Re: [squid-users] possible memory leak

2007-11-01 Thread Tek Bahadur Limbu
Hi Rihad, rihad wrote: Squid using almost twice as much memory as was accounted for (according to top(1)): 4243 squid 29 200 1325M 1317M kserel 42:39 0.00% squid Since last time, after you reduced your cache_mem from 1000 MB to 300 MB, your Squid memory usage has gone down

[squid-users] transparent Proxy

2007-11-01 Thread Tarak Ranjan
Hi List, I'm new to this list. i have a question about transparent proxy. if i apply an ACL for downloading mp3 and mpeg. but it's not working, user's are able to download mp3 or mpeg... here is my config..squid.conf file. port 8080 acl blocksites url_regex

Re: [squid-users] Squid Stopped Working

2007-11-01 Thread Tek Bahadur Limbu
Hi Jason, Jason Zammit wrote: Hi, Squid suddenly stopped working this afternoon. I am very new to squid and linux. I have gone through the cache.log and came across this section, which would have been around the time I started getting calls. Any help or advice is appreciated CACHE.LOG

[squid-users] First Time squid Config Problem

2007-11-01 Thread Robin-Vossen
Hello, I am a first time user of Squid. I think its great and I want to get a certificate or something that supports that I can fully operate Squid. But thats now where my question is about. My question is about my config. My /etc/squid/squid.conf file Is written by myself. And I think I made a

[squid-users] Squid to Log DNS Querys

2007-11-01 Thread Robin-Vossen
Hello, I wonder is there a way to log all DNS requests that go out of our network with Squid. Since I noticed that we had a Trojan Horse on our Company Network. And well it didnt send it self the data out. It did send DNS Querys to there DNS Server.. And a Firewall doesnt detect that. Is there a

RE: [squid-users] transparent Proxy

2007-11-01 Thread Thomas Raef
You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl http_access deny blocksites One other

[squid-users] FTP Client to work through squid

2007-11-01 Thread cuchulain 78
Hi all, If Im correct in my research FTP clients will only work through Squid if they have a HTTP mode available. Ive tested with CuteFTP which works fine through Squid but does anybody know of any free FTP clients that would have this mode? Many thanks,

Re: [squid-users] Squid Cache on a Solaris ZFS file system

2007-11-01 Thread Tek Bahadur Limbu
Hi Michael, Michael Pye wrote: On Tue, Oct 30, 2007 at 01:38:31PM +0545, Tek Bahadur Limbu wrote: I wanted to know if somebody here is running a Squid cache on a Solaris box (i386)? Basically, I want to know if somebody here on this list is using a ZFS file system for a proxy cache and what

RE: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Thomas Raef
Hello, I wonder is there a way to log all DNS requests that go out of our network with Squid. Since I noticed that we had a Trojan Horse on our Company Network. And well it didnt send it self the data out. It did send DNS Querys to there DNS Server.. And a Firewall doesnt detect that. Is

Re: [squid-users] transparent Proxy

2007-11-01 Thread Tarak Ranjan
Thomas Raef wrote: You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl http_access deny

Re: [squid-users] transparent Proxy

2007-11-01 Thread Amos Jeffries
Thomas Raef wrote: You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl http_access deny blocksites

Re: [squid-users] Squid Stopped Working

2007-11-01 Thread Amos Jeffries
Tek Bahadur Limbu wrote: Hi Jason, Jason Zammit wrote: Hi, Squid suddenly stopped working this afternoon. I am very new to squid and linux. I have gone through the cache.log and came across this section, which would have been around the time I started getting calls. Any help or advice

RE: [squid-users] transparent Proxy

2007-11-01 Thread Thomas Raef
Thomas Raef wrote: You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl http_access

RE: [squid-users] transparent Proxy

2007-11-01 Thread Thomas Raef
Thomas Raef wrote: You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl http_access

Re: [squid-users] transparent Proxy

2007-11-01 Thread Amos Jeffries
Tarak Ranjan wrote: Thomas Raef wrote: You need to apply your acls with some deny statements. http_reply_access deny blockfiles for your mp3's, etc. To block websites I use dstdomain instead of url_regex. So my squid.conf contains: acl blocksites dstdomain /etc/squid/squid-block.acl

Re: [squid-users] Squid and squid_ldap_auth... strange base needed!

