[squid-users] SquidNT TCP_DENIED

2008-11-02 Thread Chris Lee
Hi, Form the access.log of my new SquidNT (version 2.7.STABLE4) box, I got some TCP_DENIED entry, before the users can access the website. 1225693114.517 10 10.1.10.147 TCP_DENIED/407 1721 CONNECT urs.microsoft. com:443 - NONE/- text/html 1225693114.547 30 10.1.10.147 TCP_DENIED/407 193

[squid-users] squid is dying

2008-11-02 Thread Anuj Shrestha
i m using squid in freebsd 7.0 below are the compile options, proxy01# squid -v Squid Cache: Version 3.0.STABLE9 configure options: '--bindir=/usr/local/sbin' '--sysconfdir=/usr/local/etc/squid' '--datadir=/usr/local/etc/squid' '--libexecdir=/usr/local/libexec/squid' '--localstatedir=/usr/loc

Re: [squid-users] no response from squid while telnetting

2008-11-02 Thread Anuj Shrestha
Hii, It does work with GET aa/n/n but not with aa/n/n, i had problem with alteon squid fail over, now its fine and thank you for your valuable reply. thanks, anuj shrestha Amos Jeffries wrote: [EMAIL PROTECTED] wrote: hiii, i m using squid Version 3.0.STABLE9, while i telnet on the squ

Re: [squid-users] Ignoring query string from url

2008-11-02 Thread nitesh naik
Henrik / Amos, Tried using these setting and I could see see delay in serving the requests even for cached objects. 1225687535.330 5459 81.52.249.101 TCP_MEM_HIT/200 1475 GET http://abc.xyz.com/3613/172/500/248/211/i5.js?z=9059 - NONE/- application/x-javascript 1225687535.330 5614 81.52.249.1

RE: [squid-users] Reverse - Apache - Syn Flood

2008-11-02 Thread Adam Carter
> Connection flooding is worse.. and requires offending clients to be > blacklisted by firewalling once identified. If it's a botnet, there can be tens of thousands of hosts, so blacklisting can be difficult. Also, unless you have a multi-gigabit connection then they can just fill your pipe with

Re: [squid-users] Reverse - Apache - Syn Flood

2008-11-02 Thread Amos Jeffries
> Hi all, > > I want to setup Squid reverse proxy for my apache servers. But.. Can > Squid protect my apache servers from Syn flood and Bot-Net attack ? or > Squid drop this connection, when apache is the syn_recv ? or Squid > Reverse be enough to this as resource ? or Can it be resource problem? >

RE: [squid-users] Performance

2008-11-02 Thread Amos Jeffries
> > Marcel Grandemange wrote: >> Good day users. >> >> >> I seem to have a performance issue where my squid server doesn't seem to >> exceed 400k on objects in cache, it is not the specs of the box as im >> able >> to with >> Different proxy software achieve 8m on a P3. >> >> Advise? Need More info

Re: [squid-users] Reverse - Apache - Syn Flood

2008-11-02 Thread Henrik Nordstrom
On sön, 2008-11-02 at 20:34 +0200, Mehmet CELIK wrote: > I want to setup Squid reverse proxy for my apache servers. But.. Can > Squid protect my apache servers from Syn flood and Bot-Net attack ? or > Squid drop this connection, when apache is the syn_recv ? or Squid > Reverse be enough to this as

[squid-users] Reverse - Apache - Syn Flood

2008-11-02 Thread Mehmet CELIK
Hi all, I want to setup Squid reverse proxy for my apache servers. But.. Can Squid protect my apache servers from Syn flood and Bot-Net attack ? or Squid drop this connection, when apache is the syn_recv ? or Squid Reverse be enough to this as resource ? or Can it be resource problem? thanks ever

RE: [squid-users] Performance

2008-11-02 Thread Marcel Grandemange
>I'd also check "df -i", maybe you're running out of inodes in your cache dir Doesn’t seem so df -i Filesystem 1K-blocks UsedAvail Capacity iused ifree %iused Mounted on /dev/ad0s1a 81029320 28328770 4621820638% 613110 98675286% / devfs 11

RE: [squid-users] Performance

2008-11-02 Thread Marcel Grandemange
Marcel Grandemange wrote: > Good day users. > > > I seem to have a performance issue where my squid server doesn't seem to > exceed 400k on objects in cache, it is not the specs of the box as im able > to with > Different proxy software achieve 8m on a P3. > > Advise? Need More info? > >Yes,

Re: [squid-users] Questions on research into using digest auth against MS AD2003

2008-11-02 Thread Henrik Nordstrom
On lör, 2008-11-01 at 19:49 -0700, Chuck Kollars wrote: > "One-time" generally refers to the 'nonce' (and 'cnonce') used by > challenge-response authentication protocols. But verifying the > nonce-hashed-by-password would require using the actual original > cleartext password, something proxies do

Re: [squid-users] no response from squid while telnetting

2008-11-02 Thread Amos Jeffries
[EMAIL PROTECTED] wrote: hiii, i m using squid Version 3.0.STABLE9, while i telnet on the squid box then it only shows [EMAIL PROTECTED] ~] % telnet proxy1.zodiac.com.np 80 Trying 202.79.40.131... Connected to proxy1.zodiac.com.np. Escape character is '^]'. it doesn't send any bad error as

Re: [squid-users] ACLs based on users based on Samba PDC?

2008-11-02 Thread Leonardo Rodrigues Magalhães
Adam McCarthy escreveu: After much fussing, I seem to have a working Squid 2.6 working against a Samba 3 PDC. My only question is now, can I say, ok, if you finds my username, give it complete access. Then perhaps, if it sees user, "bob" perhaps, then it says, only give them windowsupdate.mic

Re: [squid-users] Squid 3.1

2008-11-02 Thread İsmail ÖZATAY
Henrik Nordstrom yazmış: On lör, 2008-11-01 at 14:05 +0200, İsmail ÖZATAY wrote: I'm suspecting it may be gcc-3.3 related. Is there a more recent gcc version you can upgrade to and try again? Amos Opps i am already using gcc version 3.3.5 . ;) . I have just checked it... Is