y. I'm using LRU.
'heap lru' is faster.
> Shouldn't squid be cycling out older data rather than the fresh files it
> just pulled in assuming they meet the minimum and maximum size for caching?
Yes, it should...
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.
> tor 2007-04-19 klockan 14:30 +0200 skrev Matus UHLAR - fantomas:
>
> > Are there any protocols that natively support proxies? I can't find any now.
> > If there are, they should/could support proxy authentication too.
On 21.04.07 16:26, Henrik Nordstrom wrote:
> Ther
t won't
> be a problem with 4GB RAM to play with? Or should I reduce the amount
> cached on each drive?
if the clean size of disks/arrays is 69881KiB, I'd use ~55MiB for aufs.
Note that filesystems have usually bad performance if they are filled up too
much.
--
Matus UHLAR - fanto
...
Or am I wrong and can I do this somehow?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
It's now safe to throw off your computer.
okieBlockSite dstdom_regex msn\.
> acl cookieBlockSite dstdom_regex aol\.
> ..
> ..
> ..
>
> Or is it more preferable dump the above into an external file:
>
> acl cookieBlockSite dstdom_regex "/etc/squid/cookie-blocked.acl"
are you sure they have to be regexes?
On 18.04.07 09:35, Edjé wrote:
> What're other procols than http which support authentication whith squid?
Are there any protocols that natively support proxies? I can't find any now.
If there are, they should/could support proxy authentication too.
--
Matus UHLAR - fantomas, [EM
n expert eye to them? Also, since software updates
> dont work, is there a way I can make squid not try to cache them?
> Perhaps Always_direct?
always_direct does not talk about caching, it controls the proxy hierarchy.
use no_cache (renamed to cache in 2.6) to (dis)allow cachin
On 02.04.07 10:30, RdBSD wrote:
> can i divide request like forward 25% of the requests to one parent and
> 75% to another ? what version do i have to use
have you ever read comments in squid.conf?
look at weight option in cache_peer section.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED]
etching html body until i change that
> code and add custom html code to it.
You can use redirector or ICAP for this.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem
and routing is set up proper Squid will be
> happy.
maybe he just needs to set up routing and/or add new IP range to squid ACL's
to allow access.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Va
> On 21.03.07 18:53, Chris Rosset wrote:
> > From: Chris Rosset <[EMAIL PROTECTED]>
> > Date: Wed, 21 Mar 2007 18:53:42 -0400
> > Subject: Re: [squid-users] Squid high CPU usage issue
> > To: Matus UHLAR - fantomas <[EMAIL PROTECTED]>, squid-users@squid-cac
On 21.03.07 18:53, Chris Rosset wrote:
> From: Chris Rosset <[EMAIL PROTECTED]>
> Date: Wed, 21 Mar 2007 18:53:42 -0400
> Subject: Re: [squid-users] Squid high CPU usage issue
> To: Matus UHLAR - fantomas <[EMAIL PROTECTED]>, squid-users@squid-cache.org
>
>
>
'frox' - an intercepting FTP proxy which can be configured to
use squid.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Microsoft
piece of information anymore. Thanks in advance.
Never heard about that. DNS server could do that but I think it's not
important, see above.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na
1GB of
reserved area) vs. 5.5GB when it's 64 bit (6gb of RAM minus some OS usage).
since the 72/104, it's 44739242 vs. 56784423 objects metadata.
> That's not good.
what? that 64bit squid has bigger memory usage? It's the price of higher
limits.
--
Matus UHLAR - fantomas,
in the machine and what's the architecture?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
2B|!2B, that's a question!
amp;bk=117381
hell, do you intercept https connections?
> Other "https" websites work fine with squid, for example I can log in to
> banking and other webmail sites like gmail.
>
> I am routing to squid from the firewall like this:
> iptables -t nat -A PREROUTING -i et
lain.
what if you configure the proxy in browsers?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
42.7 percent of all statistics are made up on the spot.
escribing that squid is NOT pop3/imap/smtp proxy there.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
- Holmes, what kind of school did you study to be a detective?
- Elementary, Watson.
you won't be able to do DNS resolution.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
One OS to rule them all, One OS to find the
are not send to proxies, but to DNS servers.
But why do you found this a problem?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Nothing is fool-proof to a talented fool.
e not using useless
regular expressions for ACLs. Then, try applications like squidguard for
ACLs.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Honk if you love peace and quiet.
On 22.02.07 15:51, Matt wrote:
> Is there a way to get Squid to display normal date/time in access.log?
use custom log format - directive "logformat"
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to
ventually? In some FAQ I read that sibling caches should not be located
> towards the route to the internet, so that is why I am asking.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto ad
find anything stating this to be true.
yes.
