Re: [squid-users] Two connections per client

2016-03-15 Thread Amos Jeffries
On 16/03/2016 12:38 p.m., Chris Nighswonger wrote: > Why does netstat show two connections per client connection to Squid: > > tcp0 0 127.0.0.1:3128 127.0.0.1:34167 > ESTABLISHED > tcp0 0 127.0.0.1:34167 127.0.0.1:3128 > ESTABLISHED > > In this case, the

Re: [squid-users] gzip deflate

2016-03-15 Thread Amos Jeffries
On 16/03/2016 11:26 a.m., joe wrote: > any way of having decompression in futur? > there is lots a public nice source if it help to use it to make squid > better > using zlib > There is an eCAP module for that . Most reports have been that adding compr

Re: [squid-users] Sudden but sustained high bandwidth usage

2016-03-15 Thread Amos Jeffries
On 16/03/2016 6:51 a.m., Heiler Bemerguy wrote: > > Hi joe, Eliezer, Amos.. today I saw something different regarding high > bandwidth and caching of windows updates ranged requests.. > > A client begins a windows update, it does a: > HEAD to check size or something, which is ok.. > then a ranged

[squid-users] access from same ID and different IP addresses.

2016-03-15 Thread asakura
Hello, Recently, in our environment, CPU load on the squid proxy server is happening trouble to become a 100%. example PID USER PR NI VIRT RES SHR S %CPU %MEMTIME+ COMMAND 29767 squid 20 0 1430m 1.3g 5332 R 99.1 17.4 6836:56 squid 16856 squid 20 0 29764 3280 1620 S

[squid-users] Two connections per client

2016-03-15 Thread Chris Nighswonger
Why does netstat show two connections per client connection to Squid: tcp0 0 127.0.0.1:3128 127.0.0.1:34167 ESTABLISHED tcp0 0 127.0.0.1:34167 127.0.0.1:3128 ESTABLISHED In this case, there is a content filter running in front of Squid on the same box. T

[squid-users] gzip deflate

2016-03-15 Thread joe
any way of having decompression in futur? there is lots a public nice source if it help to use it to make squid better using zlib -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/gzip-deflate-tp4676698.html Sent from the Squid - Users mailing list archive at

Re: [squid-users] Sudden but sustained high bandwidth usage

2016-03-15 Thread Eliezer Croitoru
Hey, Your words describe the BUG in his wildest and simplest form. Please file a bug report to follow the progress. Writing here more and more will not be really a good help as it is. Eliezer On 15/03/2016 19:51, Heiler Bemerguy wrote: Hi joe, Eliezer, Amos.. today I saw something different r

Re: [squid-users] squid eat bandwidth

2016-03-15 Thread HackXBack
with my squid server i have 1 ethernet this squid box is connected with mikrotik routerOS this mikrotik have users conneted to it and in it i can redirect port 80 that come from users to squid server okay now i see that this squid take internet more than it give to users this mean it take bandwidt

Re: [squid-users] Sudden but sustained high bandwidth usage

2016-03-15 Thread Heiler Bemerguy
Hi joe, Eliezer, Amos.. today I saw something different regarding high bandwidth and caching of windows updates ranged requests.. A client begins a windows update, it does a: HEAD to check size or something, which is ok.. then a ranged GET, which outputs a TCP_MISS/206, then the next GET gives

Re: [squid-users] how i will avoid the warning info ? "This cache hit is still fresh and more than 1 day old"

2016-03-15 Thread joe
if you don't want your clients to see any specific reply just add this be warned some info if you deny might fkp your clients browsing. example: reply_header_access Warning deny all -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/how-i-wi

Re: [squid-users] Squid with LDAP-authentication: bypass selected URLs

2016-03-15 Thread FredB
I guess you have an acl with proxy_auth ? Something like acl ldapauth proxy_auth REQUIRED ? So you can just add http_access allow ldapauth !pdfdoc and perhaps http_access allow pdfdoc after Fred ___ squid-users mailing list squid-users@lists.squid-cac

