Re: [squid-users] Squid working in Firefox not Internet Explorer 7

2008-10-15 Thread Amos Jeffries
On Wednesday 15 October 2008, Myles Tippett wrote: Hi there, I've looked for someone asking a similar question here but can't find a decent answer. I've set up Squid on a Windows XP box and I've blocked a few URL's. My Firefox browser blocks these sites when the proxy IP port are inputted

Re: [squid-users] HTTPS traffic in normal transparent proxy

2008-10-15 Thread Amos Jeffries
On ons, 2008-10-15 at 10:23 -0400, [EMAIL PROTECTED] wrote: My configuration is... http_port 0.0.0.0:3128 transparent https_port 0.0.0.0:3129 transparent cert=/usr/local/squid-test/CA/servercert.pem key=/usr/local/squid-test/CA/serverkey.pem Iptable rules are: iptables -t nat -A

Re: [squid-users] Using Squid as a reverse-proxy to SSL origin?

2008-10-15 Thread Amos Jeffries
I've looked in the archives, site, and Squid book, but I can't find the answer to what I'm looking to do. I suspect that it's not supported. My origin server accepts Basic auth over SSL (non-negotiable). I'd like to stick a reverse proxy/surrogate in front of it for caching/acceleration,

Re: [squid-users] Authentication Issue with Squid and mixed BASIC/NTLM auth

2008-10-15 Thread Amos Jeffries
Hey all, I've got a tough situation I'm hoping someone can help me with. We 'downgraded' from an old 3.0PRE build that a predecessor had setup on a reverse proxy, to squid 2.6.STABLE20. The proxy runs your standard OWA over Reverse Proxy setup, with login=PASS to an OWA backend running

Re: [squid-users] LDAP authentication memory leak

2008-10-15 Thread Amos Jeffries
Hi, Running a stress test on 3.0.STABLE8 and Linux, without caching (cache deny all+null disk storage scheme) and with LDAP authentication, Squid process memory footprint rises at a rate of about 6.4MB per hour. I tried mailing lists archives and Bugzilla but found nothing. Is this a

Re: [squid-users] Inelegant routing based on file size

2008-10-15 Thread Amos Jeffries
Hi All I am looking to route download traffic based on file size of the download requests. If a user in our network was to download a 10mb file, he gets routed through link 1. If a user requests a 100mb file download, he gets routed through link 2. How is this achieved? It can not. File

Re: [squid-users] Authentication Issue with Squid and mixed BASIC/NTLM auth

2008-10-16 Thread Amos Jeffries
hit bad news for 3.1, its definitely a bug that needs looking into at some point. Amos Thanks for the help. -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: Wednesday, October 15, 2008 6:46 PM To: Chris Natter Cc: squid-users@squid-cache.org Subject: Re

Re: [squid-users] Unable to have certain site to be non-cacheable and ignore already cached data

2008-10-16 Thread Amos Jeffries
Thanks so much Henrick and Leonardo! Looks I should learn regexes, since taked $ as the whatever after meaning but not end of string :) Now it logs as TCP_MISS. Thanks so much again! If you are needing to match just the domain its better to use 'dstdomain' ACL type instead of regex. Squid

Re: [squid-users] squidnt.com, warning

2008-10-16 Thread Amos Jeffries
On tor, 2008-10-16 at 17:01 +0100, Mr Lyphifco wrote: It seems that the site http://squidnt.com/ is trying to masquerade as an official website for Mr Serassio's Windows port of Squid. It doesn't explicitly state this, but the wording of the site contents strongly implies such a thing.

Re: [squid-users] Disabling error pages

2008-10-16 Thread Amos Jeffries
On tor, 2008-10-16 at 13:02 +0100, Robert Morrison wrote: I've found lots of references online (in this list's archives, other sites and the FAQ) to customising error pages in squid, but haven't yet found reference to removing error pages completely. You can't. Oce the request has reached

Re: [squid-users] Re-distributing the cache between multiple servers

2008-10-16 Thread Amos Jeffries
Hi, I have two reverse proxy servers using each other as neighbours. The proxy servers are load balanced (using a least connections algorithm) by a Netscaler upstream of them. A small amount of URLs account for around 50% or so of the requests. At the moment there's some imbalance in the

Re: [squid-users] FW: Load balanced cache-server

2008-10-17 Thread Amos Jeffries
Battsetseg.M wrote: Hi all, We’re medium sized ISP and want to implement caching. After doing some research, we decided to use load balancer with 4-5 servers. Our exiting gateway bandwidth is totally 300Mbps. After doing some calculations included in O’Reilly ‘Web Caching ‘ we got to have a

Re: [squid-users] Update Accelerator, Squid and Windows Update Caching

2008-10-17 Thread Amos Jeffries
Richard Wall wrote: On Fri, Oct 10, 2008 at 12:30 PM, Amos Jeffries [EMAIL PROTECTED] wrote: Richard Wall wrote: Hi, I've been reading through the archive looking for information about squid 2.6 and windows update caching. The FAQ mentions problems with range offsets but it's not really clear

