Re: [squid-users] squidclient and PROXY procotol enabled http_port

2018-04-14 Thread Eliezer Croitoru
Would a nc(netcat) bash based script that will run this kind of request would be good enough? Eliezer Eliezer Croitoru Linux System Administrator Mobile: +972-5-28704261 Email: elie...@ngtech.co.il -Original Message- From: squid-users On Behalf Of Rafael Akchurin Sent: Saturday, A

Re: [squid-users] Secure Web Proxy Stress Testing

2018-04-14 Thread Panagiotis Bariamis
Thank you , Bariamis Panagiotis On Tue, Apr 10, 2018 at 10:14 PM, Panagiotis Bariamis wrote: > Thank you for the clarification. > > On Tue, Apr 10, 2018, 21:11 Alex Rousskov com> wrote: > >> >> >> >Polygraph supports HTTPS proxies and HTTPS servers. IIRC, Polygraph v5 >> >supports the combinati

Re: [squid-users] SSL intercept in explicit mode

2018-04-14 Thread Antony Stone
On Saturday 14 April 2018 at 13:22:32, MK2018 wrote: > I had used squid effectively and perfectly for more than a year before I > could understand (on my own) how to craft an 'allow' or 'deny' line that > contains all of: source acl, dst acl, connection method, HTTP command, TCP > port, excluded d

Re: [squid-users] SSL intercept in explicit mode

2018-04-14 Thread MK2018
Amos Jeffries wrote > Which parts (if any in the current text) are you getting confused or > lost by? It is not about confusion as much as it is about syntax. Since I'm always bumping to fight unwanted user traffic / analyze traffic consumption, I would need to use 'stare' verb. But, I had only tr

Re: [squid-users] squidclient and PROXY procotol enabled http_port

2018-04-14 Thread Amos Jeffries
On 14/04/18 20:13, Rafael Akchurin wrote: > Question > > Is it possible to ask squidclient to prepend the PROXY header to its request? > It should be relatively easy to add, but has not been coded yet if thats what you mean. Patches welcome. Amos

Re: [squid-users] SSL intercept in explicit mode

2018-04-14 Thread Amos Jeffries
On 14/04/18 20:51, MK2018 wrote: > Amos Jeffries wrote >> FYI this is "server-first all". peek and splice before "bump all" is >> similar but also different in ways that allow it to handle more problems >> in better ways. > > I never really got to understand how to implement peek and splice verbs.

Re: [squid-users] SSL intercept in explicit mode

2018-04-14 Thread MK2018
Amos Jeffries wrote > FYI this is "server-first all". peek and splice before "bump all" is > similar but also different in ways that allow it to handle more problems > in better ways. I never really got to understand how to implement peek and splice verbs. I was glad I could get away with server-f

[squid-users] squidclient and PROXY procotol enabled http_port

2018-04-14 Thread Rafael Akchurin
Greetings to everyone, I have the following deployment: - Several Squid nodes configured with "http_port 3128 require-proxy-header" - One haproxy what relays TCP connections to nodes - squidclient that is run on each node manually Browsers pointing to haproxy are corre

Re: [squid-users] Squid is very slow after moving to production environment

2018-04-14 Thread Amos Jeffries
On 13/04/18 05:55, Roberto Carna wrote: > People, I can't test de new proxy in the production environment > because I affect the users. I think is a good idea to add 10/15 users > to my new proxy, and test it with users from my IT area. Maybe the > problem is DansguardianI don't know. > > I'm

Re: [squid-users] SSL intercept in explicit mode

2018-04-14 Thread Amos Jeffries
On 14/04/18 10:05, MK2018 wrote: > Aaron Turner wrote >> Thanks Yuri. That helps. As for the "sslproxy_flags >> DONT_VERIFY_PEER", yes I understand the risks. In my specific case, >> where my "users" are actually a bunch of automated web clients doing >> some web crawling it's the right thing to