> Also, should the acl use a -i in the regex line to do a case-insensitive
> match meaning I want to match any combination of BadDomaN.COM.
yes.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receiv
ack-end server at some later time.
this can be done by some external job running out of squid (e.g. cron)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek r
h_basic.c file of sources, But how can I
> obtain the char * with IP adres for send it? I think it could be in
> auth_user_request_t struct of authenticateBasicStart
> function, but where? and how convert it to char*)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.
27;t know what name to store file under.
However, it's often a problem of web developera who don't know this and
don't (properly) set up this header...
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to thi
rivate copy of
their reply.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Despite the cost of living, have you noticed how popular it remains?
x27;m guessing it is something to do with my configuration..
>
> Can anybody help me? (Oh for info, I'm using the WinNT version 2.6Stable)
use real content filter, not such simple rules that can be easily avoided.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
lication server to know the "original" URL.
Why do you rewrite URL's then?
> I though about adding a new header field in the proxy request, like
> "X-Rewritten-From: /abc/1234"... Can I do this? How? Or any other
> solutions for this use case?
maybe ICAP w
e to have, to be able to put larger objects in
> > a separate space. Thanks. :)
On 04.02.07 13:57, Adrian Chadd wrote:
> You already can, to some extent. See the cache_dir configuration
> information; there's a "max object" size parameter. cache_dirs are checked
> in
On 22.01.07 11:48, Brian Bepristis wrote:
> Is there a way I can require authentication on all ports except 443 I
yes, but why?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adr
ssages? Most of MTAs (including yours it seems) only know Re: as reply
prefix, so the AW: are being repeated...
thank you
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAV
pamAssassin 3.1.4 (2006-07-26) on
> fantomas.fantomas.sk
>
> What the actual status on IPv6 support for Squid ?
>
> thanks
Hello,
please, If you are writing a new post, send it as new mail and not
as reply/followup on old mail. It makes problems in threading clients.
Thank y
ot; section in squid.conf. You can get it via http environment
> variable,for CGI,it's "$ENV{'HTTP_X_FORWARDED_FOR'}".
$_SERVER['HTTP_X_FORWARDED_FOR'] should work in php (too?).
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning:
ient IP in the X-Forwarded-For header,
> available to PHP and other scripting languages.
unless you have 'forwarded_for off' directive in your config file, or deny
forwarded_for via 'header_access' directive.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.f
ettings, but are configured normally.
However, this has nothing to do with squid (and squid has nothing to do with
e-mail, so it even belongs here ;)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varova
ors in the cache.log that
> i want to get rid of/understand.
are ALL access rights of /cache/cache/01/C9/0001C926 and
/cache/cache/01/C9 correct?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
The 3 biggets disasters: Hiroshima 45, Tschernobyl 86, Windows 95
led properly.
>
> http://wiki.squid-cache.org/SquidFaq/InstallingSquid#head-ace04b18aa4598683afdce8360108bcdd93a7943
probably not setuid root
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na
ections to proxy?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Enter any 12-digit prime number to continue.
ilable bandwidth is all used up (i.e.
> > the default condition for any WAN link).
> [...]
>
> I've added Henrik's explanation to the Wikified FAQ
> http://wiki.squid-cache.org/SquidFaq
Where exactly? And what about
http://en.wikipedia.org/wiki/Explicit_Congestion_Notification
server 2 has 1 processor. Can this error be caused due
> to high load???
I have squid-2.6 on FreeBSD-4.11 and I have no ptoblems with it.
Which sub-version of squid, FreeBSD and what cache_dir types do you use?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning
he parent proxy may go direct in such cases.
However, I prefer things like ICAP for content filtering, not another proxy
server (the same way I prefer milter/amavis plugins over extra SMTP daemon
when filtering spam/virus content)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantoma
there something in the way this URL is written that sends this
> request out DIRECT instead of through the parent (DG) proxy?
you probably have uncommented the following line (as it is in default
squid.conf):
hierarchy_stoplist cgi-bin ?
which causes all requests containing "?" (as the
squid unless that server
is very slow from some reason
On 23.11.06 10:57, Wojciech Puchar wrote:
> yes, it must be compiled with large file option
largefiles are needed only for files >=2GiB
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to
to allow conneting to pop3
port in such case.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Fucking windows! Bring Bill Gates! (Southpark the movie)
On 14.11.06 01:42, zulkarnain wrote:
> Briefly speaking, even my machine equipped with 8 GB
> of RAM, as long as I'm using 32 bits OS, squid process
> only able to use 3 GB or RAM and other system process
> will get 5 GB?
not exactly - other system process may only get 3GB too ;-
sweitching to 64bit
mode, contrary to AMDs which speed up in such case...
You can use 8GB of RAM in 32-bit mode too, but you need to have kernel with
PAE support. And, squid will be limited to 1 to 3 GB of RAM (depends on the
kernel setup)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.
queues and shared memory:
if you have FreeBSD5 or higher, you can use aufs, which should be faster and
doesn't require SHM tuning.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto a
any other access rules?