Re: [squid-users] Authentication Issue with Squid and mixed BASIC/NTLM auth

2008-10-17 Thread Amos Jeffries
you have the login=PASS on the cache_peer line? and woudld you mind sharing the config? Amos Thanks! -Chris -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: Thursday, October 16, 2008 5:37 AM To: Chris Natter Cc: squid-users@squid-cache.org Subject: Re: [squid

Re: [squid-users] Disk Space problem in a squid-proxy server

2008-10-17 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: * This message has been scanned by IMSS NIT-Silchar Please see below the output of pwd and df commands:- [EMAIL PROTECTED] squid]# pwd /var/log/squid [EMAIL PROTECTED] squid]# ls -l total 1005212 -rw-r--r-- 1 squid

Re: [squid-users] Disk Space problem in a squid-proxy server

2008-10-18 Thread Amos Jeffries
Chuck Kollars wrote: ... At the most the squid server would run for another day and then stop running!! ... Please suggest some pointers to delete some files under /var partition to create more space !! ... Both your question and all the responses to it I've seen assume Squid is the

Re: [squid-users] signal 6

2008-10-18 Thread Amos Jeffries
dikshie wrote: Hi, i always get: pid 80196 (squid), uid 65534: exited on signal 6 so many signal 6. i dont know why i cant get coredump files. sfc-cache# cat etc/squid.conf | grep coredump coredump_dir /usr/local/squid31/var/cache sfc-cache# ls var/cache/ 00 02 04

Re: [squid-users] Complicate ACL affect performance?

2008-10-18 Thread Amos Jeffries
Henrik K wrote: On Sat, Oct 18, 2008 at 12:44:46PM +0300, Henrik K wrote: On Fri, Oct 17, 2008 at 10:24:21PM +0200, Henrik Nordstrom wrote: On tor, 2008-10-16 at 12:02 +0300, Henrik K wrote: Optimizing 1000 x www.foo.bar/randomstuff into a _single_ www.foobar.com/(r(egex|and(om)?)|fuba[rz])

Re: [squid-users] Complicate ACL affect performance?

2008-10-18 Thread Amos Jeffries
Henrik K wrote: On Sat, Oct 18, 2008 at 11:54:52PM +1300, Amos Jeffries wrote: Henrik K wrote: On Sat, Oct 18, 2008 at 12:44:46PM +0300, Henrik K wrote: Not sure what the splay code does in Squid, didn't have time to grab it. Produces a very inefficient unsorted but alphabetically ordered

Re: [squid-users] Complicate ACL affect performance?

2008-10-18 Thread Amos Jeffries
snip No. Because most users will not write their ACL regex normally, and the regex has to match a forward-coded domain anyway. The squid algorithm works on forward-coded domains. Oops. I meant to write: Because most users will write their ACL regex normally (wont even think to write

Re: [squid-users] Disk Space problem in a squid-proxy server

2008-10-18 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: * This message has been scanned by IMSS NIT-Silchar Can I reconfigure the current squid cache ? No need. The cache IS NOT IN /var and cannot now be the cause of the problem. Amos If so please tell which all of

Re: [squid-users] Why are cache_peer_access acls called 4 times in a row?

2008-10-18 Thread Amos Jeffries
Elli Albek wrote: Hi, I have a simple setup for testing accelerator: http_port 127.0.0.4:80 accel defaultsite=1.2.3.4:80 cache_peer 1.2.3.4 parent 80 0 no-query originserver name=parent_sl acl my_acl urlpath_regex ^/rev/ acl port80 port 80 http_access deny !port80 http_access allow port80

[squid-users] Squid 3.0 STABLE10 is available

2008-10-18 Thread Amos Jeffries
If you encounter any issues with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

Re: [squid-users] Squid conf for live video stream

2008-10-20 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: Hi all, i configured squid transparent for caching live video stream. I need to cache the live video objects from my particular domain. But mostly url's vary from request to request.Because VOD service. So... you are running a service which has explicitly been

Re: [squid-users] squid and accept-encoding gzip,deflate

2008-10-20 Thread Amos Jeffries
Aviral Pandey wrote: Thanks Henrik...But I have seen vice-versa to be working i.e., server sending a gzipped response and squid serving deflated one when client asks for deflated content Are you sure? squid does _transfer_ chunked decoding. But thats special compression only 'zipped'

Re: [squid-users] Unable to match empty user-agent strings?

