SSDs are not that good with squid from my experience , I prefer to get
higher RPMs with SAS disks (15k rpm)
On Sun, May 12, 2013 at 2:39 PM, Hussam Al-Tayeb wrote:
> On Sunday 12 May 2013 01:02:19 Ahmad wrote:
>> hi ,
>> i want to ask about ssd hardsik to the squid opersting system
>>
>> does it
Thank you Amos,
They say it is related to SMP configuration. I am facing this problem
with single worker configuration.
I will try to patch provided on bugzilla and feed back to the list.
On Fri, May 3, 2013 at 2:12 PM, Amos Jeffries wrote:
> On 3/05/2013 10:00 p.m., Hasanen AL-Bana wr
Hi,
I started getting this alot with squid 3.3.4 whenever I rebott my
server , to get rid of it , I have to remove the swap files in each
cache_dir :(
2013/05/03 12:44:51| FATAL: pinger: Unable to open any ICMP sockets.
2013/05/03 12:44:51| Store rebuilding is 10.54% complete
2013/05/03 12:44:51|
Thank you , but I already placed new squid.conf , refresh_patterns are
the same from squid 2.7 , but still most of similar objects are not
getting cached !
On Sun, Apr 7, 2013 at 12:00 PM, Squidblacklist
wrote:
> You will not be wise to use a squid.conf from that old squid on a new
> squid proxy,
Hi,
I am using squid 3.2.9 , for some reason it is not caching objects
which used to be cached easily with 2.7 ... anyone else having similar
issue ?
bellow is an example :
The following URL is not getting into my squid cache no matter what I do :(
http://download.macromedia.com/get/flashplayer/c
The following URL is not getting into my squid cache no matter what I do :(
http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_11_plugin.exe
wget -d
http://download.macromedia.com/get/flashplayer/current/licensing/win/install_flash_player_11_plugin.exe
DEBUG
On Sun, Mar 31, 2013 at 3:20 AM, Amos Jeffries wrote:
> On 31/03/2013 9:07 a.m., Hasanen AL-Bana wrote:
>>
>> The above config for cache_dirs is not working probably.
>
>
> You are top-posting.
> . Why?
> .. There is no "above config".
Sorry , it is the new
: 1159378 of 2097152 (55%)
Filesystem Space in use: 121538556/-1957361748 KB (-5%)
Filesystem Inodes in use: 1176103/146243584 (1%)
Flags:
Removal policy: lru
LRU reference age: 0.17 days
On Sat, Mar 30, 2013 at 5:10 PM, Hasanen AL-Bana wrote:
> Thank you Amos for clarifying these issues.
> I wil
, 2013 at 12:57 PM, Amos Jeffries wrote:
> On 30/03/2013 6:33 a.m., Hasanen AL-Bana wrote:
>>
>> Hi,
>>
>> I am running squid 3.2 with an average of 50k req/min. Total received
>> bandwidth is around 200mbit/s.
>> I have problem when my aufs cache_dirs reac
Hi,
All my drives are formatted with ext4 mounted with 'noatime' option.
On Sat, Mar 30, 2013 at 12:26 AM, babajaga wrote:
> First idea ... filesystem flushing buffers.
>
> Which filesystem do you use ?
> Which mount-options ?
>
>
>
> --
> View this message in context:
> http://squid-web-proxy-c
Hi,
I am running squid 3.2 with an average of 50k req/min. Total received
bandwidth is around 200mbit/s.
I have problem when my aufs cache_dirs reaches size above 600GB.
Traffic starts dropping and going up again , happening every 20~30 minutes.
I have more that enough RAM in the system (125GB DDR
gt; On Mar 14, 2013, at 9:23 AM, Hasanen AL-Bana wrote:
>
> > I thought Squid can fetch the original certificate for a website and
> > pass it to the browser instead of the one created by me,
> > Isn't that how dynamic ssl generation should work ?
>
> No, there are t
Hi,
I have successfully installed squid 3.3 compiled with ssl support
Interception SSL traffic is working fine with browsers loaded with my
self created .DER file.
But without it , I keep getting browser warningings , chrome doesn't
work at all with gmail in this case.
My SSL settings are :
alway
set forwarded_for off
On Mon, Apr 30, 2012 at 5:50 PM, Roman Gelfand wrote:
> My squid server is behind NATed firewall. When accessing site
> www.dnsstuff.com, it reports my ip address as local address of the
> client.