2007-11-01 Thread Amos Jeffries
Mauricio Silveira wrote: Hi all I'm a real newbie on using LDAP... I'm using here Slackware 12 without pam. I have just compiled squid 2.6.STABLE16, I'm on a fight with the ldap auth module... Look at this: The former: /usr/libexec/squid/squid_ldap_auth -b dc=LINUXDEV,dc=INTRANET -D

Re: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Marcus Kool
When you install a name server on the box where Squid is and change /etc/resolv.conf you can see all queries of Squid (provided that no other software runs on the box). -Marcus Thomas Raef wrote: Hello, I wonder is there a way to log all DNS requests that go out of our network with Squid.

Re: [squid-users] First Time squid Config Problem

2007-11-01 Thread Michael Alger
On Thu, Nov 01, 2007 at 03:06:38AM -0700, Robin-Vossen wrote: My /etc/squid/squid.conf file Is written by myself. And I think I made a mistake somewere since when I start Squid it crashes. Did you check the squid logs to see what the problem was? The cache log is the one you'll be looking for.

Re: [squid-users] transparent Proxy

2007-11-01 Thread Tarak Ranjan
ok. it's seems to me that it's working. i have another issue for this . while manually in my browser if i select proxy then the acl's are working fine . when i select Auto detect that time it's not working, in the sense acl's are hot hitting. although i've disable allow_direct okay,

RE: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Robin-Vossen
Ok, damn.. :( I just have to find something else to do that then.. Thanks for telling me :( traef06 wrote: Hello, I wonder is there a way to log all DNS requests that go out of our network with Squid. Since I noticed that we had a Trojan Horse on our Company Network. And well it didnt

[squid-users] spontaneous machine reboots

2007-11-01 Thread rihad
Machine running Squid 2.6 with kqueue+aufs on FreeBSD 6.2 reboots spontaneously every 2-3 days. We've practically ruled out hardware problems by replacing the box and having the same problems. Squid port build options: everything off, except aufs and kqueue. Some squid.conf lines: cache_mem

Re: [squid-users] transparent Proxy

2007-11-01 Thread Tarak Ranjan
[Tom replied with:] More information about your configuration is needed. Are you using a transparent proxy? If not, then your users could easily add their own proxy settings and bypass squid. If you are using squid in transparent mode, then your firewall rules redirecting port 80 traffic to

Re: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Tek Bahadur Limbu
Hi Robin, Robin-Vossen wrote: Hello, I wonder is there a way to log all DNS requests that go out of our network with Squid. Since I noticed that we had a Trojan Horse on our Company Network. And well it didnt send it self the data out. It did send DNS Querys to there DNS Server.. And a Firewall

[squid-users] Jason Fitzpatrick is out of the office.

2007-11-01 Thread Jason . Fitzpatrick
I will be Out of the Office Start Date: 31/10/2007. End Date: 05/11/2007. I am currently out of the office, I will respond to your message when I return. If the matter is urgent please contact a member of the LPIS Technical Services Team.

Re: [squid-users] spontaneous machine reboots

2007-11-01 Thread Slacker
rihad, on 11/01/2007 04:38 PM [GMT+500], wrote : Machine running Squid 2.6 with kqueue+aufs on FreeBSD 6.2 reboots spontaneously every 2-3 days. We've practically ruled out hardware problems by replacing the box and having the same problems. So you thinks its squid causing these reboots?