2008-10-20 Thread Amos Jeffries
James Cohen wrote: Hi, I think I've found a bug but first wanted to double-check I wasn't doing anything dumb. In our reverse proxy setup we want to block people from leeching the images using Wget or similar applications. To do this we want to block user agents that match Wget and because

RE: [squid-users] Authentication Issue with Squid and mixed BASIC/NTLM auth

2008-10-20 Thread Amos Jeffries
Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: Friday, October 17, 2008 10:31 PM To: Chris Natter Cc: squid-users@squid-cache.org Subject: Re: [squid-users] Authentication Issue with Squid and mixed BASIC/NTLM auth Um, something weird is going on. I'm a little scared

Re: [squid-users] Verify Squid.conf File

2008-10-21 Thread Amos Jeffries
Tarak Ranjan wrote: hi List, can anyone provide me the url for verifying yhe squid.conf file. i want suggestion from the list , that how my current squid.conf file looks, how can i improve the security as wl as performance level , Sorry I have not maintained the tester very well. I figured

Re: [squid-users] integration with active directory

2008-10-21 Thread Amos Jeffries
Matt Harrison wrote: Hi all, I have a gentoo box that acts as a firewall, router and squid proxy. I've been following a guide[1] to integrate squid authentication with our active directory domain. The guide is a little bit out of date and it doesn't seem to work for me. Authentication is

Re: [squid-users] How can I block a https site?

2008-10-22 Thread Amos Jeffries
Matus UHLAR - fantomas wrote: On 21.10.08 16:23, Alejandro Bednarik wrote: You can also use url_regex -i acl bad_sites url_regex -i /etc/squid/bad_sites.txt http_access deny bad_sites using regexes is very ineffective and may lead to problems if you don't count with: - dot matching ANY

Re: [squid-users] about refresh_pattern

2008-10-23 Thread Amos Jeffries
Sandy lone wrote: Hello, Under what cases squid will use refresh_pattern? If the response objects have expire or age headers, squid will follow their values. Yes. Unless refresh_pattern have been specified with ignore-* HTTP violations. If the response objects have neither expire nor age

Re: [squid-users] squid3 keeps many idle connections

2008-10-23 Thread Amos Jeffries
Malte Schröder wrote: On Thu, 23 Oct 2008 01:10:58 +0200 Henrik Nordstrom [EMAIL PROTECTED] wrote: On ons, 2008-10-22 at 11:31 +0200, Malte Schröder wrote: Not normal. Squid version? 3.0.STABLE10 And how did you measure these? You are not counting TIME_WAIT sockets are you? by getting

Re: [squid-users] How can I block a https site?

2008-10-23 Thread Amos Jeffries
with: - dot matching ANY character - regex matching the middle of string, not just the end of it (like dstdomain does) On 22.10.08 23:45, Amos Jeffries wrote: - URL parts often included in regex not occuring in CONNECT requests. - neither the http(s):// part. no, but it can match different

Re: [squid-users] Question about ACLs and http_access in Squid 3

2008-10-24 Thread Amos Jeffries
Tom Williams wrote: Ok, now that I've basically got Squid 3 configured as a HTTP accelerator, I have a question about ACL rules and http_access. Here is the basic config: I've got two web servers behind a load balancer. The idea is to have Squid server as a HTTP accelerator for Apache so

Re: [squid-users] How do I configure Keepalive-Timeout?

2008-10-24 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: Hello,I have a question. I'd like to configure Keepalive-Timeout. But I can't find Keepalive section in the squid.conf file. Does persistent_request_timeoutTAG mean Keepalive-timeout? If so, Can I choose KeepAlive on or KeepAlive off on each destination site? And

Re: [squid-users] Problems with downloads

2008-10-25 Thread Amos Jeffries
Henrik Nordstrom wrote: On fre, 2008-10-24 at 08:31 -0500, Osmany Goderich wrote: It was the range_offset_limit -1 KB line that was not letting squid resume downloads. I set it back to 0KB as it is by default and woila!!! Everything back to normal!! Good. range_offset_limit -1 says Squid

Re: [squid-users] Question about ACLs and http_access in Squid 3

2008-10-25 Thread Amos Jeffries
Tom Williams wrote: Amos Jeffries wrote: Tom Williams wrote: Ok, now that I've basically got Squid 3 configured as a HTTP accelerator, I have a question about ACL rules and http_access. Here is the basic config: I've got two web servers behind a load balancer. The idea is to have Squid

Re: [squid-users] Delivering ident to url_rewrite_program

2008-10-26 Thread Amos Jeffries
Stefan Adams wrote: In squid 3.0STABLE9: Following Redirector interface is broken re IDENT values from http://wiki.squid-cache.org/SquidFaq/SquidRedirectors, I can see ident requests appearing in access.log, but with a url_rewrite_program of /usr/bin/tee, the ident field is ALWAYS '-'. I have

