RE: [squid-users] Allowing linked sites - NTLM and un-authenticated users

2012-04-03 Thread Jasper Van Der Westhuizen
-Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: Monday, April 02, 2012 9:27 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users On 2/04/2012 5:54 p.m., Jasper Van Der Westhuizen wrote:

Re: [squid-users] Authentication problem

2012-04-03 Thread Amos Jeffries
On 3/04/2012 3:40 a.m., Mohamed Amine Kadimi wrote: Dear Developpers and Community, I would like to set up the following configuration using squid: When a user asks for a web page he is transparently redirected to squid, where an authentication must be done before serving the user with

Re: [squid-users] squid refresh_pattern - different url with same XYZ package

2012-04-03 Thread Amos Jeffries
On 3/04/2012 5:57 a.m., Mohsen Saeedi wrote: Hi I have a problem with squid refresh_pattern. i used regex on refresh_pattern and every exe file for example cached and then clients can download it with high rate. but when someone download from some website(for example mozilla or filehippo) ,

Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users

2012-04-03 Thread Amos Jeffries
On 3/04/2012 6:12 p.m., Jasper Van Der Westhuizen wrote: -Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: Monday, April 02, 2012 9:27 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users On

[squid-users] ntlm and kerberos

2012-04-03 Thread Anders.Larsson
Hi! Im using at the moment ntlm to auth to AD, I got a test server that are using Kerberos.. Now I want to change the prod machine to use Kerberos to.. is there a way to have both auth directives in conf ? I want to take it in steps so I have to create a acl for src ip/hosts.. But how do I

Re: [squid-users] squid refresh_pattern - different url with same XYZ package

2012-04-03 Thread Eliezer Croitoru
On 03/04/2012 09:37, Amos Jeffries wrote: On 3/04/2012 5:57 a.m., Mohsen Saeedi wrote: Hi I have a problem with squid refresh_pattern. i used regex on refresh_pattern and every exe file for example cached and then clients can download it with high rate. but when someone download from some

[squid-users] Serious problem with read_timeout

2012-04-03 Thread Jean-Philippe Menil
Hi, i encounter serious outage with squid 3.HEAD-20120307-r12077. Every time i download some test files, it stop after 15 minutes. If i go down read_timeout to 1 minutes, the download stop after 1 minutes. Is it a know issue, or must i increment read_timeout to excessively timeout? special

[squid-users] Can't establish connection by windows-client (repdoc)

2012-04-03 Thread Alexander Busam
Hi! I use squid as a transparent proxy (hostname: hmsmbsrv, ip: 192.168.1.26, 192.168.2.26). The Windows program I use is repdoc. You can download the Smart Client for testing at http://www.repdoc.com/repdocUpdateService/Default.aspx When I start the program the very first time I got

RE: [squid-users] Allowing linked sites - NTLM and un-authenticated users

2012-04-03 Thread Jasper Van Der Westhuizen
-Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: Tuesday, April 03, 2012 8:43 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users On 3/04/2012 6:12 p.m., Jasper Van Der Westhuizen wrote:

Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users

2012-04-03 Thread Amos Jeffries
On 3/04/2012 10:27 p.m., Jasper Van Der Westhuizen wrote: -Original Message- From: Amos Jeffries [mailto:squ...@treenet.co.nz] Sent: Tuesday, April 03, 2012 8:43 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Allowing linked sites - NTLM and un-authenticated users On

Re: [squid-users] ntlm and kerberos

2012-04-03 Thread Amos Jeffries
On 3/04/2012 7:26 p.m., Anders.Larsson wrote: Hi! Im using at the moment ntlm to auth to AD, I got a test server that are using Kerberos.. Now I want to change the prod machine to use Kerberos to.. is there a way to have both auth directives in conf ? Yes. Simply put them both in.

