Re: [squid-users] squid problems with DNS resolution

2003-08-14 Thread Greg Norris
On Wed, Aug 06, 2003 at 09:53:42PM -0500, Greg Norris wrote: The proxy server is also running pdnsd, which is providing name resolution for the local network. This appears to be working properly... email, http (minus squid), etc. have no apparent problem resolving hostnames. I've tried

[squid-users] squid problems with DNS resolution

2003-08-14 Thread Greg Norris
I've recently setup squid for a small home network (2 boxes, not counting the proxy server itself). Unfortunately, I instantly get the error text below almost every time I try to access a non-cached site. If I do a shift-reload, the site will then load successfully, and I don't have any further

RE: [squid-users] Reconfiguration by a non-root user

2003-08-14 Thread Adam Aube
SetGID does not help for this context.. only the owner or root may send signal to processes. So instead one must make the squid binary SetUID (owned by the squid user). Come to think of it, sudo might be a better choice. Adam

Re: [squid-users] Resource temporarily unavailable

2003-08-14 Thread Adam
Brian wrote: 2003/08/06 14:10:19| storeAufsOpenDone: (11) Resource temporarily unavailable 2003/08/06 14:10:19|/squid/s00/00/83/8369 2003/08/06 14:10:19| storeSwapOutFileClosed: dirno 0, swapfile 8369, errflag=-1 (11) Resource temporarily unavailable i'm getting these

Re: [squid-users] Authentification via samba 3.0 to an activedirectory server

2003-08-14 Thread Kinkie
Markus Meissner [EMAIL PROTECTED] writes: [...] - The last resort: Using the new ntlm_auth provided by the samba-team. Using this from the command-line works, wow (NT_STATUS_OK: Success (0x0)). But integrating it in squid leads to the following error: [2003/08/12 15:19:37, 3]

RE: [squid-users] denying .zip files and exes

2003-08-14 Thread Adam Aube
Is there a way for me to fix this. I want to deny files not the name zip Go to www.google.com. As your search phrase, use: squid-users block exe zip Check out the first few hits. Adam attachment: winmail.dat

Re: [squid-users] Multiple Domain Multiple NT Group

2003-08-14 Thread Serassio Guido
Hi, At 08.39 12/08/2003, Adnan TOPÇU wrote: Hello All, Servers OS are Win NT 4.0. We have two domains (D1 and D2) and there are two groups (LIMITED and FULL) on both domains. I can create two local groups Warning: Samba, and so Squid too, supports only Global Groups ! (LocalLimited LocalFull )

Re: [squid-users] Dial Access Server Squid

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, aqil wrote: But alas, even after setting the browser to use 10.1.1.1 as its proxy server, and even ping can be done from both sides (from client and from the proxy), I still can surf internet from a dial access... Without the traffic being proxied by Squid? I do not see

Re: [squid-users] [ Squid Cache: Version 3.0-PRE2-20030806 ][ SSL ]

2003-08-14 Thread Imad Soltani
hello , chapter 2 : i want to squid get all the https request from internet and redirect it in first to a web server ( may be in a second part load balacing/fail over issue ? ) i check network and dns resolution , all works fine the linux systeme is a redhat 8 , squid version is on the subject

[squid-users] want to block downloads from kazza

2003-08-14 Thread ads squid
Hi, 10 % of my total users continuously download from kazza. It has totally hampered speed of other users. I checked mail archieve but could not get required thing. I tried with acl options. acl STOP1 src 192.168.0.42 acl WORKING time MTWHF 07:30-16:32 acl SITE dstdomain desktop.KaZaA.com

[squid-users] user names rather than ip addy`s

2003-08-14 Thread Andy Dean
Hi After getting smb_auth going, thankyou those who helped, can i get squid to tie the usernames to web sites rather than the ip addresses of the machines, thankyou Regards Andy Dean IT Services E-Mail Disclaimer: The information in this e-mail is confidential, and may be legally

Re: [squid-users] Authentification via samba 3.0 to an activedirectory server

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, Markus Meissner wrote: No, basic auth with the following config leads to the same error. Then I think there is something wrong with your Samba installation. Does wbinfo work? Regards Henrik