Re: [squid-users] Delivering ident to url_rewrite_program

2008-10-27 Thread Amos Jeffries
Stefan Adams wrote: On Sun, Oct 26, 2008 at 8:35 PM, Amos Jeffries [EMAIL PROTECTED] wrote: Stefan Adams wrote: In squid 3.0STABLE9: Following Redirector interface is broken re IDENT values from http://wiki.squid-cache.org/SquidFaq/SquidRedirectors, I can see ident requests appearing

[squid-users] Squid 3.1.0.1 beta is available

2008-10-28 Thread Amos Jeffries
please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

Re: [squid-users] NTLMv2 issue caused by Samba's Winbind helper

2008-10-29 Thread Amos Jeffries
Jamie Stallwood wrote: Hi, One of my customers has had issues with authentication Vista machines when using the Samba 2.0 winbind authenticator program in Squid. The NTLM authenticator returned: Login for user [EMAIL PROTECTED] failed due to [Invalid parameter] auth_param ntlm program

Re: [squid-users] SQUID + FIREFOX + ACTIVE DIRECTORY

2008-10-29 Thread Amos Jeffries
Chris Robertson wrote: Chris Nighswonger wrote: On Wed, Oct 29, 2008 at 5:16 PM, nairb rotsak [EMAIL PROTECTED] wrote: http_access allow all NTLMUsers Does the 'all' trump the 'NTLMUsers' acl here? Chris The all is redundant. The all ACL will always match, so the test next falls

Re: [squid-users] Squid 3.1

2008-10-31 Thread Amos Jeffries
İsmail ÖZATAY wrote: Hi there, I can not configure squid 3.1 beta on my openbsd 4.3 server. When try to configure a get lots of errors. Has anybody ever tried this ? Thanks ismail Some details about the errors would be helpful. Others have managed to get it to work on OpenBSD. Amos --

Re: [squid-users] Connection to webmail sites problem using more than one parent proxy

2008-10-31 Thread Amos Jeffries
Sergio wrote: Hello Everybody, We have this scenario: We have proxy connected to internet trough 3 parent proxy [client] | | [proxy] | | +-+---+ | | | [parentproxy1],[parentproxy2],[parentproxy3] We have

Re: [squid-users] Connection to webmail sites problem using more than one parent proxy

2008-10-31 Thread Amos Jeffries
Sergio wrote: Hello Everybody, We have this scenario: We have proxy connected to internet trough 3 parent proxy [client] | | [proxy] | | +-+---+ | | | [parentproxy1],[parentproxy2],[parentproxy3] We have

Re: [squid-users] Javaws apps with SQUID

2008-10-31 Thread Amos Jeffries
italianpenguin wrote: An update : disabling ntlm authentication in squid, and setting http_access allow all temporarly, everything works. So probably the problem is NTLM authentication. Is there a way to tell squid that javaws requests are not checked by the squid authorizations ? Regards

Re: [squid-users] Resend: Squid and DNS

2008-10-31 Thread Amos Jeffries
░▒▓ ɹɐzǝupɐɥʞ ɐzɹıɯ ▓▒░ wrote: anyone can help me ? 2008/10/28 ░▒▓ ɹɐzǝupɐɥʞ ɐzɹıɯ ▓▒░ [EMAIL PROTECTED]: i use this : http://etutorials.org/shared/images/tutorials/tutorial_102/bssl_0202.gif but the Between Switch -router and Firewall . i put squid server how to make ppl ( local ) can

Re: [squid-users] Performance

2008-10-31 Thread Amos Jeffries
Marcel Grandemange wrote: Good day users. I seem to have a performance issue where my squid server doesn't seem to exceed 400k on objects in cache, it is not the specs of the box as im able to with Different proxy software achieve 8m on a P3. Advise? Need More info? Yes, * version of

Re: [squid-users] High Load

2008-10-31 Thread Amos Jeffries
Pablo García wrote: Luis, Please define Heavy Load, how manu req/s, is this a forward, transparent or reverse proxy ? is this a memory only cache ? what are the vmstat outputs when it stops responding ? did run the ulimit -n 16384 before start the squid ? Are there any error messages in the

Re: [squid-users] does squid support authentication in transparent mode ?

2008-10-31 Thread Amos Jeffries
nishith datta wrote: is it possible to support ncsa based authentication in transparent mode proxy In short No. Amos -- Please be using Current Stable Squid 2.7.STABLE5 or 3.0.STABLE10 Current Beta Squid 3.1.0.1

Re: [squid-users] Ignoring query string from url

2008-10-31 Thread Amos Jeffries
nitesh naik wrote: Henrik, url rewrite helper script works fine for few requests ( 100 req/sec ) but slows down response as number of requests increase and it takes 10+ second to deliver the objects. Is there way to optimise it further ? url_rewrite_program /home/zdn/bin/redirect_parallel.pl

