FW: [squid-users] Peering squid multiple instances.

2010-03-24 Thread GIGO .
From: gi...@msn.com To: squ...@treenet.co.nz Subject: RE: [squid-users] Peering squid multiple instances. Date: Wed, 24 Mar 2010 07:12:15 + Dear Amos, Thank you for your response and better design tips. However i am not able to comprehend

Re: [squid-users] Peering squid multiple instances.

2010-03-24 Thread Amos Jeffries
GIGO . wrote: Dear Amos, Thank you for your response and better design tips. However i am not able to comprehend it well (due to lack of expereince and knowledge both however at current). So i request you to elaborate it a bit more. Your guidance would be a real valuable. Question 1: You

Re: [squid-users] The requested URL could not be retrieved TCP_MISS/502

2010-03-24 Thread Umesh Bodalina
Could this mean that there is a problem with the web site or their network? Or is it some kind of configuration issue on our squid proxy or our network? Regards Umesh On 23 March 2010 16:20, Zeller, Jan jan.zel...@id.unibe.ch wrote: hmm seems not to work properly : behind proxy : $ httping

[squid-users] Not accessing privoxy parent

2010-03-24 Thread Gerard Earley
Hi all I'm trying to set up squid as a adblocking proxy by using privoxy as a parent. Unfortunately squid doesn't seem to want to access the parent privoxy. The authentication works, its simply accessing the parent that's not doing what it should. Any help would be appreciated. via off

[squid-users] Issues with Radius,Squid3, 64 Bit

2010-03-24 Thread mickymax
Hi, I am using Squid3S25 on Suse SLES 10, 64 bit, squid_radius_auth-1.10. When I try squid_radius_auth with a user bob with password secret with the command squid_radius_auth -h x.x.x.x -w shared_secret1 I can see that the password secret of a user seems to be garbage: [files] users: Matched

Re: [squid-users] Issues with Radius,Squid3, 64 Bit

2010-03-24 Thread Amos Jeffries
micky...@gmx.de wrote: Hi, I am using Squid3S25 on Suse SLES 10, 64 bit, squid_radius_auth-1.10. When I try squid_radius_auth with a user bob with password secret with the command squid_radius_auth -h x.x.x.x -w shared_secret1 I can see that the password secret of a user seems to be

Re: [squid-users] Issues with Radius,Squid3, 64 Bit

2010-03-24 Thread mickymax
Thx for the quick reply. Do you know if there is a timeline for adjusting the RADIUS module for squid/64? Or is there no priority for this? Micky Original-Nachricht Datum: Thu, 25 Mar 2010 01:09:34 +1300 Von: Amos Jeffries squ...@treenet.co.nz An:

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Leonardo Carneiro - Veltrac
Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines all have a CA certificate installed to make them trust the proxy for decryption.

Re: [squid-users] Issues with Radius,Squid3, 64 Bit

2010-03-24 Thread Amos Jeffries
micky...@gmx.de wrote: Thx for the quick reply. Do you know if there is a timeline for adjusting the RADIUS module for squid/64? Or is there no priority for this? There is no plans for RADIUS in Squid. Amos -- Please be using Current Stable Squid 2.7.STABLE8 or 3.0.STABLE25 Current

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Amos Jeffries
Leonardo Carneiro - Veltrac wrote: Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines all have a CA certificate installed to make

Re: [squid-users] Issues with Radius,Squid3, 64 Bit

2010-03-24 Thread Amos Jeffries
micky...@gmx.de wrote: Thx for the quick reply. Do you know if there is a timeline for adjusting the RADIUS module for squid/64? Or is there no priority for this? There is no plans for RADIUS in Squid. Amos -- Please be using Current Stable Squid 2.7.STABLE8 or 3.0.STABLE25 Current

[squid-users] TCP_HIT/504 on fetch after UDP_HIT

2010-03-24 Thread Taylan Develioglu
Hi, I'm trying to set up two squid siblings in front of lighttpd as reverse proxies and have a question about some behavior I'm seeing. Squid versions are 2.7.STABLE7-1~bpo50+1 from the debian backports repository. My goal is to create a setup with two cache siblings and one origin server

Re: [squid-users] squid 3.0.19 + transparent + sslbump

2010-03-24 Thread Stefan Reible
Zitat von Amos Jeffries squ...@treenet.co.nz: Leonardo Carneiro - Veltrac wrote: Amos Jeffries wrote: Some factums worth knowing: * 3.0 does not support sslBump or any other form of HTTPS man-in-middle attacks. 3.1 is required for that. * sslBump in 3.1 requires that the client machines

Re: [squid-users] TCP_HIT/504 on fetch after UDP_HIT

2010-03-24 Thread Taylan Develioglu
I know it's bad form to reply to your own post, but I found a partial explanation. from http://linuxdevcenter.com/pub/a/linux/2001/09/17/squidpeering.html?page=2 FALSE HITS: (ICP only) Because ICP does not communicate request headers (only the URI is presented in an ICP query), it is possible

[squid-users] Allowing ports used by Squid through Iptables.

