[squid-users] Call for adaptation after sni peeked

2019-10-22 Thread Jatin Bhasin
Hi All, This question is related to ssl decryption and ecap adaptation call. When the ssl connection starts then before it even extracts sni squid sends fakeConnect which comes to ecap as well. I am using peek in step 1 and after fakeConnect squid extracts the sni, but at this point squid does no

Re: [squid-users] assertion failed: Controller.cc:838: "!transients || e.hasTransients()"

2019-10-22 Thread Alex Rousskov
On 10/22/19 3:24 PM, Antonio SJ Musumeci wrote: > Squid 4.8 > > Attempting to get a SMP setup with rock enabled. Instance points to an > origin web server. > > With "workers 1" everything appears to work fine. If I set "workers 2" I > get a number of issues: > > If I request a particular object

[squid-users] assertion failed: Controller.cc:838: "!transients || e.hasTransients()"

2019-10-22 Thread Antonio SJ Musumeci
Squid 4.8 Attempting to get a SMP setup with rock enabled. Instance points to an origin web server. With "workers 1" everything appears to work fine. If I set "workers 2" I get a number of issues: If I request a particular object a kid will fail with: assertion failed: Controller.cc:838: "

Re: [squid-users] (no subject)

2019-10-22 Thread Vieri Di Paola
On Tue, Oct 22, 2019 at 1:48 PM Amos Jeffries wrote: > > I do not see any DIVERT rule at all in your firewall config dump. That > is at least part of the problem. I opened the previous dump and saw the divert rules here below: Chain PREROUTING (policy ACCEPT 573K packets, 462M bytes) pkts bytes

Re: [squid-users] (no subject)

2019-10-22 Thread Vieri Di Paola
On Tue, Oct 22, 2019 at 1:48 PM Amos Jeffries wrote: > > On 22/10/19 11:22 pm, Vieri Di Paola wrote: > > > > I use Shorewall on this system. This program configures iptables and > > routing. > > I dumped all the network information while trying to access port 80 on > > host with IP addr. 104.113.

Re: [squid-users] (no subject)

2019-10-22 Thread Amos Jeffries
On 22/10/19 11:22 pm, Vieri Di Paola wrote: > > I use Shorewall on this system. This program configures iptables and routing. > I dumped all the network information while trying to access port 80 on > host with IP addr. 104.113.250.104 form local host with IP addr. > 10.215.144.48: I do not see

Re: [squid-users] (no subject)

2019-10-22 Thread Vieri Di Paola
Hi, On Fri, Oct 18, 2019 at 10:13 PM Amos Jeffries wrote: > > If you are able to share your config maybe we could help spot something, > both for that and for the timeout issue. I prepared and tested a trimmed-down squid conf: # cat squid.conf acl SSL_ports port 443 acl Safe_ports port 80

Re: [squid-users] external_acl_type and ipv6

2019-10-22 Thread Amos Jeffries
On 22/10/19 7:31 pm, Vieri Di Paola wrote: > Hi, > > What is the advantage of using ipv6 instead of ipv4 by default for > external_acl_type? > * larger packet sizes, * simplicity, and * all modern OS support IPv6 by default. There is also: " o IPv6 s