Re: [squid-users] SQUID + FIREFOX + ACTIVE DIRECTORY

2008-10-31 Thread Amos Jeffries
nairb rotsak wrote: I am actually flabbergasted at all the people saying this doesn't work. I haven't tried Squid 3 yet.. so I can't comment on it. The squid that comes with Ubuntu (6.06) is squid 2.5 (I think) the one with 8.04 is squid 2.6 (again, just going from what I remember.. I am

Re: [squid-users] Resend: Squid and DNS

2008-10-31 Thread Amos Jeffries
at 11:08 AM, Amos Jeffries [EMAIL PROTECTED] wrote: ░▒▓ ɹɐzǝupɐɥʞ ɐzɹıɯ ▓▒░ wrote: anyone can help me ? 2008/10/28 ░▒▓ ɹɐzǝupɐɥʞ ɐzɹıɯ ▓▒░ [EMAIL PROTECTED]: i use this : http://etutorials.org/shared/images/tutorials/tutorial_102/bssl_0202.gif but the Between Switch -router and Firewall . i put

Re: [squid-users] Squid 3.1

2008-11-01 Thread Amos Jeffries
İsmail ÖZATAY wrote: Amos Jeffries yazmış: İsmail ÖZATAY wrote: Hi there, I can not configure squid 3.1 beta on my openbsd 4.3 server. When try to configure a get lots of errors. Has anybody ever tried this ? Thanks ismail Some details about the errors would be helpful. Others have

Re: [squid-users] squid accelerator always requests peer to refresh

2008-11-01 Thread Amos Jeffries
Daniel Vollbrecht wrote: I configured Squid (3.0 STABLE7) in web accelerator mode to speed up a slow dynamic website. Now all img and css files are completely served by squid. They don't show up on the slow machine 10.1.1.2. But the dynamic content itself always (page reload, other clients)

Re: [squid-users] Squid 3.1

2008-11-01 Thread Amos Jeffries
İsmail ÖZATAY wrote: Amos Jeffries yazmış: İsmail ÖZATAY wrote: Amos Jeffries yazmış: İsmail ÖZATAY wrote: Hi there, I can not configure squid 3.1 beta on my openbsd 4.3 server. When try to configure a get lots of errors. Has anybody ever tried this ? Thanks ismail Some details about

Re: [squid-users] squid accelerator always requests peer to refresh

2008-11-01 Thread Amos Jeffries
Daniel Vollbrecht wrote: Are the dynamically generated pages given proper expiry information? (Expires: or Cache-Control: headers) the dynamically generated page answers with these headers (wget -S): Expires: Mon, 26 Jul 1997 05:00:00 GMT Cache-Control: no-cache, must-revalidate Pragma:

Re: [squid-users] no response from squid while telnetting

2008-11-02 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: hiii, i m using squid Version 3.0.STABLE9, while i telnet on the squid box then it only shows [EMAIL PROTECTED] ~] % telnet proxy1.zodiac.com.np 80 Trying 202.79.40.131... Connected to proxy1.zodiac.com.np. Escape character is '^]'. it doesn't send any bad error

RE: [squid-users] Performance

2008-11-02 Thread Amos Jeffries
Marcel Grandemange wrote: Good day users. I seem to have a performance issue where my squid server doesn't seem to exceed 400k on objects in cache, it is not the specs of the box as im able to with Different proxy software achieve 8m on a P3. Advise? Need More info? Yes, * version

Re: [squid-users] Reverse - Apache - Syn Flood

2008-11-02 Thread Amos Jeffries
Hi all, I want to setup Squid reverse proxy for my apache servers. But.. Can Squid protect my apache servers from Syn flood and Bot-Net attack ? or Squid drop this connection, when apache is the syn_recv ? or Squid Reverse be enough to this as resource ? or Can it be resource problem?

Re: [squid-users] SquidNT TCP_DENIED

2008-11-03 Thread Amos Jeffries
Chris Lee wrote: Hi, Form the access.log of my new SquidNT (version 2.7.STABLE4) box, I got some TCP_DENIED entry, before the users can access the website. SquidNT no longer exists. If you fetched it from a website claiming to be SquidNT, please be aware there are now fraudulent

Re: [squid-users] error:unsupported-request-method

2008-11-03 Thread Amos Jeffries
??? ??z?up??? ?z??? ??? wrote: 1225701560.304 1 192.169.1.56 TCP_DENIED/400 1614 NONE error:unsupported-request-method - NONE/- text/html what is that mean ? squid 2x ( from UBUNTU packages ) A program tried to use the proxy with a request that is either not HTTP or is part of the HTTP

Re: [squid-users] R: [squid-users] Connection to webmail sites problem using more than one parent proxy

2008-11-03 Thread Amos Jeffries
! Thanks a lot for help! Sergio -Messaggio originale- Da: Amos Jeffries [mailto:[EMAIL PROTECTED] Inviato: sabato 1 novembre 2008 4.40 A: Sergio Cc: squid-users@squid-cache.org Oggetto: Re: [squid-users] Connection to webmail sites problem using more than one parent proxy Sergio wrote

