Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Just for information: http://pastebin.com/dBYV9Zzb Here is completely actual Cisco NBAR filtering capabilities from one of my front 2901 with IOS 15.5 + actual NBAR2 protocol pack. Just take a look. You can see there P2P, Torrents, FB, YT, etc.e

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Finally, read this thread too: http://www.spinics.net/lists/squid/msg81113.html Some questions already answered here. 05.05.16 3:26, Yuri Voinov пишет: > > As a part of solution I recommend (by my own experience) consider to use this: > > https

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 As a part of solution I recommend (by my own experience) consider to use this: https://www.urlfilterdb.com/products/ufdbguard.html But I repeat: this is NOT magic button "Disable all". This is relatively effective tool to block categories. This

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Generally, for effective blocking of everything better design would first consider - as everyone and everything is engeneered, and then look for the magic button "to disable all to hell." Then it becomes clear what is possible and what means - and

Re: [squid-users] URL/P2P blocking

2016-05-04 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Facebook uses Akamai as background CDN, so you need to block Akamai (related URL's, which can be difficult, so consider to use Cisco NBAR DPI functionality). too in case to completely block FB. YT still uses QUIC/SPDY, so read this http://wiki.sq

[squid-users] URL/P2P blocking

2016-05-04 Thread Maile Halatuituia
?Someone with ideas on how to block Facebook,Youtube, P2P Traffic though my squid box. Facebook seems to be working but likely some users bypass to youtube.com and the rest are blocked. Also am looking to block P2P traffic , BITS proticols, etc etc Cheers Confidentiality Notice: This email (i

Re: [squid-users] quick_abort_min by acl?

2016-05-04 Thread Amos Jeffries
On 5/05/2016 1:01 a.m., Jester Purtteman wrote: > Greetings! > > > > Is there a way I'm not seeing to apply ACLs to quick_abort_min? It seems > like it would be handy to be able to tell squid to finish downloads for > specific sites, and not others. No, the quick_abort_* directives do not su

[squid-users] quick_abort_min by acl?

2016-05-04 Thread Jester Purtteman
Greetings! Is there a way I'm not seeing to apply ACLs to quick_abort_min? It seems like it would be handy to be able to tell squid to finish downloads for specific sites, and not others. ___ squid-users mailing list squid-users@lists.squid-cache.o

Re: [squid-users] ldap authentication with encrypted credentials

2016-05-04 Thread L . P . H . van Belle
In addition, due to last samba and windows security fixes there was a behavior change. So beware with squid and samba/winbind/ldap/windows auth. Read : https://www.samba.org/samba/history/samba-4.4.2.html This was a big impact.. BUt beware, use samba 4.2.12 4.3.9 or 4.4.3 All version bug rel

Re: [squid-users] ldap authentication with encrypted credentials

2016-05-04 Thread Amos Jeffries
On 4/05/2016 11:56 p.m., Sampei wrote: > I'll explain better: > Squid is running on Debian 5 older server and every Windows (XP/7/10) > client uses it to surf on web. > Clients are configured in outofdate Microsoft domain where Domain > Controllers are based on Windows 2000 server. > So far I permi

Re: [squid-users] Is there a way to allow connection according to user certificate?

2016-05-04 Thread Yuri Voinov
04.05.16 18:05, Amos Jeffries пишет: On 4/05/2016 11:20 p.m., Ser de Bronce wrote: Hi there, Maybe someone already knows any solution: I have transparent proxy and according to some reasons I can’t use login/password authentication. However I still need to control who can access my proxy.

Re: [squid-users] Is there a way to allow connection according to user certificate?

2016-05-04 Thread Amos Jeffries
On 4/05/2016 11:20 p.m., Ser de Bronce wrote: > Hi there, > > > Maybe someone already knows any solution: > > > I have transparent proxy and according to some reasons I can’t use > login/password authentication. However I still need to control who can > access my proxy. > > > I can install ce

Re: [squid-users] ldap authentication with encrypted credentials

2016-05-04 Thread Sampei
I'll explain better: Squid is running on Debian 5 older server and every Windows (XP/7/10) client uses it to surf on web. Clients are configured in outofdate Microsoft domain where Domain Controllers are based on Windows 2000 server. So far I permit Internet access to clients by specify IP addre

Re: [squid-users] Is there a way to allow connection according to user certificate?

2016-05-04 Thread Yuri Voinov
04.05.16 17:20, Ser de Bronce пишет: Hi there, Maybe someone already knows any solution: I have transparent proxy and according to some reasons I can’t use login/password authentication. However I still need to control who can access my proxy. Transparent proxy can't use any authentif

[squid-users] Is there a way to allow connection according to user certificate?

2016-05-04 Thread Ser de Bronce
Hi there, Maybe someone already knows any solution: I have transparent proxy and according to some reasons I can’t use login/password authentication. However I still need to control who can access my proxy. I can install certificates to my users. Is it possible to allow connection only if a u