[squid-users] Cache performance

2010-12-17 Thread benjamin fernandis
Dear Friends, I m going to use squid for cache purpose only.And i heard that for squid cache performance i have to use good RAM and HDD.I have 4gb RAM and 160 GB SATA HDD.And i have 200 users' network.So please suggest me the same.Means can i go with this H/W specification or is there any

[squid-users] Delay pool question

2010-12-17 Thread Nick Cairncross
Hi List, A quick Delay Pool question..and a favour.. Currently using basic Delay Pool configuration for users: delay_class 1 4 delay_parameters 1 -1/-1 -1/-1 -1/-1 200/200 delay_access 1 allow !SERVERSUBNETS AuthenticatedUsers delay_access 1 deny all Users authenticate via Kerberos,

Re: [squid-users] Re: Can squid be configured as SMTP/SMTPS proxy?

2010-12-17 Thread Amos Jeffries
On 17/12/10 20:11, Manuel wrote: Hello, How common is for the client app to work with SMTPS proxies? I have a vBulletin forum in a backend that I want it to send e-mails to the users through a SMTP server in a different server. vBulletin app works fin with SMTP servers through TLS and SSL but

Re: [squid-users] Delay pool question

2010-12-17 Thread Amos Jeffries
On 17/12/10 23:23, Nick Cairncross wrote: Hi List, A quick Delay Pool question..and a favour.. Currently using basic Delay Pool configuration for users: delay_class 1 4 delay_parameters 1 -1/-1 -1/-1 -1/-1 200/200 Careful with those big numbers. They are in *bytes* and only the

RE: [squid-users] ssl-bump pause for 2 minutes for certain sites

2010-12-17 Thread Ming Fu
Hi Amos, The pause happens when ICAP sends about 90% of the payload. The Content-Length header shown the exact size as 106900. I believe by the time squid starts to send the RESPMOD payload, all the DNS should already finished. If you look at the tcpdump on port 443, it pauses for 2 minutes

Re: [squid-users] Cache performance

2010-12-17 Thread Marcello Romani
Il 17/12/2010 11:09, benjamin fernandis ha scritto: Dear Friends, I m going to use squid for cache purpose only.And i heard that for squid cache performance i have to use good RAM and HDD.I have 4gb RAM and 160 GB SATA HDD.And i have 200 users' network.So please suggest me the same.Means can i

Re: [squid-users] Cache performance

2010-12-17 Thread Chad Naugle
I would also highly recommend using at least a Dual Core CPU, 1.6GHz + for 200 users. CPU performance is also a very important factor for user volume. - Chad E. Naugle Tech Support II, x. 7981 Travel Impressions, Ltd. Marcello Romani

Re: [squid-users] maxconn

2010-12-17 Thread Jason Greene
On Thu, Dec 16, 2010 at 7:41 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 17/12/10 10:38, Jason Greene wrote: I m trying to close a security hole I want to use maxconn on ALL IPs acl limitusercon maxconn 3 http_access deny all limitusercon Testing the all there is not useful. That

RE: [squid-users] Cache performance

2010-12-17 Thread Chad Naugle
True, but I recommend it, especially for the OS processing the disk I/O, and authenticators, etc, but it's not really a requirement. - Chad E. Naugle Tech Support II, x. 7981 Travel Impressions, Ltd. Bradley, Stephen W. Mr. bradl...@muohio.edu

Re: [squid-users] maxconn

2010-12-17 Thread Jason Greene
It doesn't make sense... I set the limit to 50 and I run my scan and the vulnerability shows... I drop it back by 5 and run my scan... it show until I get to 20...the vulnerability goes away I increase the limit by 1 until I get to 25 where it shows back up... I drop back down to 24 ... still

Re: [squid-users] maxconn

2010-12-17 Thread Amos Jeffries
On 18/12/10 04:35, Jason Greene wrote: On Thu, Dec 16, 2010 at 7:41 PM, Amos Jeffriessqu...@treenet.co.nz wrote: On 17/12/10 10:38, Jason Greene wrote: I m trying to close a security hole I want to use maxconn on ALL IPs acl limitusercon maxconn 3 http_access deny all limitusercon

[squid-users] Re: Can squid be configured as SMTP/SMTPS proxy?

2010-12-17 Thread Manuel
I am not sure if I understood what is not capable of Squid. You mean that use Squid to hide the client IP sender is not possible? This is the goal, the first message at serverfault is mine: http://serverfault.com/questions/212333/how-to-hide-the-client-ip-sender-and-show-only-the-smtp-server-ip