Re: [squid-users] error:unsupported-request-method

2008-11-03 Thread Amos Jeffries
On Tue, Nov 4, 2008 at 5:48 AM, Amos Jeffries [EMAIL PROTECTED] wrote: A program tried to use the proxy with a request that is either not HTTP or is part of the HTTP extensions your squid can't handle yet. see cache.log for info on which request method was tried. Amos -- Please be using

Re: [squid-users] origin server health detect

2008-11-04 Thread Amos Jeffries
nitesh naik wrote: Hi, Is there way to stop forwarding requests to origin if monitoring url returns 404 in squid 3 ? Sometimes few nodes in our origin server cluster are unavailable and we would like to disable origin which is up but responding with 404 http status code. Also I would like to

Re: [squid-users] Squid-3 + Tproxy4 clarification

2008-11-04 Thread Amos Jeffries
Arun Srinivasan wrote: Hi List, Has anyone successfully used cache_peer support with tproxy4 enabled? Not that I'm aware of at this point. The scenario is running Squid proxy with tproxy4 enabled and another http proxy (no tproxy4) on the same box. First Squid would receive the request

Re: [squid-users] Timezone issue

2008-11-04 Thread Amos Jeffries
squid wrote: If you want to display the local time in squid error pages, you should change or edit the squid error pages as you want. Please read : http://www.squid-cache.org/mail-archive/squid-users/199904/0133.html Or if you want to change the time zone in logformat refer :

Re: [squid-users] Squid-3 + Tproxy4 clarification

2008-11-05 Thread Amos Jeffries
to try having both squid instances listening on different ports of the machines public IP. You will still loose the spoofing ability within the second-hop proxy, but the traffic should at least flow properly. Amos 2008/11/4 Amos Jeffries [EMAIL PROTECTED]: Arun Srinivasan wrote: Hi List, Has

Re: [squid-users] squid cache proxy + Exchange 2007 problems

2008-11-05 Thread Amos Jeffries
Retaliator wrote: Hello, i found out after few months i have problems with clients using office 2007 against exchange 2007. if proxy is enabled out of office and more issues wont work becasue squid blocks them, the autodiscover service is a part of exchange 2007, if you remove the proxy it

Re: [squid-users] Ignoring query string from url

2008-11-05 Thread Amos Jeffries
nitesh naik wrote: Hi All, Issues was with Disk I/O. I have used null cache dir and squid response is much faster now. cache_dir null /empty Thanks everyone for your help. Regards Nitesh Oh dear, I can't believe I overlooked this. cache_dir aufs (linux) or diskd (FreeBSD) is likely to

Re: [squid-users] Vedio streming erros

2008-11-05 Thread Amos Jeffries
Hi, We want to go to below website which contains streaming vedio. When We get there all the images. But We will NOT get streaming vedio. If We bypass squid, We get streamig Vedio. http://uticctv.mine.nu/index.htm The above site has a user name and password. I can Not give it you. sorry

Re: [squid-users] Re: Constant Login Prompt for NTLM Auth against Samba PDC

2008-11-05 Thread Amos Jeffries
I figured it out to a point: I had this config, which worked on another setup: #Samba PDC Auth auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp #auth_param ntlm max_challenge_reuses 0 #auth_param ntlm max_challenge_lifetime 2 minutes auth_param ntlm children

Re: [squid-users] Squid memory usage

2008-11-06 Thread Amos Jeffries
nitesh naik wrote: Hi All, Squid memory usage grows beyond allocate cache_mem size of 8 GB. Total physical memory available on machine is 20 GB. Does that mean there is memory leak and I should replace malloc library and compile squid ? cache_mem is the size of the in-memory object cache

Re: [squid-users] Security Concerns

2008-11-06 Thread Amos Jeffries
On Thu, 2008-11-06 at 14:52 +, David Hurcomb wrote: Hello, I am running Squid on a Linux box which is also hosting a customer database (Oracle). I am concerned that by having the Proxy server on the same box as the database that I am introducing an increased security risk. e.g. an

Re: [squid-users] HTTP header field {\r}

2008-11-06 Thread Amos Jeffries
Luis Daniel Lucio Quiroz wrote: Hi Squids, I'm having a lot of: HTTP header field {\r} at cache.log. Currently we are having performance problems. This log is related to my performance? Maybe. What type of performance problems? How can I explain this, why this happens, are we having

Re: [squid-users] Auto-configuration file hosted by squid

2008-11-06 Thread Amos Jeffries
Jan Welker wrote: Hi, We do have three types of client proxy configurations at our company: 1. Direct proxy: proxy.company.com:8080 2. Auto-configuration file: http://proxy.company.com:8080/ 3. Auto detect proxy.company.com:80 Clients use ether one of the configuration. The client

