi Antony, > > 4.13 is a compiler from source. Show us the command you use to compile it. > workers just write in squid.conf. I don't think you understood what I meant by "details" - show us exactly what you have put into the config file

Re: [squid-users] Is there a worker option in the source build?

2020-10-14 Thread Antony Stone
On Wednesday 14 October 2020 at 11:19:54, m k wrote: > hi all, > > I have installed squid 4.13. How? Package? Compiled from source? What O/S have you installed it on? > When I set workers, Give us a clue how you're doing that? > squid doesn't work. In what way? Doesn't start? Gives an

Re: [squid-users] How to select parent proxy based on user password

2020-09-22 Thread Antony Stone
On Tuesday 22 September 2020 at 22:35:36, Ajb B wrote: > how can you map the user password to a parent proxy? > > so that > > testuser1:qvmgPUJ5xW-121@18.234.74.214:3292 > testuser1:qvmgPUJ5xW-122@18.234.74.214:3292 > testuser1:qvmgPUJ5xW-123@18.234.74.214:3292 > map to a different parent

Re: [squid-users] Strange Squid SSL Interception Behavior

2020-08-24 Thread Antony Stone
On Tuesday 25 August 2020 at 00:21:31, Mathew Brown wrote: > I set up the necessary iptables forwarding ports Please show us what those iptables rules are. Antony. -- "It wouldn't be a good idea to talk about him behind his back in front of him." - murble

Re: [squid-users] Can squid proxy pass the SMTP port 587

2020-08-20 Thread Antony Stone
On Thursday 20 August 2020 at 21:41:20, santosh panchal wrote: > Hi Team > > How to configure squid to pass my smtp traffic on port 587 Install sendmail, exim, postfix or any other MTA of your choice and configure it to relay your outbound email. Squid is not an MTA. Antony. -- The truth

Re: [squid-users] Need squid latest version 4.12 RPM packaged files for centos7 and x86_64 architecture

2020-08-20 Thread Antony Stone
On Thursday 20 August 2020 at 12:25:04, rahul.n...@orange.com wrote: > Hi Team, > > I am looking for a urgent support on squid latest version 4.12 RPM files > based on CentOS7 and x86_64 architecture. "Urgent" is all very well, but we can't help until you tell us what the problem is. > Also,

Re: [squid-users] Squid and multipart form decode

2020-07-23 Thread Antony Stone
On Thursday 23 July 2020 at 15:33:01, Ryan Le wrote: > sorry not decode, just parse to send headers to icap as well. Aha, icap - sorry, I can't help you there, but I'm pretty sure there are others here who have used it. > On Thu, Jul 23, 2020 at 9:27 AM Antony Stone wrote: > > On

Re: [squid-users] Squid and multipart form decode

2020-07-23 Thread Antony Stone
On Thursday 23 July 2020 at 15:22:56, Ryan Le wrote: > I have been trying to configure squid to decode and send multipart form > data to another service. What do you mean by "decode"? > Is there an acl or build parameter needed for multipart form data support? No; Squid sends on what it gets

Re: [squid-users] try and reslove domain via local DNS and not squid

2020-06-24 Thread Antony Stone
On Wednesday 24 June 2020 at 17:36:34, robert k Wild wrote: > hi all, > > i want squid not to try and resolve our domain name ie so it resolves > internally on our local DNS server and not go out squid to try and resolve What is in /etc/resolv.conf on your squid server? Antony. -- Never

Re: [squid-users] Server monitoring

2020-06-10 Thread Antony Stone
On Wednesday 10 June 2020 at 21:08:35, Ronan Lucio wrote: > Hi guys, > > How do you suggest to monitor service availability? > A know that some people use to monitor a few URLs through the proxy, > but, I'd like to know if there is any way to remotly monitor squid service. Do you mean "is it

Re: [squid-users] Switch cache peer Parent server for every 30 minutes

2020-06-10 Thread Antony Stone
On Wednesday 10 June 2020 at 18:11:03, Prem Chand wrote: > Hi Alex, > > Thanks for responding to my issue . I didn't get how the math was done(why > it's multiplied by 2) to get 16 slots if possible could you please elaborate > with an example. I believe what Alex meant was: You want 30