Re: [squid-users] 2003/08/13 08:20:21| httpAccept: FD 15: accept failure: (24) Too many open files

2003-08-14 Thread Brian Hechinger
so ulimit for filedescriptors on solaris defaults to 256 for non-root. is there a way to determine how many filedescriptors squid needs so that i can set a proper ulimit? -brian On Wed, Aug 13, 2003 at 06:06:44AM -0700, Schelstraete Bart wrote: Just increase the number of open files in your

Re: [squid-users] WCCP

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, Masood Ahmad Shah wrote: it's not more than 100% :) I'm using it 90% so I think it must be typo error. It is possible to use LMT factors larger than 100%. But it is recommended to not go above 50%, except maybe for images. The LMT factor is a percentage of the object age

Re: [squid-users] deny files

2003-08-14 Thread Fernando Maior
Also, If the file is suffixed as .EXE instead of .exe, it will not be enough. So it should be better to use -i, like this: acl hello urlpath_regex -i .\exe$ http_access DENY hello As told by Henrik, it is pretty critical the place where you put your rules. You see, Squid rule processing is

Re: [squid-users] Re: custom error messages

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, ads squid wrote: My squid is Version 2.4.STABLE7 and error pages are in directory /etc/squid/errors/ERR_ACCESS_DENIED I still ask if /etc/squid/errors is the directory which is specified for error pages in your squid.conf? I have edited ERR_ACCESS_DENIED as suggested.

[squid-users] Kazaa - ICQ - FTP through Squid 2.4 STABLE 7

2003-08-14 Thread Daniel Arjona
I'm running squid 2.4 STABLE 7 in my main server (LINUX RH 8.0) and I can't connect to ICQ, Kazaa, Morpheus, and AudioGalaxy. Can i use FTP through Squid? How? Can anyone guide me throw this?! I must connect to them! Regards DANIEL A. ARJONA V. Network/Servers Administrator Transit

RE: [squid-users] bungling my squid.conf for front-end-https=on, OWA

2003-08-14 Thread David Gibson
OK - edited the perl script to examine the redirection. It looks ok- strange thing though- all redirector data comes in as http, even though I'm connecting on port 443. when I add the cache_peer line, all proxy requests start going to the ip address of the cache_peer server, no matter what the

Re: [squid-users] Kazaa - ICQ - FTP through Squid 2.4 STABLE 7

2003-08-14 Thread PASCUAL, Mike A.
You might take a look for you firewall, this is a firewall issue. kazaa port 1214 take a search to the other program port. Mike - Original Message - From: Daniel Arjona [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Thursday, August 14, 2003 3:34 AM Subject: [squid-users] Kazaa - ICQ

Re: [squid-users] wb_group problem

2003-08-14 Thread Aleksandr Shcherbakov
wbinfo says: wbinfo -r username Could not get groups for user username wbinfo -r domain\username Could not get groups for user domain\username - Original Message - From: Henrik Nordstrom [EMAIL PROTECTED] To: ? [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Wednesday,

Re: [squid-users] Authentification via samba 3.0 to an activedirectory server

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, Markus Meissner wrote: Hm, sounds good, but... I don't know how to find it. lsof gives me many files, doing a grep on squid has still a lot of files, none of them looks like a named pipe. I have some pipes in the output, but they don't have a filename. What should I

[squid-users] Direct conection to one site

2003-08-14 Thread Luiz C. Spies
Hi i have my squid server working fine, but one of my clients have a site... with a problem the squid can cache this site, someone can tell me how i put this site to direct conection to pass ou squid? Luiz C. Spies

RE: [squid-users] Compile WCCP module optimally

2003-08-14 Thread Henrik Nordstrom
On Wed, 13 Aug 2003 [EMAIL PROTECTED] wrote: I have this set up using the ip_gre module. I didn't do anything to patch it. How do I do that? I managed to find a patch for ip_gre at swelltech but don't have a clue as to how to apply it. Then use ip_wccp. The way I understand it all, the

Re: [squid-users] Squid Report not working

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 18.41, Jim_Brouse/[EMAIL PROTECTED] wrote: How can I tell why it failed or if it did attempt to run at the scheduled time? Yoy should be receiving emails if there was any problems. To see if it was run you can look into the cron log. Usually in /var/log/ For

[squid-users] SMTP,POP3 and News problems

2003-08-14 Thread aba ab
I can't use the SMTP, POP3 and NEWS services with the SQUID (the http works fine), I have only this access list acl allPorts port 0-65000 http_access allow all allPorts (I am sure that I have the clients well configured) somebody knows what is the problem?

