RE: [squid-users] Full domain block

2007-11-05 Thread Paul Cocker
Thanks, chaps. Should be easy enough as there's a line break prior to each name so a simple search & replace should nail them all. Paul Cocker IT Systems Administrator TNT Post -Original Message- From: Thomas Raef [mailto:[EMAIL PROTECTED] Sent: 05 November 2007 19:12 To: squid-users@sq

Re: [squid-users] Squid cluster - flat or hierarchical

2007-11-05 Thread Amos Jeffries
John Moylan wrote: Hi, I have 4 Squid 2.6 reverse proxy servers sitting behind an LVS loadbalancer with 1 public IP address. In order to improve the hit rate all 4 servers are all peering with eachother using ICP. squid1 -> sibling squid{2,3,4} squid2 -> sibling squid{1,3,4} squid3 -> sibling

Re: [squid-users] FreeBSD, enable or not memory_pools

2007-11-05 Thread Alexandre Correa
i´m using memory_pools on memory_pools_limit 16 MB working fine.. :) On Nov 6, 2007 3:31 AM, Tek Bahadur Limbu <[EMAIL PROTECTED]> wrote: > Hi Alexandre, > > Alexandre Correa wrote: > > Hello !! > > > > Wich is best for FreeBSD, enable or disable memory_pools ? > > > > freebsd 6.2 amd64 > > Th

Re: [squid-users] FreeBSD, enable or not memory_pools

2007-11-05 Thread Tek Bahadur Limbu
Hi Alexandre, Alexandre Correa wrote: Hello !! Wich is best for FreeBSD, enable or disable memory_pools ? freebsd 6.2 amd64 The default value seems to work fine for me. But you are free to experiment with it and report back your results! regards !! -- With best regards and good wishe

RE: [squid-users] Quick question about an cache.log issue

2007-11-05 Thread Amos Jeffries
> Thanks Amos, the tool (http://squid.treenet.co.nz/cf.check/) was very > ... enlightening. I think this squid newbie will work through some > of the errors and warnings before I post back. :) > It's new code and still undergoing some extensions. Some items listed as 'not present version X' ac

RE: [squid-users] Quick question about an cache.log issue

2007-11-05 Thread Eric Young
Thanks Amos, the tool (http://squid.treenet.co.nz/cf.check/) was very ... enlightening. I think this squid newbie will work through some of the errors and warnings before I post back. :) Thanks Eric Young -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED] Sent: Mon

Re: [squid-users] Optimal maximum cache size

2007-11-05 Thread Amos Jeffries
> Is there such a thing as too much disk cache? Presumably squid has to > have some way of checking this cache, and at some point it takes longer > to look for a cached page than to serve it direct. At what point do you > hit that sort of problem, or is it so large no human mind should worry? > :)

Re: [squid-users] Quick question about an cache.log issue

2007-11-05 Thread Amos Jeffries
> In my cache.log I am getting > > Looks to me like: > > 2007/11/05 09:23:42| The request GET http://cp.slalom.com/ is DENIED, > because it matched 'password' someone forgot their password. or browsers first request for the item. > 2007/11/05 09:23:42| The reply for GET http://cp.slalom.com/ is

[squid-users] FreeBSD, enable or not memory_pools

2007-11-05 Thread Alexandre Correa
Hello !! Wich is best for FreeBSD, enable or disable memory_pools ? freebsd 6.2 amd64 regards !! -- Sds. Alexandre J. Correa Onda Internet / OPinguim.net http://www.ondainternet.com.br http://www.opinguim.net

[squid-users] squidGuard 1.3.0 released

2007-11-05 Thread Guido Serassio
We are pleased to announce the availability of the release 1.3.0 of squidGuard. squidGuard-1.3.0 is based on the original squidguard-1.2.0 codebase, but has many new publicly available enhancements and features which have been developed over the last six years after squidGuard-1.2.0 was released,

RE: [squid-users] Full domain block

2007-11-05 Thread Thomas Raef
You'll have to modify each domain entry for squid dstdomain. The line containing youtube.com has to be .youtube.com in order for squid to block the entire domain. Thomas J. Raef e-Based Security, LLC www.ebasedsecurity.com 1-866-838-6108 "You're either hardened, or you're hacked!" > -Origina

