Re: [squid-users] Use squid to switch to Tor network

2012-02-22 Thread Nguyen Hai Nam
Hi, The scenario is: [intercept] squid will forward traffic to Privoxy by cache_peer directive. But I only want forward some *specific* routing to Privoxy to the unreachable path, the remain Internet traffic is as usual. Can it? Thanks. On 2/15/2012 7:26 PM, Amos Jeffries wrote: The key

[squid-users] Use squid to switch to Tor network

2012-02-14 Thread Nguyen Hai Nam
Hi Squid guys, We're using Squid 3.2 on Solaris 11 system smoothly, but few days ago our ISP has had troubles with external Internet routing so we can't reach many websites. I discovered that if I use Tor's browser I can open that websites normally (yes, it's slow btw), at least we can open

[squid-users] Host header forgery detected when googling

2012-01-09 Thread Nguyen Hai Nam
Hi, I got many security alerts from Squid that told Host header forgery detected, part of the log file is here: https://pastee.org/7vqst This error happens when users: 1. open google.com on browser and was redirected to local google.com.vn 2. open result links when googling 3. open

[squid-users] Compiler stopped when building Intercept Squid 3.2.0.14 daily release

2011-12-23 Thread Nguyen Hai Nam
Hi Amos, It's close to holiday but, hope you could know this: http://bugs.squid-cache.org/show_bug.cgi?id=3461 And Merry Christmas to every Squid users! Best regards, ~ Neddie

[squid-users] fatal error in Squid 3.2.0.14

2011-12-22 Thread Nguyen Hai Nam
Hi, Today I've got this message from Squid: You've encountered a fatal error in the Squid Cache version 3.2.0.14. If a core file was created (possibly in the swap directory), please execute 'gdb squid core' or 'dbx squid core', then type 'where', and report the trace back to

[squid-users] Squid 3.2.0.14 didn't work in interception mode

2011-12-20 Thread Nguyen Hai Nam
Hi there, I'm building new squid box which is 3.2.0.14 on OpenIndiana 151a, the configuration is as usual but when squid started up, intercept mode didn't work. IP NAT table already works: # ipnat -l List of active MAP/Redirect filters: rdr rtls0 0.0.0.0/0 port 80 - 10.2.176.31 port 3129

Re: [squid-users] Squid 3.2.0.14 didn't work in interception mode

2011-12-20 Thread Nguyen Hai Nam
On 12/20/2011 7:06 PM, Amos Jeffries wrote: On 21/12/2011 12:33 a.m., Nguyen Hai Nam wrote: Hi there, I'm building new squid box which is 3.2.0.14 on OpenIndiana 151a, the configuration is as usual but when squid started up, intercept mode didn't work. IP NAT table already works: # ipnat

[squid-users] Squid 3.2 overload

2011-12-14 Thread Nguyen Hai Nam
Hi, I've deployed a squid box 3.2.0.13 for one branch office, there are 10 users there. It's a small office then I think to use an old computer Pentium 4 2.4Ghz is enough; and the configuration is intercepting squid proxy. The current issue in there is: when someone open a few websites that

[squid-users] Re: Squid 3.2 overload

2011-12-14 Thread Nguyen Hai Nam
Hi Amos, I'll try 3.2.0.14 soon. Thanks On 12/15/11, Amos Jeffries squ...@treenet.co.nz wrote: On 15/12/2011 6:55 p.m., Nguyen Hai Nam wrote: Hi, I've deployed a squid box 3.2.0.13 for one branch office, there are 10 users there. It's a small office then I think to use an old computer

Re: [squid-users] Squid 3.2.0.13 daily release

2011-12-07 Thread Nguyen Hai Nam
On 12/7/2011 4:13 AM, Amos Jeffries wrote: cc'd to squid-dev so the developers can see this info. On Tue, 06 Dec 2011 16:43:38 +0700, Nguyen Hai Nam wrote: Hi, I've installed Squid 3.2.0.13 as an intercepting proxy server. Today I tried to build latest version 3.2.0.13 20111205, the problem

[squid-users] Squid 3.2.0.13 daily release

2011-12-06 Thread Nguyen Hai Nam
Hi, I've installed Squid 3.2.0.13 as an intercepting proxy server. Today I tried to build latest version 3.2.0.13 20111205, the problem is sometimes I suffer lost connection when downloading, eg. it freezes at xx% and I have to pause and start to continue, When open some websites, it's

Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Nguyen Hai Nam
of the set-up below (with the Squid box the same as the Gateway) Internet Router       Eth0 |- Squid box Default Gateway -| Eth1   Switch       LAN # Edz. On Mon, Dec 5, 2011 at 5:14 PM, Nguyen Hai Nam nam...@nd24.net wrote: Hi Amos, You're right, switch is not really true. But I still

Re: [squid-users] Make Squid in interception mode completely

2011-12-06 Thread Nguyen Hai Nam
diagram or illustration shows a difference with my illustration. If you believe they are the same and getting header fields shown, look through your firewall and squid acls. # Edz. On Tue, Dec 6, 2011 at 5:05 PM, Nguyen Hai Nam nam...@nd24.net wrote: Hi Edmonds, That's really like my setup

Re: [squid-users] Make Squid in interception mode completely

2011-12-05 Thread Nguyen Hai Nam
Hi Amos, You're right, switch is not really true. But I still can't find the way on Solaris-like system like /proc/sys/net/bridge On Mon, Dec 5, 2011 at 7:25 PM, Amos Jeffries squ...@treenet.co.nz wrote: Like a switch? or or did you really mean like a bridge? * switch ... no solution.

[squid-users] Make Squid in interception mode completely

2011-12-04 Thread Nguyen Hai Nam
Hi, As last time I had a squid box working in interception mode as well: traffic was redirected from default gateway to squid box, then IP-filter will NAT to intercepting squid. Look like this: INTERNET Router | | SwitchDefault gateway | \ | \ |+ Squid box |

[squid-users] Problem with Varnish and intercept Squid

2011-12-03 Thread Nguyen Hai Nam
Hi, Now, I'd like to have additional Varnish as a cache agent in front of intercept Squid 3.2 (built successfully before). Varnish was built with default setting and start up script: # ./varnishd -a 0.0.0.0:8080 -b 0.0.0.0:3129 -s malloc,512M Varnish will listen at tcp port 8080 first, if

Re: [squid-users] Can't make Squid 3.2 work as Interception proxy

2011-12-01 Thread Nguyen Hai Nam
On 12/1/2011 5:55 AM, Amos Jeffries wrote: Yes that is packets successfully arriving at squid and HTT request being processed fine. The intercept flag tells squid to accept origin server formatted (partial) URLs. Its absence tells Squid to accept proxy formatted (absolute) URLs. The

[squid-users] Can't make Squid 3.2 work as Interception proxy

2011-11-30 Thread Nguyen Hai Nam
Hi, I've just installed Squid 3.2 on OpenIndiana 151a server. I have to build squid 3.2 because I can't build squid 3.1. I decide to install transparent/interception proxy: # ./configure --prefix=/usr/squid --enable-ipf-transparent # make # make install Modify in squid.conf with these

Re: [squid-users] Can't make Squid 3.2 work as Interception proxy

2011-11-30 Thread Nguyen Hai Nam
On Wed, Nov 30, 2011 at 7:38 PM, Amos Jeffries squ...@treenet.co.nz wrote: NP: the whole NAT system underwent an upgrade in 3.1. Portions of it have not had much testing yet because nobody with non-Linux seems interested or able to assist with the deep investigations needed. For starters, I