Re: [squid-users] www.domain.qc.ca is ok BUT domain.qc.ca is denied.

2015-10-16 Thread Ron Wheeler

Have you looked in the web server logs?
What happens when Squid is not used?

Ron
On 16/10/2015 10:00 AM, sebastien.boulia...@cpu.ca wrote:


Hi,

When I try to access www.domain.qc.ca <http://www.domain.qc.ca> it 
works perfectly BUT when I try domain.domain.qc.ca, it fails.


1445003869.430  4 65.94.187.169 TCP_MISS/200 9269 GET 
http://www.domain.qc.ca/ - FIRSTUP_PARENT/xx.xx.xx.xx text/html


1445003436.890  0 m.y.i.p TCP_DENIED/403 4096 GET 
http://domain.qc.ca/ - HIER_NONE/- text/html


1445003437.316  0 m.y.i.p TCP_DENIED/403 3876 GET 
http://domain.qc.ca/favicon.ico - HIER_NONE/- text/html


1445003437.857  0 m.y.i.p TCP_DENIED/403 4096 GET 
http://domain.qc.ca/ - HIER_NONE/- text/html


1445003438.269  0 m.y.i.p TCP_DENIED/403 3876 GET 
http://domain.qc.ca/favicon.ico - HIER_NONE/- text/html


My config is

http_port xxx.xx.xx.xx:80 accel defaultsite=domainweb1 name=incoming80

acl www80 myportname incoming80

cache_peer www.domain.qc.ca parent 80 0 no-query originserver 
name=domainwebwww


acl domainwebacl dstdomain www. domain.qc.ca

http_access allow www80 domainwebacl

cache_peer_access domainwebwww allow www80 domainwebacl

cache_peer_access domainwebwww deny all

Anyone have an idea ?

Is it a web server side issue or a Squid issue ?

Thanks you very much!

Sébastien



___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users



--
Ron Wheeler
President
Artifact Software Inc
email: rwhee...@artifact-software.com
skype: ronaldmwheeler
phone: 866-970-2435, ext 102

___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] squid and post method

2015-02-28 Thread Ron Wheeler
To get any useful input, you probably need to describe how you are using 
squid.

What is the origin and destination of the POST requests?
What do you want to know about the request?

Ron

On 28/02/2015 7:07 PM, HackXBack wrote:

in my squid proxy server, I would like to monitor certain HTTP/HTTPS POST
requests before it goes out of squid. What are my options?
Thanks.



--
View this message in context: 
http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-and-post-method-tp4670122.html
Sent from the Squid - Users mailing list archive at Nabble.com.
___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users



--
Ron Wheeler
President
Artifact Software Inc
email: rwhee...@artifact-software.com
skype: ronaldmwheeler
phone: 866-970-2435, ext 102

___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users


Re: [squid-users] SSL/SSH/SFTP/FTPS to alternate ports

2014-10-12 Thread Ron Wheeler

On 12/10/2014 11:33 AM, Timothy Spear wrote:

B,

I was going to attach the logs, but I now feel like an idiot. :D
The jump box I am running Squid on, currently only allows 80 and 443 
outbound. I recalled this when I went to scp the log files and the 
connection was refused
I detest overlooking things like this. Sometimes, you really need 
question any assumptions.


You are not alone! Sometimes-Always



Tim

On Oct 12, 2014, at 11:11 AM, crazy world crazywo...@outlook.com 
mailto:crazywo...@outlook.com wrote:


Do you have the log for the connection when you can't access? Other 
than 22 and 443 as you said.


Thanks,

-B


Subject: Re: [squid-users] SSL/SSH/SFTP/FTPS to alternate ports
From: n61...@gmail.com mailto:n61...@gmail.com
Date: Sun, 12 Oct 2014 10:49:05 -0400
CC: n61...@gmail.com mailto:n61...@gmail.com; 
squid-users@lists.squid-cache.org 
mailto:squid-users@lists.squid-cache.org

To: crazywo...@outlook.com mailto:crazywo...@outlook.com

Here is the access log. I should have included it in the original 
post. This is accessing a test machine I setup to hit SSH on 22 and 
443. I can also hit HTTPS on multiple other ports.


1413125068.706 87 10.110.98.21 TCP_MISS/503 0 CONNECTXXX..com 
http://xxx..com/:22 - HIER_NONE/- -
1413125086.496   8061 10.110.98.21 TCP_MISS/200 3657 
CONNECTXXX..com http://xxx..com/:443 - 
HIER_DIRECT/54.68.15.208 -


Yes, my intent in the rule set is to provide a list of allowed ports 
and sites.


Tim

On Oct 11, 2014, at 11:37 PM, B crazywo...@outlook.com 
mailto:crazywo...@outlook.com wrote:


check out your access log seeing what it says. Sounds like you
are looking for an AFW from squid. The ports themselves are
defined. You need to make sure the other ports are opened.

Your rule tells squid to block the non-allowed sites to the
non-allowed ports. Still sounds like FW function, but with the
domain feature only.

-B
On 10/12/2014 7:48 AM, Timothy Spear wrote:

Hello,

Here is the issue:
I can proxy through Squid just fine to HTTP and HTTPS. I can
also run SSH via Corkscrew to a SSH server running on port
443 and it works fine.
What I cannot do, is access HTTPS or SSH on any other port
except 443. I have lost track of the number of things I have
tried so any help will be appreciated and I feel like I am
missing something simple.
OS: Ubuntu 14.04.1 LTS
Squid: 3.3.8-1ubuntu6.1

Here is my current Squid 3 configuration:


debug_optionsall,3

# local network we proxy for
acllocalnetsrc10.110.98.0/24

# what ports can be the desitnation
aclallowedPortsport21
aclallowedPortsport22
acl allowedPorts port 
aclallowedPortsport80
acl allowedPorts port 443
acl allowedPorts port 8443

aclCONNECTmethodCONNECT

# determine the available sites
aclallowedSitesdstdomain/etc/squid3/allowed-sites.squid

# now block anything not on the localnet or ports
http_accessdeny!localnet

# allow connect only for approved ports
http_access deny CONNECT !allowedPorts

# now only allow to the specific sites
http_accessallowlocalnet allowedSites allowedPorts

http_port3128
access_log/var/log/squid3/access.logsquid
hosts_file /etc/hosts


Background (just FYI):
I am trying to setup Squid to control network access from a
local subnet to a select number of domains. I do not need to
bump the encrypted traffic and play man in the middle, I just
need to prevent the servers on the local network from
accessing unauthorized networks. Yes, I know I can do this in
the Firewall, but that is IP based and I am dealing with
enough other companies that maintaining the IP list has
become a major pain. Instead I want to use domains, which I
can do in Squid.

Thanks,

Tim


___
squid-users mailing list
squid-users@lists.squid-cache.org  
mailto:squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users





___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users



--
Ron Wheeler
President
Artifact Software Inc
email: rwhee...@artifact-software.com
skype: ronaldmwheeler
phone: 866-970-2435, ext 102

___
squid-users mailing list
squid-users@lists.squid-cache.org
http://lists.squid-cache.org/listinfo/squid-users