[squid-users] Domain URL blacklists

2007-11-01 Thread Paul Cocker
I am using elements of Shalla's blacklists to block content. However, they ship in two files, domains and URLs, the former being IP addresses and the later URLs. Since our squid proxy is running on Windows I would need to experiment with cygwin to get SquidGuard running, and that isn't something I

Re: [squid-users] spontaneous machine reboots

2007-11-01 Thread Adrian Chadd
On Thu, Nov 01, 2007, rihad wrote: Machine running Squid 2.6 with kqueue+aufs on FreeBSD 6.2 reboots spontaneously every 2-3 days. We've practically ruled out hardware problems by replacing the box and having the same problems. Squid port build options: everything off, except aufs and

RE: [squid-users] Domain URL blacklists

2007-11-01 Thread Paul Cocker
My bad, in fact from further analysis it seems that the domain files are the mysite.com listings and URLs are things like mysite.com/something/?somethingelse.htm. Does the later have any relevance or use within Squid? Paul Cocker IT Systems Administrator -Original Message- From: Paul

Re: [squid-users] How to setup squid as http proxy server

2007-11-01 Thread Keshava M P
Hi, Have you put the correct http_port directive in your squid.conf? It should be something like http_port 127.0.0.1:3178 cheers! On 10/31/07, ying lcs [EMAIL PROTECTED] wrote: Hi, I am able to compile and get squid running on my ubuntu machine. However, when I see my proxy setting in my

Re: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Robin-Vossen
Well I have no idea what the name of the Trojan horse was. But, our DNS server was down. And I still had DNS querys over the network. I thought that was strange. But I thought.. Oh Well So, some time later on some PCs started to show Trojan behavior. (Minesweeper autostarting etc) I thought, oh

Re: [squid-users] First Time squid Config Problem

2007-11-01 Thread Robin-Vossen
Thanks alot Ill look into that asap. And well the Typo error are since I am building Squid on a Gentoo box without a Graphical Shell or a Webbrowser ;) Thanks again Ill look into that asap. Michael Alger-3 wrote: On Thu, Nov 01, 2007 at 03:06:38AM -0700, Robin-Vossen wrote: My

[squid-users] professional support recomendations

2007-11-01 Thread Robin Mordasiewicz
Can anyone recomend a good professional support organization for squid. ie. providing 24*7 phone support. The company I work for requires a support contract for all software. --

[squid-users] ssl cert chain support for squid

2007-11-01 Thread Srinivas B
Hi, As we know, Verisign is switching to 3 tier ssl, It requires Intermediate cert now. I am using Squid 2.6 stable 12. and also was looking at this thread http://www.squid-cache.org/mail-archive/squid-users/200410/1017.html But I dont know how to specify this. any help?? Thanks srini

RE: [squid-users] Domain URL blacklists

2007-11-01 Thread Thomas Raef
My bad, in fact from further analysis it seems that the domain files are the mysite.com listings and URLs are things like mysite.com/something/?somethingelse.htm. Does the later have any relevance or use within Squid? Paul Cocker IT Systems Administrator [Tom replied with:] I don't

Re: [squid-users] Domain URL blacklists

2007-11-01 Thread jeff donovan
On Nov 1, 2007, at 10:23 AM, Paul Cocker wrote: My bad, in fact from further analysis it seems that the domain files are the mysite.com listings and URLs are things like mysite.com/something/?somethingelse.htm. Does the later have any relevance or use within Squid? Paul Cocker IT Systems

Re: [squid-users] ssl cert chain support for squid

2007-11-01 Thread Michael Pye
On Thu, Nov 01, 2007 at 09:56:08AM -0700, Srinivas B wrote: As we know, Verisign is switching to 3 tier ssl, It requires Intermediate cert now. I asked this very same question only yesterday. See http://marc.info/?l=squid-usersm=119383366330808w=2 You need to have your regular ssl certifcate

RE: [squid-users] Domain URL blacklists

2007-11-01 Thread Paul Cocker
Just squid, it's running on a Windows box and I don't have the time currently to figure out how to run cygwin and squidguard together, so I'm looking simply to hook the most useful lists direct into squid and see how much it harms performance. Paul Cocker IT Systems Administrator -Original

[squid-users] squid setuid-binary ncsa_auth and pam_auth

2007-11-01 Thread Cryer,Phil
During a review on squid, we found the following setuid-binary set to run as root E: squid setuid-binary /usr/lib64/squid/ncsa_auth root 04750 E: squid setuid-binary /usr/lib64/squid/pam_auth root 04750 Kicking around Google I find that: ncsa_auth allows Squid to read and authenticate user and