Re: [squid-users] WCCP

2003-08-14 Thread Masood Ahmad Shah
it's not more than 100% :) I'm using it 90% so I think it must be typo error. -- Best Regs, Masood Ahmad Shah System Administrator ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ | * * * * * * * * * * * * * * * * * * * * * * * * | Fibre Net (Pvt) Ltd. Lahore, Pakistan | Tel:

Re: [squid-users] wb_group problem

2003-08-14 Thread Aleksandr Shcherbakov
Thank you. I'll try to solve this problem and then replay this list to finish this thread. - Original Message - From: Henrik Nordstrom [EMAIL PROTECTED] To: Aleksandr Shcherbakov [EMAIL PROTECTED] Cc: Henrik Nordstrom [EMAIL PROTECTED]; [EMAIL PROTECTED] Sent: Wednesday, August 13, 2003

RE: [squid-users] bungling my squid.conf for front-end-https=on, OWA

2003-08-14 Thread David Gibson
Glad I asked... ;) -Original Message- From: Henrik Nordstrom [mailto:[EMAIL PROTECTED] Sent: Wed 8/13/2003 2:32 AM To: David Gibson; [EMAIL PROTECTED] Cc: Subject:Re: [squid-users] bungling my squid.conf for front-end-https=on, OWA On Wednesday 13 August 2003 06.00,

Re: [squid-users] msblaster worm, squid wccp ?

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 20.25, Valentin Chopov wrote: Hi, According to the W32.Blaster.Worm technical details, it will start DoS attack to Windows Update Site after Aug 16, 2003 . If this DoS attack will be on port 80 what will happen with the squid running as a transparent proxy with

Re: [squid-users] Off Topic - Reconfiguration by a non-root user

2003-08-14 Thread Anthony M. Rasat
Linux permissions gives you headache, doesn't it? I can't help you with chmod and chown, they are supposed Linux guruz' job. However I can only suggest a trick. Perhaps all you need to simple crontab script. Let say you write a simple bash script which will do following : a. Check existance of

RE: [squid-users] Reconfiguration by a non-root user

2003-08-14 Thread Adam Aube
I want to give him right to edit the password file (for proxy_auth) and the IP address file (for ip_user_check).. So what I've done is to set operator's group to ... say squid. I also change both files to be edited to : squid, and make them writeable by squid group. Ok so far. And at last

Re: [squid-users] Re: Re: custom error messages

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 19.39, Norman Zhang wrote: But now I'm getting 2 signatures (the one I just created + default). May I ask how do I fix this? Did you read the section in the FAQ explaining when the default signature is added? -- Donations welcome if you consider my Free Squid

Re: [squid-users] Using ident or proxy_auth with cache_peer_access

2003-08-14 Thread Christopher Weimann
On Wed 08/13/2003-08:46:21AM +0200, Henrik Nordstrom wrote: Ident can not work in cache_peer_access. Perhaps this relates to my problem. I am trying to use ident to get the username. Then use that username to pick up a group from an external helper that pulls the info out of pgsql. I'm

Re: [squid-users] Using ident or proxy_auth with cache_peer_access

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 19.58, Christopher Weimann wrote: Perhaps this relates to my problem. I am trying to use ident to get the username. Then use that username to pick up a group from an external helper that pulls the info out of pgsql. I'm trying to use that group info for cache

Re: [squid-users] wb_group problem

2003-08-14 Thread Aleksandr Shcherbakov
wbinfo says: wbinfo -r username Could not get groups for user username wbinfo -r domain\username Could not get groups for user domain\username - Original Message - From: Henrik Nordstrom [EMAIL PROTECTED] To: ? [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Wednesday,