Re: [squid-users] Can't establish connection by windows-client (repdoc)

2012-04-03 Thread Amos Jeffries
On 3/04/2012 10:06 p.m., Alexander Busam wrote: Hi! I use squid as a transparent proxy (hostname: hmsmbsrv, ip: 192.168.1.26, 192.168.2.26). The Windows program I use is repdoc. You can download the Smart Client for testing at http://www.repdoc.com/repdocUpdateService/Default.aspx When I

[squid-users] Can't establish connection by windows-client (repdoc)

2012-04-03 Thread Alexander Busam
Hi! I use squid as a transparent proxy (hostname: hmsmbsrv, ip: 192.168.1.26, 192.168.2.26; squid-version: 3.1.19). The Windows program I use is repdoc. You can download the Smart Client for testing at http://www.repdoc.com/repdocUpdateService/Default.aspx When I start the program the very

RE: [squid-users] https analyze, squid rpc proxy to rpc proxy ii6 exchange2007 with ntlm

2012-04-03 Thread Clem
Hi, My report with windows7 - squid - outlook anywhere with NTLM I have to modify Windows7 local policies for lanmanager to - LM and NTLM only, by default windows7 sends NTLMv2 only, and squid is handled only LM, when I chose NTLM only, that doesn't work either. Plus that, I have to disable

Re: [squid-users] ACL based on XFF

2012-04-03 Thread Sekar Duraisamy
Hi Amos, Thanks for your detailed explanation with config. Now i can see the XFF IP as a source IP in access log and could block the users from this. Thanks a lot. Regards, Sekar On Mon, Apr 2, 2012 at 7:23 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 3/04/2012 1:13 a.m., Sekar

RE: [squid-users] bash/mysql script not working

2012-04-03 Thread Osmany Goderich
Thanx a lot. This is the outcome. Finally it works #/bin/bash while read url do if [ `echo select site from porn where site='$url'|mysql squid -u squid -psquidpass|grep -v site` ] then echo OK else echo ERR fi done But this is really not what I´m looking for. This scrip only compares what´s

[squid-users] RV: bash/mysql script not working

2012-04-03 Thread Osmany Goderich
Hi everyone, Please have a look at this bash/mysql external helper. Can anyone tell me why is it not working? #/bin/bash connect=mysql -h 127.0.0.1 -b squid -u squid -p password -e url=%DST while read $url do if [ $connect select site from porn where site='$url' ] then echo OK else echo ERR fi

[squid-users] http access to non-standard port e.g. 8080

2012-04-03 Thread Jiří Rotter
Hello people, after few hours of searching I forced to ask, because I haven't found answer. Maybe because port 8080 is commonly used for proxy itself. But the problem is simple. Clients behind proxy can't reach any site on non standard port (8080 for example). Everytime browser tell ERROR,

Re: [squid-users] bash/mysql script not working

2012-04-03 Thread Eliezer Croitoru
On 03/04/2012 16:04, Osmany Goderich wrote: Thanx a lot. This is the outcome. Finally it works #/bin/bash while read url do if [ `echo select site from porn where site='$url'|mysql squid -u squid -psquidpass|grep -v site` ] then echo OK else echo ERR fi done you can use another query with

Re: [squid-users] https analyze, squid rpc proxy to rpc proxy ii6 exchange2007 with ntlm

2012-04-03 Thread Amos Jeffries
On 3/04/2012 11:34 p.m., Clem wrote: Hi, My report with windows7 - squid - outlook anywhere with NTLM I have to modify Windows7 local policies for lanmanager to - LM and NTLM only, by default windows7 sends NTLMv2 only, and squid is handled only LM, when I chose NTLM only, that doesn't

Re: [squid-users] http access to non-standard port e.g. 8080

2012-04-03 Thread Amos Jeffries
On 4/04/2012 1:42 a.m., Jiří Rotter wrote: Hello people, after few hours of searching I forced to ask, because I haven't found answer. Maybe because port 8080 is commonly used for proxy itself. But the problem is simple. Clients behind proxy can't reach any site on non standard port (8080

Re: [squid-users] Serious problem with read_timeout

2012-04-03 Thread Jean-Philippe Menil
Le 03/04/2012 11:06, Jean-Philippe Menil a écrit : Hi, i encounter serious outage with squid 3.HEAD-20120307-r12077. Every time i download some test files, it stop after 15 minutes. If i go down read_timeout to 1 minutes, the download stop after 1 minutes. Is it a know issue, or must i

RE: [squid-users] https analyze, squid rpc proxy to rpc proxy ii6 exchange2007 with ntlm

2012-04-03 Thread Clem
-Message d'origine- De : Clem [mailto:clemf...@free.fr] Envoyé : mardi 3 avril 2012 16:54 À : 'Amos Jeffries' Objet : RE: [squid-users] https analyze, squid rpc proxy to rpc proxy ii6 exchange2007 with ntlm Hi Amos, What do you mean by squid is handled only LM ?? Windows7 by default