Re: [squid-users] Squid2.6 Stable with Mac OSX issue

2007-11-01 Thread Chris Robertson
Eric Young wrote: I am running Squid2.6 stable running on Win2003 I have a stable config running with 120+ WinXP boxes and 130+ users. I have 3 Mac OSX workstations that like the XP workstations are setup with manual proxy settings. My problem is that Mac users are getting prompt every

Re: [squid-users] squid_radius_auth

2007-11-01 Thread Chris Robertson
Matt Ruzicka wrote: We're in process of rebuilding a couple web filter boxes on Centos 4.5 running Squid 2.5.STABLE14 (latest from yum) using squid_radius_auth 1.09 for authentication with the following config: auth_param basic program /usr/local/squid/libexec/squid_radius_auth -f

RE: [squid-users] squid_radius_auth

2007-11-01 Thread Matt Ruzicka
Thanks everyone for the advice. I'm working on installing and testing 2.6 STABLE16. I'll see where we're at then, but I suspect things will be looking better. Thanks. Matt Ruzicka Sr. Systems Engineer [EMAIL PROTECTED] www.cisp.com www.yocolo.com 419.724.5345 : tel 419.867.6913 : fax

[squid-users] squid proccess freeze

2007-11-01 Thread Alexandre Correa
Hello !! I testing squid on freebsd 6.2 amd64+SMP, server is 2 procs dual-core opteron 4gb ram ... after some time running .. squid proccess refusing connections, if i try to kill them, proccess don=B4t stop.. no errors is show.. without core dumps= ... # ps auwx | grep squid USERPID

Re: [squid-users] possible memory leak

2007-11-01 Thread Chris Robertson
rihad wrote: Squid using almost twice as much memory as was accounted for (according to top(1)): 4243 squid 29 200 1325M 1317M kserel 42:39 0.00% squid Is this expected? From http://wiki.squid-cache.org/SquidFaq/SquidMemory#head-0b5e485f61e7ea4e580c60f45177f0bbcf7d7b80

Re: [squid-users] Configure squid based on content type of http response (RESOLUTION)

2007-11-01 Thread Dmitry S. Makovey
On October 31, 2007, Dmitry S. Makovey wrote: #http_reply_access allow all acl plain_content rep_mime_type -i text/plain # http_reply_access allow GET_method xml_content from_clients redirect_program /usr/local/bin/myscript redirector_access plain_content http_reply_access allow

Re: [squid-users] Squid to Log DNS Querys

2007-11-01 Thread Amos Jeffries
When you install a name server on the box where Squid is and change /etc/resolv.conf you can see all queries of Squid (provided that no other software runs on the box). Doesn't have to be on the same box as squid either. It's still the NS logging not squid. Amos -Marcus Thomas Raef

Re: [squid-users] First Time squid Config Problem

2007-11-01 Thread Amos Jeffries
Thanks alot Ill look into that asap. And well the Typo error are since I am building Squid on a Gentoo box without a Graphical Shell or a Webbrowser ;) Thanks again Ill look into that asap. Michael Alger-3 wrote: On Thu, Nov 01, 2007 at 03:06:38AM -0700, Robin-Vossen wrote: My

Re: [squid-users] Can ANyone Help Me Re: [squid-users] ACL Question - (urlpath_r

2007-11-01 Thread Chris Robertson
Vadim Pushkin wrote: Thanks Chris; Based on your excellent example: acl DenyIP_CONNECT url_regex ^[a-z]{1-5}://[0-9] Would I still be required to write IP addresses with a netmask? Or can I mix them, which is my preference. If I remember correctly, the dst acl prefers a netmask these

RE: [squid-users] Domain URL blacklists

2007-11-01 Thread Amos Jeffries
Just squid, it's running on a Windows box and I don't have the time currently to figure out how to run cygwin and squidguard together, so I'm looking simply to hook the most useful lists direct into squid and see how much it harms performance. Paul Cocker IT Systems Administrator