[squid-users] Squid 2.4 Stable 3, Novell LDAP SSL

2003-08-14 Thread Simon Magee
Hi, I am wanting to use Squid 2.4 Stable 3 (which I already have in place and working) I now want to be able to enable LDAP authentication (I have done this in a test environment) to our Novell Netware network, using SSL. I have seen various docs on the subject using stunnel etc. but was

Re: [squid-users] Re: problem with frames

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, Alex da Costa wrote: I found this at the repository... but my problem is about the MSIE. Suggestions: a) Don't use transparent proxying. b) Don't use transparent proxying. c) Don't use transparent proxying. d) See the Squid FAQ and squid.conf if your must use

Re: [squid-users] 2003/08/13 08:20:21| httpAccept: FD 15: accept failure: (24) Too many open files

2003-08-14 Thread Schelstraete Bart
Just increase the number of open files in your OS. (ulimit) rgrds, BArt Quoting Brian Hechinger [EMAIL PROTECTED]: i get a TON of these. had to restart squid. is this related to my other issue with Resource temporarily unavailable? is this the solaris ufs thing biting me in the

Re: [squid-users] 2003/08/13 08:20:21| httpAccept: FD 15: accept failure: (24) Too many open files

2003-08-14 Thread Adam
Brian so ulimit for filedescriptors on solaris defaults to 256 for non-root. is there a way to determine how many filedescriptors squid needs so that i can set a proper ulimit? Cachemgr.cgi's General Runtime page tells you how many you are currently using: File descriptor usage for

RE: [squid-users] bungling my squid.conf for front-end-https=on, OWA

2003-08-14 Thread David Gibson
Looks like squid doesn't like the virtual port in this version. [EMAIL PROTECTED] root]# squid -k reconfigure FATAL: Bungled squid.conf line 2061: httpd_accel_port virtual Squid Cache (Version 2.5.STABLE3): Terminated abnormally. Also, if this is true: when I add the cache_peer line, all proxy

Re: [squid-users] want to block downloads from kazza

2003-08-14 Thread Antony Stone
On Saturday 09 August 2003 11:24 am, ads squid wrote: Hi, 10 % of my total users continuously download from kazza. It has totally hampered speed of other users. What sort of files are they downloading? Can you block them by filetype, so that it doesn't matter where they get them from, they

[squid-users] Strange Log

2003-08-14 Thread Awie
All, In the upgrade progress, my Squid crashed (kernel panic) immediately after users starting to browse. Below I found a strange log. Thu Aug 7 16:10:10 2003.379 RELEASE -1 6BF7EAEC6EEDE0ABAB7063E887CF6E9E ? ? ? ? ?/? ?/? ? ? Thu Aug 7 16:10:10 2003.379 RELEASE -1

Re: [squid-users] CPU utilization performance issue

2003-08-14 Thread Schelstraete Bart
Adam Aube wrote: Can somebody explain to me why it's worth considering putting a Squid cache onto a Raid setup anyway? RAID isn't just for precious data - it's to keep a disk failure from taking down your system. Without RAID, if your cache disk crashed, so would Squid. Correct, We're

Re: [squid-users] fileupload restriction

2003-08-14 Thread Henrik Nordstrom
On Thursday 07 August 2003 15.21, Rohit Peyyeti wrote: Oh sorry, my mistake, here is what it is defined in my squid.conf which still does not work ;) Any output from squid -k parse? Regards Henrik -- Donations welcome if you consider my Free Squid support helpful.

