Re: [squid-users] accessing google.com

2015-07-13 Thread Philipp Wehling
Hello, thank you for your answer. This is where you really do need to understand the 28,3 debug output. I thought squid works in a first-match-manner... Do you have any documentation, I can read about? That is of course following your assumption that Squid is actively rejecting the

Re: [squid-users] accessing google.com

2015-07-13 Thread Amos Jeffries
On 13/07/2015 10:39 p.m., Philipp Wehling wrote: Hello, thank you for your answer. This is where you really do need to understand the 28,3 debug output. I thought squid works in a first-match-manner... Do you have any documentation, I can read about? Nothing that woudl be helpful Im

Re: [squid-users] Transparent proxy before NAT

2015-07-13 Thread Yuri Voinov
I use a bit another configuration: http://wiki.squid-cache.org/ConfigExamples/Intercept/CiscoIOSv15Wccp2 As you can see, squid box placed between two routers. Front router uses NAT to white IP, back router has no NAT and configured with WCCPv2 redirection. DMZ configured between two routers.

Re: [squid-users] Squid + kerberos, all childrens are busy

2015-07-13 Thread Дмитрий Рукавцов
    Hello, i have a problem here :) System - freebsd 10.1, squid 3.5.5 + kerberos (MIT), 50 users total.         Without any auth my squid works fine, system is not loaded. When i enable Kerberos auth internet slowly goes down and crushing after a while, at logs i see:        

Re: [squid-users] Squid + kerberos, all childrens are busy

2015-07-13 Thread Amos Jeffries
On 14/07/2015 5:54 a.m., Дмитрий Рукавцов wrote: Hello, i have a problem here :) System - freebsd 10.1, squid 3.5.5 + kerberos (MIT), 50 users total. Without any auth my squid works fine, system is not loaded. When i enable Kerberos auth internet slowly goes down

Re: [squid-users] Transparent proxy before NAT

2015-07-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Ah, forgot about: Your squid in scheme I wrote will have static gray IP. And this IP must be excluded from DHCP pool on router. 14.07.15 2:15, John Pearson пишет: Hi Everyone, My setup is: Internet -- Squid-eth0 -- Squid-eth1 -- Router --

Re: [squid-users] Transparent proxy before NAT

2015-07-13 Thread John Pearson
Thanks Yuri for the response, I understand. I do have Shorewall configured and I understand the security implications. My Router is also the Wireless AP, so I want to try out this setup without having to buy another Wireless AP. I don't mind it being complex, do you have any suggestions on

Re: [squid-users] cannot use squid-3.5.x for production

2015-07-13 Thread Othmar Truniger
Amos, would you mind 'pinging' again. The bug is not even confirmed yet. The FTP handling code was re-written and shuffled around a lot to get FTP native support working. I've 'pinged' the author who did that about your bug report. Hopefully he will have some time to look at it. Amos

[squid-users] Is it possible to tunnelize http traffic?

2015-07-13 Thread Sebastian Goicochea
Hello, I'm trying to improve the bypass system we use in our servers. When a site is not shown as it should, or something is broken because of a poor server's side implementation, we bypass traffic to that server at ebtables level. This works just as expected, squid never sees this traffic,

Re: [squid-users] Transparent proxy before NAT

2015-07-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Too complex setup for simple task. You can simple re-connect squid box before router and configure it as gateway for devices. And setup NAT redirection directly onto squid box. Something like this: Internet - Router + DHCP + NAT --

Re: [squid-users] Transparent proxy before NAT

2015-07-13 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: If you want to use two NIC onto Squid box, you need to configure this box TCP stack as a static router. But more better to aggregate both NIC and connect router and squid box with switch. 14.07.15 2:15, John Pearson пишет: Hi Everyone,

[squid-users] [3.5.6]: assertion failed: store.cc:850: store_status == STORE_PENDING

2015-07-13 Thread David Touzeau
Hi all We receive this error in cache.log assertion failed: store.cc:850: store_status == STORE_PENDING Just after browser sends ERR_PROXY_CONNECTION_FAILED What does it means ? Best regards ___ squid-users mailing list

Re: [squid-users] RPM for 3.5.6 CentOS 6.x

2015-07-13 Thread Amos Jeffries
On 13/07/2015 1:36 p.m., Tory M Blue wrote: Wondering when a 3.5.6 RPM will be available. I can build the beta's no issue, but I've spent a couple of days with trying to get 3.5.6 packaged up and am failing. So it would be nice to get a 3.5.6 spun up as the 3.5.x was provided and that was

Re: [squid-users] issue with multiple outgoing addresses for same source address

2015-07-13 Thread Amos Jeffries
On 13/07/2015 10:50 a.m., Jason Enzer wrote: 'm hardly a novice in squid (more of an initiate, actually) ... but it looks like you've got the deny rules backwards in examples 2 3. With they assumption that the first rule works fine, they should read: 2. http_access deny *ip2 inc3172* 3.