Note that http://www.cnn.com/test.avi? will be allowed too, you should use
some better filtering system...
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem N
On 06.11.06 19:08, Henrik Nordstrom wrote:
> m??n 2006-11-06 klockan 17:27 +0100 skrev Matus UHLAR - fantomas:
>
> > I'm not sure I understand:
> > so those two are AND-ed and their combination will be applied?
>
> The squid.conf setting is a safeguard in case Squid
On 06.11.06 17:10, Henrik Nordstrom wrote:
> m??n 2006-11-06 klockan 14:53 +0100 skrev Matus UHLAR - fantomas:
>
> > I installed squid-2.6 stable 3 on FreeBSD 4.11 and set umask to 027.
> > However, new files in spool have mode 0600, so I'd like to know whether it'
u
doing that.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Christian Science Programming: "Let God Debug It!".
Hello,
I installed squid-2.6 stable 3 on FreeBSD 4.11 and set umask to 027.
However, new files in spool have mode 0600, so I'd like to know whether it's
bug of squid, squid on FreeBSD, or it is meant this way (as long as
directive umask is describes to set minimum umask...)
--
M
gh percent of configured disk space, squid will
start removing objects according to replacement_policy.
Users shouldn't notice unless your disks are too slow, which shouldn't be
the case for you.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wi
ave to use squidguard just because
of this problem, however using it is more efficient in some cases.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek rekl
> is a white box server on a 7200 RPM IDE disk serving ~300 users.
see FAQ on squid performance tuning.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolv
thenticate" IP's.
> Can I authenticate only some kind of users or IPs?
yes, with access lists set up properly.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NED
Hello,
On 01.11.06 13:40, Marek Dvornik wrote:
> the ClamAV does'n recognize virus Exploit-IEPageSpoof on following sites:
>
> My SquidClamAV_Redirector.conf:
note that this is squid mailing list, neither ClamAV nor SquidClamAV. They
are all different products.
--
Matus UH
TON wrote:
> I use Dansguardian - http://www.dansguardian.org
DansGuardian seems to support antivirus functionality and ICAP since 2.9.8
However I personally would prefer something with ICAP support, e.g. c-icap
(note that I'm not original poster)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED
er. I don't think that could be the reason, but... Anyone has had
> the same behavior?
What does this have in common with the cache hierarchy problem you are
replying to?
please, If you are writing a new post, send it as new mail and not
as reply/followup on old mail. It makes problems in
> m??n 2006-10-30 klockan 09:35 +0100 skrev Matus UHLAR - fantomas:
>
> > I doubt cache hierarchy will help you in case of accelerator setup, unless
> > you have too much of data on webservers and too few space on proxies.
> > However using hierarchy could slow up data
vers? do you understand that squid is only HTTP proxy and
mailserver need other protocols to work?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek re
few space on proxies.
However using hierarchy could slow up data retrieving in this case.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
T
nel. Read their
documentation and decide which do you want...
I may tell you that old LRU performs worse than the others, even heap LRU...
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adr
ould have turned
on support for up to 4GB of RAM in linux.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
"They say when you play
Hello,
after upgrading to squid-2.6stable3 the comm_incoming stats from cachemgr
output seems to be missing. Was that removed or is that a bug?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na
Hello,
which version of squid is old for using htcp-oldsquid option?
I wasn't able to find this informations, it should be imho provided in
default config.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this ad
Hello,
I have small farm of 3 neighbouring servers. I am just planning to upgrade.
Some time ago it was mentioned that using HTCP instead of ICP only increases
amount of data transferred, no benefits will be taken from using HTCP over
ICP.
Is this still true with squid-2.6?
--
Matus UHLAR
d by other
proxies and fetch them to other proxies. Note that it will increase the load
on proxies very much.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT ak
ntensive, so it should be avoided
as much as possible.
Even now, it's possible to download through your proxy by using urls like
http://bad.site.com/exefiles/www.example.com/virus.exe
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail
the unsubscribe
confirmation request as spam. I don't know the solution, but it shouldn't be
hard to google for it (I'm not sure if MSN search would work, maybe it eats
pages blaming hotmail :-)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NO
e proxy)
>
> so i think that isn't working.
However, the query string must be the same to cache it, you have query
strings stripped off probably (it's also default)
At last, query result must be cacheable (search for cacheability of
http://www.unav.es/adi/servlet/Web?... , there
On 19.09.06 12:30, Michał Margula wrote:
> Matus UHLAR - fantomas wrote:
> >I would use the 4), decrease cache_disk for both disks and create ~1GB file
> >for COSS on both disks.