Re: [squid-users] limiting connections

2012-04-03 Thread Carlos Manuel Trepeu Pupo
On Mon, Apr 2, 2012 at 6:43 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 03.04.2012 02:21, Carlos Manuel Trepeu Pupo wrote: Thanks a looot !! That's what I'm missing, everything work fine now. So this script can use it cause it's already works. Now, I need to know if there is any

Re: [squid-users] Authentication problem

2012-04-03 Thread Mohamed Amine Kadimi
OK, so here's another pseudo code that comes to my mind, this is somehow similar to some commercial products (Ironport, bluecoat): - The user connects to http://www.somesite.com via the proxy - The Proxy redirects to http://authenticationportal/http://www.somesite.com with 302 return code. - User

Re: [squid-users] limiting connections

2012-04-03 Thread Eliezer Croitoru
On 03/04/2012 18:30, Carlos Manuel Trepeu Pupo wrote: On Mon, Apr 2, 2012 at 6:43 PM, Amos Jeffriessqu...@treenet.co.nz wrote: On 03.04.2012 02:21, Carlos Manuel Trepeu Pupo wrote: Thanks a looot !! That's what I'm missing, everything work fine now. So this script can use it cause

Re: [squid-users] limiting connections

2012-04-03 Thread Carlos Manuel Trepeu Pupo
On Tue, Apr 3, 2012 at 4:36 PM, Eliezer Croitoru elie...@ngtech.co.il wrote: On 03/04/2012 18:30, Carlos Manuel Trepeu Pupo wrote: On Mon, Apr 2, 2012 at 6:43 PM, Amos Jeffriessqu...@treenet.co.nz  wrote: On 03.04.2012 02:21, Carlos Manuel Trepeu Pupo wrote: Thanks a looot !!

Re: [squid-users] Serious problem with read_timeout

2012-04-03 Thread Amos Jeffries
On 04.04.2012 02:46, Jean-Philippe Menil wrote: Le 03/04/2012 11:06, Jean-Philippe Menil a écrit : Hi, i encounter serious outage with squid 3.HEAD-20120307-r12077. Every time i download some test files, it stop after 15 minutes. If i go down read_timeout to 1 minutes, the download stop after

Re: [squid-users] limiting connections

2012-04-03 Thread H
Eliezer Croitoru wrote: On 03/04/2012 18:30, Carlos Manuel Trepeu Pupo wrote: On Mon, Apr 2, 2012 at 6:43 PM, Amos Jeffriessqu...@treenet.co.nz wrote: On 03.04.2012 02:21, Carlos Manuel Trepeu Pupo wrote: Thanks a looot !! That's what I'm missing, everything work fine now. So this

[squid-users] Squid and FTP

2012-04-03 Thread Colin Coe
Hi all I'm trying to get our squid proxy server to allow clients to do outbound FTP. The problem is that our corporate proxy uses tcp/8200 for http/https traffic and port 221 for FTP traffic. Tailing the squid logs I see that squid is attempting to send all FTP requests direct instead of going

Re: [squid-users] Delay fetching web pages

2012-04-03 Thread Colin Coe
Hi Amos The problem turned out to be many DNS forwarders being configured and most of them were unreachable. Thanks CC On Sun, Apr 1, 2012 at 10:46 AM, Amos Jeffries squ...@treenet.co.nz wrote: On 28/03/2012 6:41 p.m., Colin Coe wrote: Hi all I'm running squid 3.1.10 on a RHEL6.2 box.  

[squid-users] Execute scripts

2012-04-03 Thread CyberSoul
Hi all, could anyone give any suggestion for this feature: is there any possibility of squid to execute any scripts from it? I need to run any script when acl is triggered. Any ideas? Cheers Cybersoul mailto:cybers...@gmx.com

Re: [squid-users] Execute scripts

2012-04-03 Thread Brett Lymn
On Wed, Apr 04, 2012 at 09:27:21AM +0400, CyberSoul wrote: Hi all, could anyone give any suggestion for this feature: is there any possibility of squid to execute any scripts from it? I need to run any script when acl is triggered. Any ideas? how about external_acl_type?