Re: [squid-users] Stange Access Denied issue

2003-08-14 Thread Holger Schletz
Hi, In this particular case, it was obvbious. The services on my box are only litening on one interface. This puts up the need for distinct names for the two interfaces. We're getting off topic now... Bye, Holger Am Dienstag, 12. August 2003 21:42 schrieb Antony Stone: On Tuesday 12 August

Re: [squid-users] cache query when switching squid servers

2003-08-14 Thread Henrik Nordstrom
On Thursday 07 August 2003 05.08, Andrew Thomson wrote: I'm upgrading my squid proxy server and am curious if I can just tar up my squid cache directory and then untar it on the new server?? Yes, if you use the same L2 parameter on both (and L1 is/was sufficiently large). Not if you move

Re: [squid-users] CPU utilization performance issue

2003-08-14 Thread Tay Teck Wee
Hi everyone, thanks for the input. The ACL list have since been slightly altered, using only src(22 entries), dstdomain(114 entries) and url_regex(20 entries). I am currently on kernel 2.4.20-19.9 so the Hyperthreading might hv been optimized. Now the machine is handling about 110 req/s but

Re: [squid-users] Authneticating Windows NT/2000 users with squid

2003-08-14 Thread Henrik Nordstrom
On Monday 11 August 2003 13.04, [EMAIL PROTECTED] wrote: How can I authenticate windows NT/2000 domain users with squid. By using the NT domain as password database for Squid. Can squid be integrated to use Windows Authentication. Yes. See the Squid FAQ on how to set up winbind for one

[squid-users] always_direct help

2003-08-14 Thread Brian Hechinger
ok, here's the situation. i need to send an entire domain always_direct, which is easy enough, however there are exceptions. i'm not having any luck getting the exceptions setup. here is a config snippet: acl no_proxy dstdomain .penske.com acl force_out_ext dstdomain www.penske.com

Re: [squid-users] Direct conection to one site

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 18.57, Luiz C. Spies wrote: Hi i have my squid server working fine, but one of my clients have a site... with a problem the squid can cache this site, someone can tell me how i put this site to direct conection to pass ou squid? In squid.conf you cat at best tell

Re: [squid-users] Stange Access Denied issue

2003-08-14 Thread Henrik Nordstrom
On Monday 11 August 2003 16.45, Holger Schletz wrote: I have a problem with my Squid 2.5.STABLE1 (from my SuSE 8.2 distro). It works fine except when I try to access a local Apache Server on the same machine. Are you doing interception caching? If so, have you added rules which allows access

Re: [squid-users] Resource temporarily unavailable tests

2003-08-14 Thread Adam
Brian wrote: $ egrep -i storeAufsOpenDone cache.log | wc -l 408 If only 12 people are using this, perhaps 408 is a lot - I don't get that particular error so wouldn't know. Squid Cache: Version 2.5.STABLE1 configure options: --prefix=/usr/local --disable-dependency-tracking

Re: [squid-users] OS browser logging

2003-08-14 Thread Marc Elsen
Colin wrote: Hi, I installed Squid as a reverse proxy, it is important=20 for me and my clients to log the client browser and OS (sent in the http header) like in apache. Is this possible=20 in squid? if not will this feature be included in future versions?=20 Is there a program which

Re: [squid-users] Using null fs

2003-08-14 Thread Henrik Nordstrom
On Wednesday 06 August 2003 17.58, SSCR Internet Admin wrote: yeah thats true. but IMOP, using null fs and holding those object in RAM should give a better squid performance or maybe a good hit rate since squid functions the same way as having a null fs or having a big cache_dir except no IO

AW: [squid-users] logfileWrite: c:/squid/log/store.log: (13)Perm ission denied after storeDirWriteCleanLogs (Squid 2.5 on Windows2000)

2003-08-14 Thread Wagner Markus
There is a know problem in SquidNT: sometimes the UDP communication between squid.exe and pinger.exe fails to signal the shutdown to the helper and pinger.exe don't exit. The effect is that there are 2 pinger.exe running process and logfiles can be locked from the orphaned process. Killing

Re: [squid-users] how to calculate the number of threads needed

2003-08-14 Thread Henrik Nordstrom
On Tuesday 05 August 2003 18.53, Tay Teck Wee wrote: Hi, how do I derive the number of threads I should use for the async-io? Depends on the number of drives. More drives can utilize somewhat more I/O threads than a single drive.. -- Donations welcome if you consider my Free Squid support