Re: [squid-users] SQUID PROBLEM WITH SITES THAT HAVE MORE THAN ONE IP ADDRESSES

2020-05-11 Thread Antony Stone
On Monday 11 May 2020 at 11:53:15, leomessi...@yahoo.com wrote: > Hi againthank you for your reply. > sorry but I didn't yell only asked for help! Writing in all capital letters (see your Subject line, for example) in online communications is generally interpreted as shouting. Regards,

Re: [squid-users] Let Squid use SSL certificate for a parent cache peer

2020-05-05 Thread Antony Stone
On Tuesday 05 May 2020 at 12:21:19, mariolatif741 wrote: > The purpose of proxy A is that its the proxy that will be given to my > clients. The purpose of all what I am doing is to let my clients use proxy > B indirectly through proxy A (so they can use proxy B without installing > the CA

Re: [squid-users] Let Squid use SSL certificate for a parent cache peer

2020-05-05 Thread Antony Stone
On Tuesday 05 May 2020 at 11:48:12, mariolatif741 wrote: > Since you said "If the client is participating in the TLS handshake it > *always* requires the CA to be installed.", then I guess what I want to do > is not possible. > > Can I make Squid send the requests received from the client to the

Re: [squid-users] Using a Baltimore root certificate in transparent ssl proxying

2020-04-28 Thread Antony Stone
On Monday 27 April 2020 at 23:44:41, Lei Wen wrote: > The issue we are having right now is the certificate installed on the > container is a self signed cert, we were trying to migrate this cert to a > real trusted CA cert, or a Baltimore root cert. That will not work for an intercepting

Re: [squid-users] Configure A Native FTP proxy on Squid

2020-04-26 Thread Antony Stone
On Sunday 26 April 2020 at 08:42:11, Amos Jeffries wrote: > On 26/04/20 8:26 am, Antony Stone wrote: > > On Saturday 25 April 2020 at 19:27:51, Dawood Aijaz wrote: > >> > >> Currently, I am developing a Data Loss Prevention Tool. One of the > >> requiremen

Re: [squid-users] Configure A Native FTP proxy on Squid

2020-04-25 Thread Antony Stone
On Saturday 25 April 2020 at 19:27:51, Dawood Aijaz wrote: > Hi, > > Currently, I am developing a Data Loss Prevention Tool. One of the > requirements is to monitor FTP traffic. So can someone help me set up an > FTP native proxy is squid and how will I be able to monitor FTP traffic Why do you

Re: [squid-users] setup FTP proxy and FTP content monitoring (Antony Stone)

2020-04-23 Thread Antony Stone
On Wednesday 22 April 2020 at 15:48:57, Dawood Aijaz wrote: > "a*ll I want from squid proxy is to intercept FTP and expose all the FTP > data "* I think you're looking at the wrong tool for a job like this. When you say "intercept" it sounds like you want something which will act in between an

Re: [squid-users] setup FTP proxy and FTP content monitoring

2020-04-21 Thread Antony Stone
On Tuesday 21 April 2020 at 17:26:05, Dawood Aijaz wrote: > Hi, > I am currently working on a task to monitor FTP traffic and analyze it. > So can somebody help me to set up FTP proxy for squid and to analyze FTP > data Squid supports FTP natively. You don't need to configure anything special

Re: [squid-users] [squid-announce] [ADVISORY] SQUID-2019:4 Multiple Issues in HTTP Request processing

2020-04-19 Thread Antony Stone
On Sunday 19 April 2020 at 11:47:41, Dmitry Melekhov wrote: > 19.04.2020 12:37, Amos Jeffries пишет: > > On 19/04/20 8:22 pm, Dmitry Melekhov wrote: > > > > > 4.10 does not contain fix :-) > > > > Which fix are you talking about? > > > > The bug this advisory is talking about definitely is

Re: [squid-users] Confirmation page not working

2020-04-17 Thread Antony Stone
On Friday 17 April 2020 at 15:32:38, TarotApprentice wrote: > Trying to visit the confirmation page at > http://lists.squid-cache.org/confirm/squid-users/ but it doesn’t seem to > be responding. I’ve tried over a couple of days. When you say "not responding", do you mean you get no page content

