[squid-users] Problem with ssl_choose_client_version:inappropriate fallback on some sites when using TLS1.2

2019-09-15 Thread John Sweet-Escott
Hi All We are trying to run Squid 4.8, compiled with OpenSSL 1.1.1 (see [1]) on Ubuntu 18.04 as a transparent proxy for the purpose of egress filtering of HTTPS traffic using SNI (see config in [2]). It it works correctly when contacting some addresses (e.g. https://www.ubuntu.com) but not others

[squid-users] Non-Transparent HTTP+HTTP Proxy

2019-09-15 Thread sknz
This is the configuration for my HTTP+HTTPS transparent proxy. I'm using this for logging HTTP and HTTPS traffic without issuing a client certificate. How to modify this configuration to make it NON-TRANSPARENT? In WEB-PROXY which is based on Squid, we can disable it by adding

Re: [squid-users] Squid Transparent Proxy with Coovachilli is not working

2019-09-15 Thread Matus UHLAR - fantomas
On 14.09.19 23:57, sknz wrote: eht1 is not useless really, Coovachilli created tun0 under eth1. Yes, I've heard about stateful firewall, though this is not my domain of expertise. it's very hard to guess what's the problem and how should the solution look like, when someone does this to