Re: [squid-users] SSL Bump - Splice - Chrome error

2016-01-03 Thread Alejandro Martinez
Thanks again Yuri. I have tried blocking udp protocol on port 80 and 443 but without luck. Is it possible to make google sites work in transparent mode without bumping ? only splicing ? Thanks 2016-01-03 10:11 GMT-03:00 Alejandro Martinez : > Sorry my corrector. > I want to say that i am goin

Re: [squid-users] Delay Pools or Traffic Shaping per port?!

2016-01-03 Thread Christian Kunkel
>>> How many users do you have? >> >> i wanted to put about 200-500 users on a server. is that possible? > > Certainly no problem for Squid, and I guess you could assign that number of > separate listening ports for use one per user, but I'll let someone who knows > more about Squid's internal

[squid-users] squid 4.0.3 - sslflags not working?

2016-01-03 Thread Florian Stamer
Hi I,m currently testing Squid 4.0.3 in Reverse Proxy Mode. It seems that the sslflags directives "DONT_VERIFY_PEER" and "DONT_VERIFY_DOMAIN" do not work. Here is the relevant config: https_port 443 accel cert=/etc/squid/ssl/wildcard.cer key=/etc/squid/ssl/wildcard.key defaultsite=externeURL c

Re: [squid-users] Question about redirect

2016-01-03 Thread Antony Stone
On Sunday 03 January 2016 at 20:41:51, Daniel Calin wrote: > Scenario: > External IP: 1.1.1. > Website: www.domain1.com > Website: www.domain2.com > External DNS for both sites points to 1.1.1.1 > www.domain1.com is hosted on internal LAN IP 2.2.2.1 > www.domain2.com is hosted on the internal LAN

[squid-users] Question about redirect

2016-01-03 Thread Daniel Calin
Hi guys, First of all I want to apologies if you already posted this info. I am searching for the last 6 hours but dind't found anything that is suited to my needs.I have the below scenario: Scenario: External IP: 1.1.1.1Website: www.domain1.comWebsite: www.domain2.comExternal DNS for both sites

Re: [squid-users] SSL Bump - Splice - Chrome error

2016-01-03 Thread Alejandro Martinez
Sorry my corrector. I want to say that i am going to check blocking quic proto. Sorry El 03/01/2016 10:10, "Alejandro Martinez" escribió: > Yuri > > Thanks. > > I amor.gringaus to checkpoint blocking quic. > > I cant put ca cert into clients besarse I dont have access but I do not > want to bump

Re: [squid-users] SSL Bump - Splice - Chrome error

2016-01-03 Thread Alejandro Martinez
Yuri Thanks. I amor.gringaus to checkpoint blocking quic. I cant put ca cert into clients besarse I dont have access but I do not want to bump, Just allow almost everything and deny only a few sites. I Will tell you my result. El 03/01/2016 06:22, "Yuri Voinov" escribió: > Sure, > > my confi

Re: [squid-users] Delay Pools or Traffic Shaping per port?!

2016-01-03 Thread Antony Stone
On Sunday 03 January 2016 at 12:35:10, Christian Kunkel wrote: > > Am 03.01.2016 um 10:13 schrieb Antony Stone: > > > > How many users do you have? > > i wanted to put about 200-500 users on a server. is that possible? Certainly no problem for Squid, and I guess you could assign that number of

Re: [squid-users] Delay Pools or Traffic Shaping per port?!

2016-01-03 Thread Christian Kunkel
> Am 03.01.2016 um 10:13 schrieb Antony Stone > : > >> On Sunday 03 January 2016 at 09:42:21, Christian Kunkel wrote: >> >> Am 03.01.2016 um 01:14 schrieb Antony Stone; > On Sunday 03 January 2016 at 00:46:39, Christian Kunkel wrote: Hey guys, is there any way i can do

Re: [squid-users] SSL Bump - Splice - Chrome error

2016-01-03 Thread Yuri Voinov
Sure, my config is quite different. Also - did you put cache CA cert into clients? And - did you block QUIC in your infrastructure? As described here: http://wiki.squid-cache.org/KnowledgeBase/Block%20QUIC%20protocol ? 03.01.16 8:28, Alejandro Martinez пишет: Yuri Do you haber something d

Re: [squid-users] Delay Pools or Traffic Shaping per port?!

2016-01-03 Thread Antony Stone
On Sunday 03 January 2016 at 09:42:21, Christian Kunkel wrote: > Am 03.01.2016 um 01:14 schrieb Antony Stone; > > >> On Sunday 03 January 2016 at 00:46:39, Christian Kunkel wrote: > >> > >> Hey guys, > >> > >> is there any way i can do some traffic shaping with squid? > > > > Yes, but it's nowh

Re: [squid-users] Delay Pools or Traffic Shaping per port?!

2016-01-03 Thread Christian Kunkel
Am 03.01.2016 um 01:14 schrieb Antony Stone : > >> On Sunday 03 January 2016 at 00:46:39, Christian Kunkel wrote: >> >> Hey guys, >> >> is there any way i can do some traffic shaping with squid? > > Yes, but it's nowhere near as good as doing it with IP tools on the > underlying > O/S. ok. t