Re: [squid-users] Bandwidth control with delay pool

2016-03-15 Thread FredB
You can easily make this with an acl, delay_pool is a very powerful tool eg: Bandwidth 64k for each users with an identification except for acl BP and only in time included in acl desk acl my_ldap_auth proxy_auth REQUIRED acl bp dstdom_regex "/etc/squid/limit" acl desk time 09:00-12:00 acl

[squid-users] Bandwidth control with delay pool

2016-03-15 Thread Luigi Kurihara
Good afternoon, I need to control the bandwidth using squid to certain domain/IP’s/server’s. My client needs, I reduce bandwidth in his network to employees using facebook. Ex.: facebook - 10K for the all other sites still stay normal. I read many tutorials, search in google and the one of solutio

[squid-users] Bandwidth control with delay pool

2016-03-15 Thread Luigi Kurihara
Good afternoon, I need to control the bandwidth using squid to certain domain/IP’s/server’s. My client needs, I reduce bandwidth in his network to employees using facebook. Ex.: facebook - 10K for the all other sites still stay normal. I read many tutorials, search in google and the one of solutio

[squid-users] Squid with LDAP-authentication: bypass selected URLs

2016-03-15 Thread Verwaiser
Hello, we use user-authentication using a LDAP server. We want to use a pdf - document which connects to an internet address (europa.eu) for a kind of examination. The pdf doesnt ask for proxy-authentification, so I tried to go around squid using ACLs like: acl alle src 0.0.0.0/0.0.0.0 acl pd

Re: [squid-users] how i will avoid the warning info ? "This cache hit is still fresh and more than 1 day old"

2016-03-15 Thread Amos Jeffries
On 16/03/2016 1:19 a.m., johnzeng wrote: > > Hello Dear Sir : > > i found a warning info via firebug , how i will avoid the warning info ? Is the statement made in the header incorrect? > > Age 474416 > Cache-Control max-age=31536 > Cont

Re: [squid-users] FreeBSD and Kerberos: RC4 keytabs work, AES256 don't

2016-03-15 Thread Victor Sudakov
Marko Cupa?? wrote: > > I am setting up new AD-integrated squid server, so I thought I might as > well upgrade kerberos crypto on keytabs. > > It seems that, at least on FreeBSD 10.2-RELEASE-p13, squid-3.5.15 > compiled with GSSAPI_BASE (kerberos from base system) can't > authenticate users via k

Re: [squid-users] Squid Windows Installer

2016-03-15 Thread Rafael Akchurin
Hello Patrick, The ROOTDRIVE is MSI property, not environment variable. See for example at https://msdn.microsoft.com/en-us/library/windows/desktop/aa367988%28v=vs.85%29.aspx Best regards, Rafael Akchurin Diladele B.V. -- Please take a look at Web Safety - our ICAP based web filter server for S

Re: [squid-users] squidGuard: redirect to squid-internal URLs no longer working with 3.5?

2016-03-15 Thread Silamael
On 03/15/2016 12:52 PM, Amos Jeffries wrote: >> So, if i try this, i get a 404 response and the ERR_INVALID_REQ page. > > Okay. That is the correct behaviour for this situation. > Squid does not normally load anything at the > /squid-internal-static/error-access-denied path. > > A second bug / un

Re: [squid-users] Core dump / xassert on FwdState::unregister (3.5.15)

2016-03-15 Thread squid
On 2016-03-15 09:40, sq...@peralex.com wrote: > On 2016-03-15 09:05, Amos Jeffries wrote: >> On 15/03/2016 7:34 p.m., squid wrote: >> >> This is bug 4447. Please update to a build from the 3.5 snapshot. >> > > Thanks. I'll give that a try. > Looks like it's working correctly now - been running

[squid-users] how i will avoid the warning info ? "This cache hit is still fresh and more than 1 day old"

2016-03-15 Thread johnzeng
Hello Dear Sir : i found a warning info via firebug , how i will avoid the warning info ? Age 474416 Cache-Control max-age=31536 Content-Length 1556 Content-Type image/jpeg Date Sat, 05 Mar 2016 01:38:36 GMT Expires Thu, 31 Dec 2037 23:55:55 GMT Last-Modified Wed, 25 Mar 2015 13:00:08 GMT Se

[squid-users] FreeBSD and Kerberos: RC4 keytabs work, AES256 don't

2016-03-15 Thread Marko Cupać
Hi, I am setting up new AD-integrated squid server, so I thought I might as well upgrade kerberos crypto on keytabs. It seems that, at least on FreeBSD 10.2-RELEASE-p13, squid-3.5.15 compiled with GSSAPI_BASE (kerberos from base system) can't authenticate users via kerberos using AES256 keytabs.