Re: [squid-users] Setting up proxy with private to public

2020-04-16 Thread Antony Stone
Sorry, replying to the list this time - for some reason my previous reply went to your private address. On Wednesday 15 April 2020 at 15:08:36, Chris Bidwell - NOAA Federal wrote: > So after looking further. It looks like when I'm trying to wget from my > squid server, which has the two nics

Re: [squid-users] Setting up proxy with private to public

2020-04-14 Thread Antony Stone
On Tuesday 14 April 2020 at 16:03:19, Chris Bidwell - NOAA Federal wrote: > Okay, so I think I'm starting to get somewhere but the connection isn't > completing. I can see the connection come through my firewall, but the > handshake doesn't appear to be happening. Tell us more about your network

Re: [squid-users] Setting up proxy with private to public

2020-04-13 Thread Antony Stone
On Monday 13 April 2020 at 23:46:46, Chris Bidwell - NOAA Federal wrote: > Sure. So we have a few internal networks that aren't meant to have direct > internet access without access through a proxy so that it can be better > regulated and monitored. Okay, that's a useful starting point. >

Re: [squid-users] Setting up proxy with private to public

2020-04-13 Thread Antony Stone
On Monday 13 April 2020 at 21:19:04, Chris Bidwell - NOAA Federal wrote: > Hi all, > > Very new to squid and am looking to setup several internal subnets to > access external network (internet) through squid on a separate interface. What are you trying to achieve by using Squid? What is your

Re: [squid-users] Squid transparent not caching apt requests from deb.debian.org

2020-04-03 Thread Antony Stone
On Friday 03 April 2020 at 22:26:13, zrm wrote: > Greetings! Today I bring you a Squid cache mystery. > In the first case we get TCP_MISS every time because it isn't caching > the data, in the second case it's only the first time and after that we > get TCP_REFRESH_UNMODIFIED. But how and why is

Re: [squid-users] Allowing a port only to certain IP/host

2020-03-09 Thread Antony Stone
On Monday 09 March 2020 at 15:43:14, Service MV wrote: > Hello everyone, I need to enable port 22 in squid but only to a certain > server (host.domain.com) in particular, so that the rest of the world > cannot be accessed via SSH. Squid does not support SSH. > I would like to know this is the

Re: [squid-users] About intercept https

2020-02-25 Thread Antony Stone
On Tuesday 25 February 2020 at 20:49:25, Yurii wrote: > Hi to all. I need help. > The task is to configure squid in intercept mode to proxy http/https > traffic. I cannot view any of the pastebin links you provide below. Please just cut and paste the information into an email reply, so we can

Re: [squid-users] debug headers between squid --> website

2019-12-02 Thread Antony Stone
t sniffer capture what happened. After it's all over, you then have a packet capture which you can analyse (eg: using wireshark) to find out what Squid sent to the server/s, and what came back again. Antony. > > On Dec 2, 2019, at 8:58 PM, Antony Stone > > wrote: > > >

Re: [squid-users] debug headers between squid --> website

2019-12-02 Thread Antony Stone
On Monday 02 December 2019 at 18:34:31, Ahmad Alzaeem wrote: > Hello Tem , > > How can i debug Headers that is between squid——> website request made Run a packet sniffer (tcpdump, wireshark, tshark...) on the Squid server, looking at the external interface (ie: the one pointing to the

Re: [squid-users] After enabling IPv6 squid no longer responds

2019-11-14 Thread Antony Stone
On Thursday 14 November 2019 at 19:50:00, James Moe wrote: > On 13/11/2019 12.36 pm, James Moe wrote: > > After adding v6 addresses to the server and hosts, and enabling an RA, > > squid no longer delivers anything from its cache, or is exceedingly slow > > about it. > > Here is a

Re: [squid-users] Unsuccessful at using Squid v4 with intercept

2019-10-30 Thread Antony Stone
On Wednesday 30 October 2019 at 17:11:29, FOUTREL Sébastien wrote: > Hello, I would like to use squid as a transparent proxy for my users. > "Clients" are behind a Debian "Router" which MASQUERADE them (as they use > RFC 1918 ips). > > I have a Squid 4.6 from Debian Buster packages installed on