2010-03-24 Thread GIGO .
I want to do the security hardening of my Squid Server with Iptables. I intend to have no rule on outbond traffic however ibound traffic would be restricted. please guide what are the minimum ports that are required to be open on iptables. Following is what i thought: Allow all incoming

Re: [squid-users] TPROXY and DansGuardian

2010-03-24 Thread Jason Healy
On Mar 24, 2010, at 1:37 AM, Amos Jeffries wrote: From what I understand of your requirements you don't actually need DG or anything but Squid alone. Squid can log in any format you choose to configure. If there is anything it does not yet log we'd be interested in hearing about that. DG

[squid-users] Map Single URL to Multiple Store urls

2010-03-24 Thread Ken Struys
Is there anyway to map single url's to multiple store url's based on a cookie? Lets say I have a user cookie and I want to implement caching for logged in users. I there anyway in squid I can append the cookie to the cached url? (in squid not on the client side url). I've looked at doing

Re: [squid-users] TCP_HIT/504 on fetch after UDP_HIT

2010-03-24 Thread Taylan Develioglu
I switched to htcp, but I'm still getting false hits (504). On Wed, 2010-03-24 at 15:10 +0100, Taylan Develioglu wrote: I know it's bad form to reply to your own post, but I found a partial explanation. from http://linuxdevcenter.com/pub/a/linux/2001/09/17/squidpeering.html?page=2 FALSE

[squid-users] HTCP for consistent caches for reverse proxies

2010-03-24 Thread Georg Höllrigl
Hello, Is there a way to get two squid caches used as reverse proxy to have an consistent cache? An example would be a file that contains abcd - I request the file, get balanced to squid1 which caches the file du to the expire header for one hour. Then the file gets changed to contain abcde.

[squid-users] Help with accelerated site

2010-03-24 Thread a...@gmail
Hello All, I have followed this configuration, but when I try and access the website from outside my network All I get is the default page of the apache on the machine where the Squid proxy is installed Here is the link: http://wiki.squid-cache.org/ConfigExamples/Reverse/BasicAccelerator

Re: [squid-users] Map Single URL to Multiple Store urls

2010-03-24 Thread Amos Jeffries
On Wed, 24 Mar 2010 11:04:03 -0400, Ken Struys k...@struys.ca wrote: Is there anyway to map single url's to multiple store url's based on a cookie? Lets say I have a user cookie and I want to implement caching for logged in users. I there anyway in squid I can append the cookie to the

Re: [squid-users] Allowing ports used by Squid through Iptables.

2010-03-24 Thread Amos Jeffries
On Wed, 24 Mar 2010 14:11:46 +, GIGO . gi...@msn.com wrote: I want to do the security hardening of my Squid Server with Iptables. I intend to have no rule on outbond traffic however ibound traffic would be restricted. please guide what are the minimum ports that are required to be open on

Re: [squid-users] HTCP for consistent caches for reverse proxies

2010-03-24 Thread Amos Jeffries
On Wed, 24 Mar 2010 17:44:27 +0100, Georg Höllrigl georg.hoellr...@xidras.com wrote: Hello, Is there a way to get two squid caches used as reverse proxy to have an consistent cache? An example would be a file that contains abcd - I request the file, get balanced to squid1 which caches

[squid-users] Re: Squid Kerb Auth Issue

2010-03-24 Thread Markus Moeller
How did you create the keytab ? Markus Nick Cairncross nick.cairncr...@condenast.co.uk wrote in message news:c7ce8144.1d5e1%nick.cairncr...@condenast.co.uk... Hi, I'm concerned by a problem with my HTTP.keytab 'expiring'. My test base have reported a problem to me that they are prompted

Re: [squid-users] Help with accelerated site

2010-03-24 Thread Ron Wheeler
What is squid proxying? Usually the normal behaviour is exactly what you are getting since squid normally proxies Apache on 80. Browser == Squid on 80==proxied to Apache on port 81. If Squid is not proxying Apache, then it looks like you have Apache running on 80. If you are trying to