>
> For instance,
>
> 1. squid server ip is 192.168.1.10
> 2. client accesing
rewriters.
On Fri, Apr 27, 2012 at 10:04 AM, Eliezer Croitoru wrote:
> On 27/04/2012 09:52, Hasanen AL-Bana wrote:
>>
>> On Fri, Apr 27, 2012 at 7:43 AM, Eliezer Croitoru
>> wrote:
>>>
>>> On 25/04/2012 20:48, Hasanen AL-Bana wrote:
>>>>
>&
On Fri, Apr 27, 2012 at 7:43 AM, Eliezer Croitoru wrote:
> On 25/04/2012 20:48, Hasanen AL-Bana wrote:
>>
>> wouldn't be better if we save the video chunks ? youtube is streaming
>> files with 1.7MB flv chunks, youtube flash player knows how to merge
>> them and
wouldn't be better if we save the video chunks ? youtube is streaming
files with 1.7MB flv chunks, youtube flash player knows how to merge
them and play themso the range start and end will alaways be the
same for the same video as long as user doesn't fast forward it or do
something nasty...eve
2012 03:41, Paolo Malfatti wrote:
>> > Yes, but i saw that the secuence of parameters changes : sometimes "id"
>> > is before "range" and sometimes after.
>> >
>> > -Mensaje original- From: Hasanen AL-Bana
>> > Sent: Monday, Apr
depending on the mirror & your location ,youtube will decide weather
to stream segmented videos for you or not...I have some downlinks
coming from VSAT and the script is working just fine with it, while
some other internet sources are giving me headache with 1.7M video
segments...it is not the scri
which checks
> if you are in a frameset and if not creates one. This of course has
> some subtleties with ajax...
>
> Ed W
>
>
> On 11/10/2011 12:28, Hasanen AL-Bana wrote:
>> I believe yes ! but it will cause lots of troubles with pages like
>> facebook & gmail
I believe yes ! but it will cause lots of troubles with pages like
facebook & gmail
you can redirect all requests to a url_rewriter script.
squid will pass the requested url to the script , then the script must
generate a page with 2 iFrames , first iFrame will hold the Ad, the
second iFrame goes b
Probably you have configured some private IP address behind squid that
looks like a US ip address , this will fix it for you :
forwarded_for off
add it to squid.conf
On Mon, Sep 12, 2011 at 11:37 PM, Piotr Pawlowski
wrote:
>
> Dear Squid users,
>
> I've configured Squid as transparent proxy on my
Jeffries wrote:
> On 03/09/11 07:52, Hasanen AL-Bana wrote:
>>
>> Hi Ricardo,
>> Just wondering if you could solve your problem with squid 2.7st9 and
>> TProxy4 patch from ViSolve...please let us know if there is any
>> progress...I am also stuck with it.
>>
>&
Thank you very much , i will give it a try
On Sun, Sep 4, 2011 at 7:36 AM, Yucong Sun (叶雨飞) wrote:
> I think you need to block Via and "X-Forwarded-For" headers.
>
> On Sat, Sep 3, 2011 at 12:51 PM, Hasanen AL-Bana wrote:
>> Hi,
>>
>> I configured squid 2.
Hi,
I configured squid 2.7 with tproxy patch and it is working as expected
in bridge mode on linux , client IPs are spoofed just fine but
whatismyipaddress.com still reporting my visible_hostname , is there
anyway to make squid stop adding such headers ?
thank you.
It could be possible with squid if you write some external acl helper
script which checks the IP address (or username) and decides when to
allow/deny access.
However, facebook is out of control now since the site switched to
HTTPS for most users ( or is it possible to intercept https traffic in
squ
Hi Ricardo,
Just wondering if you could solve your problem with squid 2.7st9 and
TProxy4 patch from ViSolve...please let us know if there is any
progress...I am also stuck with it.
thank you.
On Sat, Jul 2, 2011 at 1:32 AM, Ricardo Rios wrote:
>
> El 30/06/11 19:37, Ricardo Rios escribió:
>>
>>
it is easy to forward port 80 traffic to Squid using Mikrotik , it can
be done by going to ip->firewall->nat and adding new dst-nat.
Or you can just use your cache server as a gateway for the Mikrotik router.
On Wed, Aug 17, 2011 at 8:16 AM, Benjamin wrote:
>
> Hi ALL,
>
> Currently i have a req
Try Chillispot , although it is old.