Re: [squid-users] Minimum object freshness

2008-11-06 Thread Amos Jeffries
Arun Srinivasan wrote: Hi all, What is the minimum time an object in the cache would remain fresh (assuming min age in default refresh_pattern is set to 0)? somewhere between 0 seconds and undetermined. default refresh_pattern only has affect when A) server provides no freshness info, and

Re: [squid-users] Question

2008-11-06 Thread Amos Jeffries
Monah Baki wrote: Hi all, We have 2 squid servers running 2.7 stable 5. One is locally in our data center, the other is located remotely on the clients network. Is it possible to have whatever cached objects our local server has be replicated on the client? Each squid caches what it can

Re: [squid-users] url length limit

2008-11-06 Thread Amos Jeffries
Gregori Parker wrote: Hi all - I am using an array of squid servers to accelerate dynamic content, running 2.6.22 and handling a daily average of about 400 req/sec across the cluster. We operate diskless and enjoy a great hit rate (80%) on very short-lived content. About 50+ times per day, the

Re: [squid-users] How can I reduce the cache time,please?

2008-11-06 Thread Amos Jeffries
cicl chu wrote: Hi, The squid version I used is 2.5.STABLE14. Now, the min cache time is 2 minutes. How can I reduced the cache time to 1 minute, or less, please? Thanks! Please upgrade. 2.5 is very, very obsolete. Cache time is best altered by correct HTTP headers sent from the web server.

Re: [squid-users] how to route proxied web traffic out alternate gateway

2008-11-06 Thread Amos Jeffries
gluker wrote: i have a squid box with one interface (eth0). i receive web requests from my network on this interface. i would like retrieve the web sites requested from a cable modem. i would like for the cable modem to be used for web traffic ONLY. All other traffic would be routed back thru

[squid-users] Re: R: [squid-users] Connection to webmail sitesproblem using more than one parent proxy

2008-11-07 Thread Amos Jeffries
Sergio wrote: Hi Henrik, hi Amos Now with the last configuration it seems the sourcehas is working corectly. So this is the final configuration cache_peer myparentproxy1.dipvvf.it parent 3128 3130 sourcehash no-query cache_peer myparentproxy2.dipvvf.it parent 3128 3130 sourcehash no-query

Re: [squid-users] WCCP and Web Cache Packet Return

2008-11-07 Thread Amos Jeffries
Bin Liu wrote: Hi, Just read the WCCPv2 document from http://www.cisco.com/en/US/docs/ios/12_0t/12_0t3/feature/guide/wccp.html. It seems that WCCPv2 support web caches tunneling back the packets they do not service to the same router from where they are received. Once a router has received a

Re: [squid-users] Auto-configuration file hosted by squid

2008-11-07 Thread Amos Jeffries
urlpath_regex ^/proxy\.pac$ Amos Thanks, Jan On Fri, Nov 7, 2008 at 4:05 AM, Amos Jeffries [EMAIL PROTECTED] wrote: Jan Welker wrote: Hi, We do have three types of client proxy configurations at our company: 1. Direct proxy: proxy.company.com:8080 2. Auto-configuration file: http

Re: [squid-users] deny_info customization

2008-11-07 Thread Amos Jeffries
Henrik Nordstrom wrote: On fre, 2008-11-07 at 12:23 -0600, Luis Daniel Lucio Quiroz wrote: Hi Squids, There are several questions I have about deny_info I couldnt find. Looking at I found that %U corresponds url blocked, %w to wemaster email. There are other several %'s that I dont

Re: [squid-users] video stream

2008-11-08 Thread Amos Jeffries
Jeff P. wrote: Does squid support video stream protocal? like playing movies online. Thanks. Squid is HTTP-only. It supports those streaming servers which send their content through HTTP. But not those restricted to the RTSP and related stream protocols. Amos -- Please be using Current

[squid-users] Squid 3.1.0.2 beta is available

2008-11-09 Thread Amos Jeffries
with this release please file a bug report. http://bugs.squid-cache.org/ Amos Jeffries

Re: [squid-users] url length limit

2008-11-09 Thread Amos Jeffries
are all listed in the commit message: http://www.squid-cache.org/Versions/v3/3.1/changesets/b9208.patch (NOTE: the cache_dir null setting is still explicitly required for 3.0 as for 2.x) Amos -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: Thursday, November 06

Re: [squid-users] Unable to forward this request at this time.

2008-11-09 Thread Amos Jeffries
??? ??z?up??? ?z??? ??? wrote: i cant browse from outside and local ERROR The requested URL could not be retrieved While trying to retrieve the URL: http://monitor.gpi-g.com/ The following error was encountered: * Unable to forward this request at this time. This request could not

Re: [squid-users] Unable to forward this request at this time.