[squid-users] pinger? what for

2010-03-24 Thread Luis Daniel Lucio Quiroz
HI squids, I did realize that in latest snapshoot 3.1 has pinger disabled. I wonder to know what for pinger is? TIA LD

[squid-users] WebFilter by ip

2010-03-24 Thread Landy Landy
Hello List. I have an acl blocking a batch of ip addresses banned from using the internet and have others that can use the internet without problems. Now, I would like to filter the web content to those users that use the internet. I would like to block sexual content and stuff like that that

Re: [squid-users] WebFilter by ip

2010-03-24 Thread Luis Daniel Lucio Quiroz
Le Mercredi 24 Mars 2010 18:30:49, Landy Landy a écrit : Hello List. I have an acl blocking a batch of ip addresses banned from using the internet and have others that can use the internet without problems. Now, I would like to filter the web content to those users that use the internet. I

Re: [squid-users] WebFilter by ip

2010-03-24 Thread Landy Landy
Thanks in advanced for your help. go to  Dansguardian or SquidGuard I've read about these two utilities but, the problem is filtering the content for specific ip addresses.

Re: [squid-users] Help with accelerated site

2010-03-24 Thread Amos Jeffries
On Wed, 24 Mar 2010 19:48:27 -0400, Ron Wheeler rwhee...@artifact-software.com wrote: What is squid proxying? Usually the normal behaviour is exactly what you are getting since squid normally proxies Apache on 80. Browser == Squid on 80==proxied to Apache on port 81. If Squid is not

Re: [squid-users] WebFilter by ip

2010-03-24 Thread donovan jeffrey j
On Mar 24, 2010, at 8:30 PM, Landy Landy wrote: Hello List. I have an acl blocking a batch of ip addresses banned from using the internet and have others that can use the internet without problems. Now, I would like to filter the web content to those users that use the internet. I would

Re: [squid-users] pinger? what for

2010-03-24 Thread Amos Jeffries
On Wed, 24 Mar 2010 18:28:53 -0600, Luis Daniel Lucio Quiroz luis.daniel.lu...@gmail.com wrote: HI squids, I did realize that in latest snapshoot 3.1 has pinger disabled. I wonder to know what for pinger is? Squid uses it to securely do ICMP to measure distance to the possible source

[squid-users] sarg and Squid 3 Stable20

2010-03-24 Thread Joseph L. Casale
Using the redhat package on CentOS 5x64, sarg faults and can't generate all of the files needed for the view. This worked on the older version in the main repo, is there something known to change to allow sarg to work or is the issue unexpected? Thanks! jlc

Re: [squid-users] Help with accelerated site

2010-03-24 Thread a...@gmail
Hello there, Thanks for the reply Ron and Amos Maybe my original e-mail wasn't clear a bit confusing I am sorry if I confused you I have squid running on Machine A with let's say local ip 192.168.1.4 the backend server is running on machine B and ip address 192.168.1.3 Now, instead of

Re: [squid-users] Help with accelerated site

2010-03-24 Thread Ron Wheeler
a...@gmail wrote: Hello there, Thanks for the reply Ron and Amos Maybe my original e-mail wasn't clear a bit confusing I am sorry if I confused you I have squid running on Machine A with let's say local ip 192.168.1.4 the backend server is running on machine B and ip address 192.168.1.3

Re: [squid-users] Cancelled downloads

2010-03-24 Thread Carlos Lopez
Hi, I have the same situation with users on my site, they download many BIG files and then cancel them, eventhough I set some delay pools so they get bured, but the big files are kept by squid and the HD is getting full. Is there any solution to solve it, thru SQUID?. Carlos --- El sáb,

[squid-users] Squid redirection

2010-03-24 Thread jayesh chavan
Hi, I have written script which redirects my squid to local apache.It works fine for FOLLOWING SCRIPT #!c:/perl/bin/perl.exe $|=1; while () { s...@http://www.az@http://117.195.4.252@; print; } But whenever I use this script #!c:/perl/bin/perl.exe $|=1; while

[squid-users] Squid Compilation and Active Directory Authentication

2010-03-24 Thread GIGO .
purpose: To authenticate squid users through active directory before allowing them access to internet. Compile Options: ./configure --prefix=/usr --localstatedir=/var --libexecdir=${prefix}/lib/squid --srcdir=. --datadir=${prefix}/shares/squid --sysconfdir=/etc/squid3