On Thu, Jul 21, 2011 at 8:26 PM, Mr Crack wrote:
>
> Dear Friends,
> I would like to know if there is any wifi hotspot solution software in
> Linux ( free or commercial )
> In Windows, that can be done with Antamedia Hotspot software.
>
>
>
> Thanks in advance
e there is no way how to
> prevent them to do so. Last line of "defense" remains DNS which system
> prevents them to change.
>
> This is why I want DNS to filter these sites.
>
> OOOH! Can Squid even be set like DNS server?
>
> ---
> Regards
> Martin Lukeš
No , no need to change DNS entries. You can use url_rewrite_program to
rewrite specific URLs
2011/6/22 Martin Lukeš
>
> Hi all,
>
> I'd like to get answer to my question about Squid before I install it
> on my server.
>
> In case I want Squid to respond to certain requests (based on that
> reques
disable sending SYN_COOKIES in /etc/sysctl.conf
On Mon, Jun 13, 2011 at 2:20 PM, Omid Kosari wrote:
>
> Squid Cache: Version 3.1.12.1
> Linux 2.6.38-8-server #42-Ubuntu SMP Mon Apr 11 03:49:04 UTC 2011 x86_64
> x86_64 x86_64 GNU/Linux
> /proc/sys/net/ipv4/tcp_max_syn_backlog is 65536
> /proc/
I guess you could use wget to do that
export http_proxy=http://localhost:3128 ; wget http://fqdn/object
On Thu, Jun 2, 2011 at 5:20 PM, Luis Daniel Lucio Quiroz
wrote:
>
> just thinking
>
> if squid-purge tool can purge an specific object from cache by modifing the db
> cache db,
>
> is there a
as? Do you need any further clarification?
>
> Amos do you have any suggestion?
>
> Thanks in advance,
>
> GZ
>
> -Original Message-
> From: George N. Zavalis [mailto:gzaba...@dolnet.gr]
> Sent: Tuesday, May 17, 2011 12:33 PM
> To: 'Hasanen AL-Ba
Assuming you are using Linux , first you have to create proper routing
table for both ISPs , linking each IP to its gateway. Once you are
done with that , you can use tcp_outgoing_address in squid to redirect
each subnet is IPs to the proper ISP.
On Wed, Jun 1, 2011 at 10:40 AM, Roland Roland wro
Are you using any sotreurl rewriter ? if you do , then rewritten URLs
will not be found by ICP
On Mon, May 16, 2011 at 8:09 PM, George N. Zavalis wrote:
>
> Hi list,
>
> I have squid Version 2.7.STABLE9 and I tried to setup a multi instance squid
> system as proposed at http://wiki.squid-cache.or
it would be much better if you compile it from source
On Mon, May 16, 2011 at 2:47 PM, Farokh Irani wrote:
>
> Are there updated versions available for ubuntu? I have squid 3.1.6, but it
> appears that there are no newer versions available. Will I have to compile it
> from the source?
>
> Thank
cache_peer 127.0.0.1 parent 3128 3130 default
the above link points to the same server ! probably incorrect , you
must use your parent IP address instead (172.16.101.3)
On Sat, May 14, 2011 at 7:17 PM, Dr. Muhammad Masroor Ali
wrote:
>
> Dear All,
> I thought that this would have been st
Delete your cache directories , it would be better if you keep them on
a separate partition so you can quickly do mkfs.ext3 (or ext4) on that
partition. Deleteing ufs directories could take ages if you have big
tree inside them
On Wed, May 4, 2011 at 10:33 PM, Henry Yuan wrote:
> It seems that th
Yeah but what to do when you have a very loaded squid server with more
than 15000 req/min ...you will notice in /var/log/messages that kernel
is sending syn cookies and slowing down requests coming to port 3128 !
On Sat, Apr 23, 2011 at 7:51 PM, Jim Binder wrote:
> syn cookies are a feature of th
edit /etc/sysctl.conf
change net.ipv4.tcp_syncookies=1 to net.ipv4.tcp_syncookies=0 and
reboot. dont forget to remove the # from the beginning of the line.
On Sat, Apr 23, 2011 at 5:39 PM, Andreas Braathen
wrote:
>
> Squid is sending SYN packets to destination when receiving GET request from
> i
it might worth trying to change few bits in the source code and
implement this feature. I thought about adding 'tos' field to squid
reply_header structure and read this value from source. However ,
squid doesn't deal with packets, it deals with HTTP requests/replies.
in our case ,how do you guarant
It depends on how squid is getting traffic from remote serversif
you are fetching requests from remote cache peer then it is possible
to set the TOS headers depending on the parent/sibling reply.