2008-11-09 Thread Amos Jeffries
a configuration problem. By your description (IPs the same) your squid is supposed to be an accelerator for that website. Which means the cache_peer configuration needs to be checked. Amos On Mon, Nov 10, 2008 at 11:21 AM, Amos Jeffries [EMAIL PROTECTED] wrote: ??? ??z?up??? ?z??? ??? wrote: i cant

Re: [squid-users] Unable to forward this request at this time.

2008-11-10 Thread Amos Jeffries
IP 202.169.51.118 and monitor.gpi-g.com is 202.169.51.118 too What is Squid IP? Is web server actually running on 202.169.51.118:80? snip On Mon, Nov 10, 2008 at 11:28 AM, Amos Jeffries [EMAIL PROTECTED] wrote: ??? ??z?up??? ?z??? ??? wrote: my squid working for other site :( fyi : my

Re: [squid-users] squid and loadbalancing option

2008-11-10 Thread Amos Jeffries
Martin Mulder wrote: Hi, I have (maybee a stupid) question. I have an apache server as reverse proxy, squid as caching server and Zope/Plone as backend servers. Senario: 1) Apache gets a request for my.domain.com 2) Apache does a ProxyPass to my balancer 3) I have 2 sticky vhosts in apache

Re: [squid-users] squid 3.1 is stable enough for production / testing?

2008-11-10 Thread Amos Jeffries
3.1 is certainly ready for testing. That's why we started making beta releases (3.1.0.X). Please give it a try and report back your findings. I don't think this is a setup that is commonly tested so it's very good if you can test this now while the release is actively being tested. Regards

RE: [squid-users] parseHTTPRequest problem with SQUID3

2008-11-10 Thread Amos Jeffries
Thanks for your response That message means there was no HTTP/1.0 tag on the request line. Squid begins assuming HTTP/0.9 traffic. Squid 2.6 handled these fine, and my configuration hasnt changed, so was there something introduced in Squid3 that demands a hostname? no. Something has

Re: [squid-users] Unable to forward this request at this time.

2008-11-10 Thread Amos Jeffries
, external IP if squid is external, localhost maybe if squid is on same machine). Amos On Mon, Nov 10, 2008 at 9:47 PM, Henrik Nordstrom [EMAIL PROTECTED] wrote: On tis, 2008-11-11 at 03:14 +1300, Amos Jeffries wrote: Henrik Nordstrom wrote: From the error it sounds like it has declared

Re: [squid-users] Run squid2.5.6 and dansguardian got error message: (111) Connection refused

2008-11-10 Thread Amos Jeffries
thanks for your help, I run wget [EMAIL PROTECTED] logs]# wget www.google.com --09:19:40-- http://www.google.com/ = `index.html' Connecting to 10.0.2.110:9090... connected. Proxy request sent, awaiting response... 403 Forbidden 09:19:41 ERROR 403: Forbidden. this is the info

Re: [squid-users] Unable to forward this request at this time.

2008-11-11 Thread Amos Jeffries
░▒▓ ɹɐzǝupɐɥʞ ɐzɹıɯ ▓▒░ wrote: On Tue, Nov 11, 2008 at 9:31 AM, Amos Jeffries [EMAIL PROTECTED] wrote: Ahh okay. cache_peer 202.169.51.118 should be the web server IP as seen from Squid (internal IP if squid is internal, external IP if squid is external, localhost maybe if squid is on same

Re: [squid-users] Run squid2.5.6 and dansguardian got error message: (111) Connection refused

2008-11-11 Thread Amos Jeffries
zhang yikai wrote: 10.0.2.110 is the machine run squid and dansguardian, thank you for your reply. - Original Message - From: Henrik Nordstrom [EMAIL PROTECTED] To: zhang yikai [EMAIL PROTECTED] Cc: Amos Jeffries [EMAIL PROTECTED]; Kinkie [EMAIL PROTECTED]; squid-users@squid

Re: [squid-users] Run squid2.5.6 and dansguardian got error message: (111) Connection refused

2008-11-11 Thread Amos Jeffries
] To: zhang yikai [EMAIL PROTECTED] Cc: Amos Jeffries [EMAIL PROTECTED]; Kinkie [EMAIL PROTECTED]; squid-users@squid-cache.org Sent: Tuesday, November 11, 2008 3:32 PM Subject: Re: [squid-users] Run squid2.5.6 and dansguardian got error message: (111) Connection refused Understood. We got squid

Re: [squid-users] parseHTTPRequest problem with SQUID3

2008-11-11 Thread Amos Jeffries
Henrik Nordstrom wrote: On tis, 2008-11-11 at 15:24 +1300, Amos Jeffries wrote: Not fully 1.1, but from (0.9 + 1.0) to fully 1.0 + partial 1.1. Which is weird because 2.6 went almost fully 1.0 as well quite a while back. From this discussion it seems Squid-3 no longer accepts the obsolete

  1   2   3   4   5   6   7   8   9   10   >