> >
>
> Can you explain why? I am not saying you're wrong, but I want to
> underst
7;re interested
> in trying COSS out please grab the latest Squid-2.6 snapshot from
> the website.
are you speaking about current release (STABLE3) or about stable squid in
general?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-
> 4) /dev/sdc and /dev/sdd splitted for COSS and AUFS
>
> I thought that (1) would be OK. What do you think? What is recommended
> size of COSS file?
I would use the 4), decrease cache_disk for both disks and create ~1GB file
for COSS on both disks.
--
Matus UHLAR - fantomas, [EMAIL
r LFUDA policies help improve hit/byte ratios. But you needed
enough of disk space to cache.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu
full and can that have any impact. I
> am just thinking out loud ... will try some more tests ...
try using heap replacement policy. I use heap ldufa for disk, even heap LRU
is faster than old non-heap lru.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wi
ng and recompiling SQUID for this number
> of users.
you may optimize your kernel for that CPU, board, etc, however GENERIC
kernel might work.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varova
low :(
this has nothing to do with those messages. Just someone is still trying to
access http://.update.toolbar.yahoo.com/... maybe broken link somewhere.
for web access check CPU, memory, disk usage, check FAQ for performance
tuning.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.
xe file or a
> CGI running on the server it's not very easy, but to start with
> whitelisting /cgi-bin/ from the .exe block is perhaps a good idea.
Isn't this (blocking files by extension) still in the FAQ?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
War
where you can define this (bind, dnsmasq...)
locally
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
The early bird may get the worm, but
it. There is plenty of memory on the machine. It doesn't run
> any other services.
>
> So which one should i use?
Do you care about speed or the load average? Is the number more important
than performance?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warnin
e of it bad history
(unrecoverable after crash). I will use xfs probably.
> A fast hard disk and avoiding redundancy on RAIDs like RAID-1 will probably
> help.
since as RAID1 is faster when reading the data, using RAID1 might help, if
you have good setup and efficiency.
--
Matus UHLAR
ownload more than 10-MB it;'s
> simply means whole subnet is got blocked.
3. regex "172.16.18.X" matches 172.16.18.XX, 172.16.18.XXX and even
172.16.18.XYZ. using regexp's is also very ineffective. However
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk
memory 4096 KB
and why do you save up to 4MB objects in the memory?
> cache_dir aufs /var/spool/squid 9900 64 256
where's the second cache_dir you've mentioned?
what's usage of /var/spool/squid now?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
f
you probably have the hierarchy_stoplist configured to default "cgi_bin ?"
> Ok I got it to pass the query string using the 'strip_query_terms off'
> directive, but still getting misses on the files
strip_query_terms only affecte logging.
--
Matus UHLAR - fantomas, [EMAIL PR
e server return Expires: headers on those objects?
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
WinError #98652: Operation completed successfully.
m perhaps mistaken in assuming that
> Squid is the "parent" in this relationship. The error page follows.
you specify ICP port of a neighbour proxy server, only if you specify HTTP
port of THE SAME NEIGHBOUR proxy server. use 0 better.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED]
squid.
yes, you just have to properly setup ACL's not to make it open proxy.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
(R)etry, (A)bort, (C)ancer
t;
> >> This normally happens when people allow their systems
> >> to login to ym automatically. They forget this and try
> >> to login to ym on some other system.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
2B|!2B, that's a question!
change their headers
> but their content is dynamically generated and therefore they can't
> generate the content-lenght so they want to leave it off completely.
no problem. If the server supports chunked encoding, nothing bad should
happen.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; ht
king off a minimally modified
> default configuration. Current test browser is IE.
miss_access ? Didn't you redefine "all"? What exactly do you try to access?
(paste relevant line from logfile here)
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I w
ase don't mix threads, and when you want to ask new question,
send a new post.
> - Original Message -
> From: "Matus UHLAR - fantomas" <[EMAIL PROTECTED]>
> To:
> Sent: Wednesday, August 09, 2006 9:14 AM
> Subject: Re: [squid-users] squid use entire dis
illed to ~86% which is OK, when I tried
to use them a bit more, the performance degraded.
I would try "cache_dir /path/ 5000" on that 5GB drive. If it would be to
slow, I'd degrade it to 4500 to see if it helps.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk
gt; 0 KB Page faults with physical i/o: 0
>
> The swap.state is not in the new directory, I never had this issue
> before, any ideas?
does squid run under "squid" user? doesn't redhat use user like 'proxy' for
running squid under? what user/group/perm do your
nts gives you ability to
better control who accesses it, e.g. using ident lookups, see their IP
addresses/DNS names, HW addresses or using things like ntlm authentication.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this addr
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Atheism is a non-prophet organization.
knows that after if downloads the file (at
least its headers)
If you want your users deny certain kind of files, you must use real content
filter.
--
Matus UHLAR - fantomas, [EMAIL PROTECTED] ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na
501 - 600 of 1141 matches
Mail list logo