If you have a parent/sibling proxy configured in your local squid ,
then you can set the parent_hit
1- I think the fastest way to flush all the cache is to stop squid
then making mkfs.extX on your cache partition. I suppose you have a
separate partition for cache.
2- Is it possible ? I dunno
3- check refresh_pattern settings also you can set the minimum expiry time.
On Tue, Apr 19, 2011 at 6:14
you can use cache_peer and connect them as siblings
On Sun, Apr 17, 2011 at 1:10 AM, Bilal J.Mahdi wrote:
>
> Dear All
>
> What's the best way to make 3-local squid box connected to each other, and
> can we use the same transparent port or not ???
>
Hi,
I have squid 2.7STABLE9 running on Ubuntu 10.4 64it server edition.
My cache is distributed between aufs and coss files on two separate disks
I have coss on 250GB SSD running very fast...but from time to time I
face problem with coss unable to read/write to this disk.
Did anyone try to use SSD
Hi Yomi,
ICP & HTCP are protocols used between 2 or more cache servers to
communicate and share their data , if you only have one single cache
server then you don't have to worry about ICP or HTCP.
from you squidclient info I can see some bad things like your cache
miss time :Cache Misse
I had this issue before , doing squid -k reconfigure or reload doesn't
release cache disk. You need to do squid stop/start.
2011/3/13 Víctor José Hernández Gómez :
> Hi all,
>
> I had planned some work on the ext3 partition used for cache data in our
> squid 3.1.11 instalation, which should be uno
It would be much easier if you use a NAS like Mikrotik (RouterOS) and
for more features you can combine it with RADIUS server.
On Fri, Mar 11, 2011 at 4:49 PM, Leonardo Rodrigues
wrote:
> Em 11/03/11 10:28, Helmut Hullen escreveu:
>>
>> Hallo, squid-users,
>>
>> is there a simple ACL for setting
I remember there used to be a python script for doing that , squid
adzapper I think.
You specify one url_rewrite_program , and you can configure that
script to run any number of child scripts , the main scrip will take
care of passing all squid parameters to the child scripts.
On Wed, Mar 2, 2011
Please paste the output of : squidclient mgr:info
You might have ran out of disk space and your squid for some reason is
not purging objects as it should.
On Wed, Mar 2, 2011 at 11:59 AM, Dayo Adewunmi wrote:
> Hi
>
> For about 3 hours now, I haven't had much in the way of cache hits, and the
>
Hi,
If you have different IP ranges on the same machine , then you need to
add 3 gateways using linux ip route , then you can make use of
tcp_outgoing_address.
I have it documented here :
http://www.snono-systems.com/files/squid-multiwan.pdf
On Wed, Feb 23, 2011 at 9:50 AM, Senthilkumar
wrote:
>
http://www.snono-systems.com/files/squid-multiwan.pdf
On Thu, Feb 17, 2011 at 1:25 PM, wrote:
> Good day,
> My special thanks to Amos Jeffries and Hasanen AL-Bana.
> I still need further assistant and clarification on the issues below:
>
> in the sample below which IP address i
On Wed, Feb 16, 2011 at 1:00 PM, wrote:
> Example: Splitting uploads and downloads between two ISP links
>
> acl download method GET HEAD
> acl upload method POST PUT
>
> # IP used by link for downloads
> tcp_outgoing_address 192.0.2.1 download
>
> # IP used by link for uploads
> tcp_outgoing_add
Or you might try using iFrame loading comments from different page.
On Tue, Feb 8, 2011 at 10:09 PM, Andy Nagai wrote:
> Our site consists of mostly articles. Each article has user entered comments
> at the bottom. The comment section cannot be cached. They need to see their
> comments right afte
Sure it does save bandwidth , to know more about your bandwidth saving
you can run : squidclient mgr:info
You will see Byte Hit Ratio which should tell you how much bandwidth
you are saving.
On Sat, Feb 5, 2011 at 12:44 PM, Senthilkumar
wrote:
> Hi,
>
> Current network topology
> Internetsqui
No need for ICAP , storeurl script should be enough.
The problem is that youtube internal links are changing from time to
time, so we need to update our scripts from time to time.