Re: [squid-users] squidGuard: redirect to squid-internal URLs no longer working with 3.5?

2016-03-15 Thread Amos Jeffries
On 15/03/2016 9:25 p.m., Silamael wrote: > On 03/15/2016 12:10 AM, Amos Jeffries wrote: >> On 15/03/2016 2:22 a.m., Silamael wrote: >>> >>> On 03/14/2016 02:16 PM, Kinkie wrote: Hi, .. has it ever? internal:// doesn't seem like a recognized protocol to me. >>> It worked till the u

[squid-users] Landing- Disclaimer-Page for an Exchange 2013 Reverse Proxy

2016-03-15 Thread Squid Users
Hi, I've installed a Squid reverse proxy for a MS-Exchange Test-Installation to reach OWA from the outside. My current environment is as follows: Squid Version 3.4.8 with ssl on a Debian Jessie (self compiled) The Squid and the exchange system are in the internal network with private ip-addres

Re: [squid-users] squidGuard: redirect to squid-internal URLs no longer working with 3.5?

2016-03-15 Thread Silamael
On 03/15/2016 12:10 AM, Amos Jeffries wrote: > On 15/03/2016 2:22 a.m., Silamael wrote: >> >> On 03/14/2016 02:16 PM, Kinkie wrote: >>> Hi, >>> .. has it ever? internal:// doesn't seem like a recognized protocol to me. >> It worked till the update to Squid 3.5. >> > > It should not have. That wa

Re: [squid-users] Need advice on some crazy access control requirements

2016-03-15 Thread Rafael Akchurin
Hello Victor, Please send me e-mail at supp...@diladele.com . We should not pollute the list with this off topics. Best regards, Rafael -Original Message- From: Victor Sudakov [mailto:suda...@sibptus.tomsk.ru] Sent: Tuesday, March 15, 2016 8:45 AM To: Rafael Akchurin Cc: squid-users@li

Re: [squid-users] Need advice on some crazy access control requirements

2016-03-15 Thread Victor Sudakov
Rafael Akchurin wrote: > > > > In order to scan the contents of the files being downloaded you might > > need to have eCAP or ICAP module/server attached to your Squid. > > Please take a look at Web Safety - our ICAP based web filter server > > for Squid proxy > > > It's for pfSense, isn't it

Re: [squid-users] Core dump / xassert on FwdState::unregister (3.5.15)

2016-03-15 Thread squid
On 2016-03-15 09:05, Amos Jeffries wrote: > On 15/03/2016 7:34 p.m., squid wrote: >> >> I'm running FreeBSD 9.3-STABLE and Squid 3.5.15 and I'm getting regular >> core dumps with the following stack. Note that I have disabled caching. >> Any suggestions? I've logged a bug (4467): >> >> #0 0x000

Re: [squid-users] Core dump / xassert on FwdState::unregister (3.5.15)

2016-03-15 Thread Amos Jeffries
On 15/03/2016 7:34 p.m., squid wrote: > > I'm running FreeBSD 9.3-STABLE and Squid 3.5.15 and I'm getting regular > core dumps with the following stack. Note that I have disabled caching. > Any suggestions? I've logged a bug (4467): > > #0 0x000801b8c96c in thr_kill () from /lib/libc.so.7

Re: [squid-users] Need advice on some crazy access control requirements

2016-03-15 Thread Rafael Akchurin
Hello Victor, We build ICAP on native FreeBSD 10 and then provide instructions/tutorial how to install/adapt it for pfSense (which is also FreeBSD 10 inside). It will not work on FreeBSD 9 though :( Best regards, Rafael Akchurin Diladele B.V. -Original Message- From: Victor Sudakov [mai