Re: [squid-users] SSL-BUMP 5.0.4 not working as expected

2021-01-02 Thread Amos Jeffries
On 3/01/21 9:08 am, ngtech1ltd wrote: I am trying to configure 5.0.4 with sslbump to bump only a set of domains. I am unsure about the right way it should be done. The basic constrains are POLICY vs a set of rules. * Should I bump all connections with exceptions? * Should I bump non else

[squid-users] SSL-BUMP 5.0.4 not working as expected

2021-01-02 Thread ngtech1ltd
I am trying to configure 5.0.4 with sslbump to bump only a set of domains. I am unsure about the right way it should be done. The basic constrains are POLICY vs a set of rules. * Should I bump all connections with exceptions? * Should I bump non else then the exceptions? *

Re: [squid-users] Anyone has experience with Windows clients DNS timeout

2021-01-02 Thread ngtech1ltd
Hey Amos, For an INTERCEPT setup we still need to resolve before squid is touching the packets. There are registry keys for this purpose however we first need to identify this issue. The basic way to verify this is using the "set debug" on nslookup and use a fully "cold" DNS recurser. I was

Re: [squid-users] Setting up a transparent http and https proxy server using squid 4.6

2021-01-02 Thread jean francois hasson
Hi, Thank you Amos Jeffries and Antony Stone. It seems the configuration I have provides the functionality of filtering I am looking for. There is a strange behavior I can see when accessing some legitimate sites which I see traces of in cache.log : 2021/01/02 10:55:48 kid1|