On Wed, Feb 2, 2011 at 8:23 PM, Clemente Aguiar
wrote:
>
> Qua, 2011-02-02 às 10:01 -0600, Luis Daniel Lucio Quiroz e
is it implement it yet in 2.7 ??
Is there any patch for it ? I googled and found nothing , if such
thing really exists it would really boost the service speed for
clients.
On Thu, Jan 27, 2011 at 7:20 PM, Amos Jeffries wrote:
>
> On 28/01/11 01:00, he...@web.de wrote:
>>
>> Hello,
>>
>> is it
True ,most secure sites set their cookies over HTTPS.
On Tue, Jan 18, 2011 at 4:52 PM, Amos Jeffries wrote:
> On 19/01/11 01:44, Alexander Curvers wrote:
>>
>> thanks for your response Amos,
>>
>>
>> 2011/1/18 Amos Jeffries:
>>>
>>> On 18/01/1
don't you have to define ACL first ?
On Tue, Jan 18, 2011 at 1:23 AM, Alexander Curvers wrote:
> Hi i am running Version 2.7.STABLE3 on Debian
>
> im trying to block cookies
>
> ive added these lines to my config (and reloaded)
>
> header_access Cookie deny all
> header_access Set-Cookie deny all
, I have another system (Dell PE R510 4x300GB 15K SAS 24GB
RAM) and it is running just fine with 10 COSS files (50 GB each) and a
bunch of AUFS directories.
On Thu, Jan 13, 2011 at 4:52 PM, Amos Jeffries wrote:
> On 14/01/11 01:38, Hasanen AL-Bana wrote:
>>
>> Hi,
>>
>&g
Hi,
I am getting these every few minutes causing squid process to restart
2011/01/08 17:30:20| assertion failed: coss/store_dir_coss.c:276:
"curstripe == storeCossFilenoToStripe(cs, e->swap_filen)"
2011/01/08 17:36:44| assertion failed: coss/store_dir_coss.c:276:
"curstripe == storeCossFilenoToSt
Hi,
I have been working on some perl scripts doing some storeurl magic ,
but it never worked on one of my squid servers (2.7STABLE9) , then I
noticed the store.log is set to none on that serveronce I enabled
the store.log file everything worked just fine ! is there any relation
between the two
This will cause a bigger problem , if user downloading a file with
download manager ,let's say in 4 segments , squid will start 4
download threads for the same file each one from its beginning. will
consume 4 times bandwidth than really needed.
On Fri, Jan 7, 2011 at 6:49 PM, Amos Jeffries wrote:
is great.
On Fri, Jan 7, 2011 at 9:06 AM, Amos Jeffries wrote:
> On 31/12/10 04:18, Hasanen AL-Bana wrote:
>>
>> Hello everybody,
>> My setup is : Client --> [Squid Cache Server (A
This way you will run out of memory quickly , squid loves RAM... my
server has 32GB of RAM and still I see some page faults from time to
time.
On Sun, Jan 2, 2011 at 3:24 PM, David Touzeau wrote:
>
> Dear
>
> I have a server with 8Gb memory
>
> I would like to know there is any benefits to creat
I suppose your script is working just fine , however it would be
better if you post it here.
If your script have no problem , then I guess your HTTPS requests are
not being forwarded to Squid. like in my case only requests on port 80
(http) are being forwarded. that could be the reason for not gett
Well...that is not the only use for TPROXY ,but mainly it is used to
spoof client's IP address through Squid , and as far as I know that
can be done with TPROXY only by bridging interfaces.
On Fri, Dec 31, 2010 at 12:21 PM, benjamin fernandis
wrote:
> H.
>
> Ok..Let's say suppose i m ISPA
Well , you can't make use of TPROXY from another network , it can be
used only through local bridged network , if you set proxy ip & port
in your browser , you are not using TPROXY anymore , that is why you
see your squid IP address on whatismyip.com
On Fri, Dec 31, 2010 at 11:19 AM, benjamin fern
I believe you need to setup a bridge to see if traffic goes through...
[Clinet]>[ eth1 -- TProxy Bridge-- eth0 ] -> [Gateway]
--Internet > Web server
Your client must be able to reach internet without any special configuration.
The webserver on the internet must log your cli
Hello everybody,
My setup is : Client --> [Squid Cache Server (A)] ---> Internet
|
|--->
[Cache Peer as parent (B)] --> Internet
The first squid server forwards only You
71 matches
Mail list logo