Re: [squid-users] Domain URL blacklists

2007-11-01 Thread Chris Robertson
Paul Cocker wrote: My bad, in fact from further analysis it seems that the domain files are the mysite.com listings and URLs are things like mysite.com/something/?somethingelse.htm. Does the later have any relevance or use within Squid? Paul Cocker IT Systems Administrator The first would

Re: [squid-users] professional support recomendations

2007-11-01 Thread Amos Jeffries
Can anyone recomend a good professional support organization for squid. ie. providing 24*7 phone support. The company I work for requires a support contract for all software. http://www.squid-cache.org/Support/services.dyn Amos

Re: [squid-users] squid setuid-binary ncsa_auth and pam_auth

2007-11-01 Thread Amos Jeffries
During a review on squid, we found the following setuid-binary set to run as root E: squid setuid-binary /usr/lib64/squid/ncsa_auth root 04750 E: squid setuid-binary /usr/lib64/squid/pam_auth root 04750 Kicking around Google I find that: ncsa_auth allows Squid to read and authenticate user

Re: [squid-users] squid proccess freeze

2007-11-01 Thread Amos Jeffries
Hello !! I testing squid on freebsd 6.2 amd64+SMP, server is 2 procs dual-core opteron 4gb ram ... after some time running .. squid proccess refusing connections, if i try to kill them, proccess don=B4t stop.. no errors is show.. without core dumps= ... # ps auwx | grep squid USER

Re: [squid-users] Can ANyone Help Me Re: [squid-users] ACL Question - (urlpath_r

2007-11-01 Thread Amos Jeffries
Vadim Pushkin wrote: Thanks Chris; Based on your excellent example: acl DenyIP_CONNECT url_regex ^[a-z]{1-5}://[0-9] Would I still be required to write IP addresses with a netmask? Or can I mix them, which is my preference. If I remember correctly, the dst acl prefers a netmask these

RE: [squid-users] squid3 WindowsUpdate failed

2007-11-01 Thread Jorge Bastos
I've updated squid with the resume fix, and WU still not working. --- squid3 (3.0.RC1-2) unstable; urgency=low * debian/patches/08-resume-http.dpatch - Added upstream patch fixing failure to resume downloads --- Any idea? -Original Message- From: Amos Jeffries [mailto:[EMAIL

[squid-users] Re: Squid can't connect some web sites

2007-11-01 Thread Cheng Bruce
Hi, After I added the following line in the squid.conf, it runs well. header_access Via deny all On 10/25/07, Cheng Bruce [EMAIL PROTECTED] wrote: Dear all, Recently I meet the strange problem, Squid can't access some web sites. For example, http://www.hsa.gov.sg/ I'm using pfSense

RE: [squid-users] squid3 WindowsUpdate failed

2007-11-01 Thread Amos Jeffries
I've updated squid with the resume fix, and WU still not working. --- squid3 (3.0.RC1-2) unstable; urgency=low * debian/patches/08-resume-http.dpatch - Added upstream patch fixing failure to resume downloads --- Any idea? Now its probably time to do a proper debug. You could

Re: [squid-users] Re: Squid can't connect some web sites

2007-11-01 Thread Amos Jeffries
Hi, After I added the following line in the squid.conf, it runs well. header_access Via deny all Curiouser and Curiouser. That means the website is attempting to do some form of user tracking and proxy detection. Probably is that weather bit then, trying to locate the local weather for

Fwd: [squid-users] Squid-2.6(stable13) surport multi router with wccpv2

2007-11-01 Thread hobbes
Thank you! On 10/31/07, Adrian Chadd [EMAIL PROTECTED] wrote: On Wed, Oct 31, 2007, Amos Jeffries wrote: Do squid-2.6(stable13) surport multi router with wccpv2 ? To one router ,i test it successfully,now i don't know if surport multi router. Yes. Just add multiple wccp2_router

Re: [squid-users] possible memory leak

2007-11-01 Thread rihad
Chris Robertson wrote: rihad wrote: Squid using almost twice as much memory as was accounted for (according to top(1)): 4243 squid 29 200 1325M 1317M kserel 42:39 0.00% squid Is this expected? From