Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-29 Thread Muhammad Yousuf Khan
Thanks, it means i have to shift it back to proxy mode. since i am still using it on testing environment it wouldn't be an hurdle for me. On Wed, Feb 29, 2012 at 9:26 AM, Amos Jeffries squ...@treenet.co.nz wrote: On 29/02/2012 9:27 a.m., Muhammad Yousuf Khan wrote: Thanks, if i use squid as

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-29 Thread Amos Jeffries
On 1/03/2012 12:42 a.m., Muhammad Yousuf Khan wrote: Thanks, it means i have to shift it back to proxy mode. since i am still using it on testing environment it wouldn't be an hurdle for me. back? Squid since version 2.6 have been able to open multiple ports simultaneously. Several traffic

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-29 Thread Muhammad Yousuf Khan
Thanks. that will help. On Wed, Feb 29, 2012 at 5:47 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 1/03/2012 12:42 a.m., Muhammad Yousuf Khan wrote: Thanks, it means i have to shift it back to proxy mode. since i am still using it on testing environment it wouldn't be an hurdle for me.

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-28 Thread Matus UHLAR - fantomas
On 28.02.12 01:24, Muhammad Yousuf Khan wrote: Thank you very much for you help i also thought for the same but it doesn't help me. because i like to block this on certain time window. like it will b allowed only in lunch hours or after COB so this might not work. any suggestion on this

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-28 Thread Muhammad Yousuf Khan
Thanks, if i use squid as non transparent proxy would it work for HTTPS for just blocking a domain. Thanks. On Tue, Feb 28, 2012 at 3:13 PM, Matus UHLAR - fantomas uh...@fantomas.sk wrote: On 28.02.12 01:24, Muhammad Yousuf Khan wrote: Thank you very much for you help i also thought for the

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-28 Thread Amos Jeffries
On 29/02/2012 9:27 a.m., Muhammad Yousuf Khan wrote: Thanks, if i use squid as non transparent proxy would it work for HTTPS for just blocking a domain. Yes. HTTPS tunnel CONNECT requests have a special type of URL, which only contains deatinstion domain name and port. You can use the

[squid-users] https facebook dstdomain acl doesn't work

2012-02-27 Thread Muhammad Yousuf Khan
acl testdomain dstdomain .facebook.com http_access deny testdomain above is my acl how ever http works fine it blocked now when i go to https facebook it just allow it. how can i stop this. kindly help Thank you. MYK

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-27 Thread Naira Kaieski
Hi, I can block https access on firewall. Try it: IPTABLES=`which iptables` $IPTABLES -A FORWARD -d 66.220.149.0/24 -p tcp -j DROP # facebook $IPTABLES -A FORWARD -d 69.63.190.0/24 -p tcp -j DROP # facebook $IPTABLES -A FORWARD -d 69.171.224.0/24 -p tcp -j DROP # facebook $IPTABLES -A FORWARD

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-27 Thread Muhammad Yousuf Khan
Thank you very much for you help i also thought for the same but it doesn't help me. because i like to block this on certain time window. like it will b allowed only in lunch hours or after COB so this might not work. any suggestion on this scenario. Thanks, On Mon, Feb 27, 2012 at 8:45 PM,

Re: [squid-users] https facebook dstdomain acl doesn't work

2012-02-27 Thread James Robertson
Thank you very much for you help i also thought for the same but it doesn't help me. because i like to block this on certain time window. like it will b allowed only in lunch hours or after COB so this might not work. any suggestion on this scenario. I was interested in this thread as I had