[squid-users] Optimal maximum cache size

2007-11-05 Thread Paul Cocker
Is there such a thing as too much disk cache? Presumably squid has to have some way of checking this cache, and at some point it takes longer to look for a cached page than to serve it direct. At what point do you hit that sort of problem, or is it so large no human mind should worry? :) Paul IT

Re: [squid-users] Full domain block

2007-11-05 Thread Jason Taylor
Paul Cocker wrote: Alas, it was all so perfectly planned. Grab some blacklists from Shalla - http://www.shallalist.de/ - and hook the domain lists into squid using dstdomain. Unfortunately, it seems squid's interpretation of domain names is incredibly literal, so rather than youtube.com blocking

[squid-users] Full domain block

2007-11-05 Thread Paul Cocker
Alas, it was all so perfectly planned. Grab some blacklists from Shalla - http://www.shallalist.de/ - and hook the domain lists into squid using dstdomain. Unfortunately, it seems squid's interpretation of domain names is incredibly literal, so rather than youtube.com blocking *.youtube.com, we in

[squid-users] Quick question about an cache.log issue

2007-11-05 Thread Eric Young
In my cache.log I am getting 2007/11/05 09:23:42| The request GET http://cp.slalom.com/ is DENIED, because it matched 'password' 2007/11/05 09:23:42| The reply for GET http://cp.slalom.com/ is ALLOWED, because it matched 'password' 2007/11/05 09:23:42| The request GET http://cp.slalom.com/ is

Re: [squid-users] squid3 WindowsUpdate failed

2007-11-05 Thread Alex Rousskov
On Sun, 2007-11-04 at 19:30 +1300, Amos Jeffries wrote: > I have just had the opportunity to do WU on a customers box and > managed to reproduce one of the possible WU failures. > > This one was using WinXP, and the old WindowsUpdate (NOT > MicrosoftUpdate, teht remains untested). With squid conf

Re: [squid-users] Trying to trouble-shot a squid redirector error

2007-11-05 Thread Alex Rousskov
On Fri, 2007-11-02 at 12:01 -0500, ying lcs wrote: > I am trying to setup squid redirector on squid 2.6 STABLE 16 based on > content type. i.e. if squid sees content type == text/plain redirects > to 'http://127.0.0.1/dummy.txt'. > > A kind person helped me with this configuration for my needs:

[squid-users] Squid cluster - flat or hierarchical

2007-11-05 Thread John Moylan
Hi, I have 4 Squid 2.6 reverse proxy servers sitting behind an LVS loadbalancer with 1 public IP address. In order to improve the hit rate all 4 servers are all peering with eachother using ICP. squid1 -> sibling squid{2,3,4} squid2 -> sibling squid{1,3,4} squid3 -> sibling squid{1,2,4} squid4 -

Re: [squid-users] Basic Pam authentification problem with on mandrake 9.0

2007-11-05 Thread Edjé
ok i'll try it. Selon Amos Jeffries <[EMAIL PROTECTED]>: > Edjé wrote: > > I have an understanding problem with squid-2.4 on red Hat 9.0. My settings > are: > > > > For squid authentification: > > > > authenticate_program /usr/lib/squid/pam_auth > > authenticate_children 25 > > auth

Re: [squid-users] Basic Pam authentification problem with on mandrake 9.0

2007-11-05 Thread Amos Jeffries
Edjé wrote: I have an understanding problem with squid-2.4 on red Hat 9.0. My settings are: For squid authentification: authenticate_program /usr/lib/squid/pam_auth authenticate_children 25 authenticate_ttl 1 hour authenticate_ip_ttl 7200 seconds authenticate_ip_ttl_is_str

Re: [squid-users] Multiple instances of Squid necessary for multiple IP's?

2007-11-05 Thread Amos Jeffries
Adrian Chadd wrote: On Sat, Nov 03, 2007, Reid wrote: I'm running Squid on a server that has 3 IP addresses, and clients can connect to the proxy using any of the 3 IP's. Currently the OUTgoing IP always appears as a single IP, but I want the outgoing IP to appear as the IP that the client con

[squid-users] Basic Pam authentification problem with on mandrake 9.0

2007-11-05 Thread Edjé
I have an understanding problem with squid-2.4 on red Hat 9.0. My settings are: For squid authentification: authenticate_program /usr/lib/squid/pam_auth authenticate_children 25 authenticate_ttl 1 hour authenticate_ip_ttl 7200 seconds authenticate_ip_ttl_is_strict on acl