Re: [squid-users] Multiple LDAP authentication server for Squid

2019-09-16 Thread Antony Stone
On Monday 16 September 2019 at 12:17:12, Antonino Sanacori wrote: > Thanks Amos but I have a 3.x version. Try http://www.squid-cache.org/Versions/v3/3.5/manuals/basic_ldap_auth.html then. Antony. > On 13/09/2019 11:17, Amos Jeffries wrote: > > On 12/09/19 10:41 pm, Antonino Sanacori wrote: >

Re: [squid-users] squid email using curl/smtp using squid

2019-09-08 Thread Antony Stone
On Sunday 08 September 2019 at 17:35:24, --Ahmad-- wrote: > ? It might be that: a) we don't quite understand what you have done: "i enabled port port in squid for mailing in squid ssl ports 587" is not easy to understand or b) Squid is not designed to be an email proxy, so why are you try

Re: [squid-users] SQUID proxy to access web application from another subnet

2019-08-22 Thread Antony Stone
On Friday 23 August 2019 at 00:21:48, jagadeesh am wrote: > Hello, > > I have one query. Could you please suggest me what to do. Read the documentation :) > I have a requirement to access a web application running on Server 1 which > is connected to Private network 192.168.2.2 network , from

Re: [squid-users] squid.config

2019-08-13 Thread Antony Stone
On Tuesday 13 August 2019 at 21:18:51, Sérgio Vieira wrote: > Hello, > Regarding squid config file, on MacOS, I can’t add the following parameter: > strip_query_terms off > > I can access the file and edit it, but after restart the file removes the > added line... > > I have the config file at

Re: [squid-users] Squid + OpenSSL w/FIPS

2019-07-02 Thread Antony Stone
On Tuesday 02 July 2019 at 23:05:27, Cody Cushing wrote: > Hello, I would like to use Squid as a forward proxy to ensure traffic > leaving my VM is using a TLS connection negotiated through a client using > FIPS certified encryption. I have OpenSSL w/FIPS configured on my VM, and > Squid properly

Re: [squid-users] Useragent request/reply headers with squid .

2019-06-15 Thread Antony Stone
On Saturday 15 June 2019 at 11:37:29, --Ahmad-- wrote: > Guys im just trying to understand HTTP protocol and squid as GW for > internet . Hm, "understand" or "break" :) ? > i just want to know how can squid deal with headers . You *have* read the warning / advice at

Re: [squid-users] Squid auth helpers aren't installing

2019-05-23 Thread Antony Stone
On Thursday 23 May 2019 at 09:37:44, amlgp wrote: > Hi, I am using Centos 6 and for some reason the Squid helpers aren't > installing. I go to /usr/lib64 after installing squid and there is no auth > helpers in there at all. I am on a 64bit computer and I have checked > /usr/lib and they both

Re: [squid-users] Squid proxy in Azure

2019-05-20 Thread Antony Stone
On Monday 20 May 2019 at 09:43:56, Peter Spencer wrote: > Good morning > > Was hoping you could please advise.. we are looking to put a squid proxy in > Azure. Reason being, we have two sites with network resilience. At the > moment, we have one squid proxy on one of our local site DCs, and

Re: [squid-users] youtube restriction.

2019-04-08 Thread Antony Stone
tion which is causing the problem. > With a old version of squid (2.6) there are no problems There are a *lot* of differences between Squid 2.6 and 3.5, especially for HTTPS. You *have* made suitable adjustments to the configuration file, I hope? Antony. > Date: Fri, 5 Apr 2019 15:39:08

Re: [squid-users] youtube restriction.

2019-04-05 Thread Antony Stone
On Friday 05 April 2019 at 15:06:00, Wegner Michaël wrote: > Hi, > > I install squid + squidguard, and I can't play youtube video. > For example : https://m.youtube.com/watch?v=Hmj3LToi4W8 ; > https://m.youtube.com/watch?v=jbBUQ-uvlRU > > Error : video not available access to this video is

  1   2   3   4   5   6   7   8   >