Re: [squid-users] Top user's download speed show by real-timemonitoring

2003-08-14 Thread David Wilson
Hi Henrik, Thanks for your response. I currently use SARG for log file analysis, I'll configure it for each user. Do you think it would be possible to configure SNMP and MRTG to do the real-time stats for each user ? Does Squid's SNMP have a separate OID for each ACL (user) ? -- Many thanks

Re: [squid-users] application timeout

2003-08-14 Thread Henrik Nordstrom
On Wed, 6 Aug 2003, Rodney Green wrote: What do you mean by serious problems ? Any advice would be welcome. If tuning the pconn_timeout parameter up makes a difference for an application then the web server contacted is most likely broken and assumes one TCP connection == one user. This

Re: [squid-users] Top user's download speed show by real-timemonitoring

2003-08-14 Thread David Wilson
Hi Orlando, Thanks for your response. Yes SARG works great thanks, I've used it on numerous occasions. I think I've figured a way to configure it for each user. Thanks anyways. -- Many thanks and kind regards, David Wilson D c D a t a +27 33 3427003 http://www.dcdata.co.za [EMAIL

[squid-users] User Authentication using NCSA module.

2003-08-14 Thread ads squid
Hi, I want to use NCSA type user authentication. Looking for source code since FAQ says I need to compile and install one of the supplied authentication modules. I got squid-ncsa_auth-2.5.STABLE3-2.i586.rpms from web. I installed this rpm but still get following error after squid reconfigure.

[squid-users] SUMMARY [squid-users] always_direct dont work

2003-08-14 Thread Jordi Vidal
Hi Henrik, it worked! Thanks, no_cache deny acl do what I wanted. I had also to purge the object from the cache with client -m PURGE -p 8080 http://web.to.be.checked/; Followings request to the url are not cached now. Thanks also to Bart Schelstraete, Adam Aube and Siew Wing who

[squid-users] Http logging

2003-08-14 Thread Colin
Hi, I have installed squid as a reverse proxy. I need to log squid access in apache like logs. Is it possible to configure squid to do this or do I need an external program to create these logs? Thanks in advance, Colin

RE: [squid-users] Problems with the ncsa_auth

2003-08-14 Thread Adam Aube
I have RedHat 9, Squid-2.5.Stable1-2 working fine and now I decided to use user authentification with the ncsa module. I supose it might be a problem related with the password file, but can't guess what. All paths seem to be correct. Your settings look ok. Have you checked the permissions on

[squid-users] How to cycle thru a pool of IPs for outgoing traffic?

2003-08-14 Thread Andre Tomás
I have Squid running on a machine that has a class C network bound to it. I'd like Squid to randomly cycle thru the whole range of IPs for outgoing traffic. I found how to route traffic based on ACL but that's not exactly what I need. I simply need to randomly select an address out of a pool

Re: [squid-users] delay pools

2003-08-14 Thread Henrik Nordstrom
On Tuesday 05 August 2003 09.35, Jun Tanamal wrote: Hi, I just installed and configured squid with delay pools according to 'Bandwidth Limiting How-to' by Tomasz. I also configured it to be a transparent proxy. I have a running apache in the same machine. When I start squid, apache stops

[squid-users] Configuring multiple network card

2003-08-14 Thread Mathew Thomas
Hi, I am setting up a couple super squid proxy servers for the University. My servers have got multiple network cards. All the faculty proxy servers will use my proxy as the parent, and then my proxy server will fetch the pages from internet for the faculty proxy servers. There is no direct

RE: [squid-users] CPU utilization performance issue

2003-08-14 Thread Tay Teck Wee
Hi Nooshin, from what I've read, aufs are more suitable for linux while diskd are more for the other OSes. BTW I also have some lower spec machines(DELL 2450 dual pro 1GHz, 1G RAM) running their caching(squid2.4-stable7) disks on ext3 and their CPU utilization are only about 30% on 100 req/s in

[squid-users] Negative Byte Hit Ratio Caused by iCAP

2003-08-14 Thread Snowy
Hi, Henrik, It turns out that the bad negative byte hit ratio is due to the iCAP patch I have applied to Squid2.5-STABLE1. After disabling the iCAP module during the configuration and compilation, the byte hit ratio is normal now. However, it is still surprising because I did not enable iCAP in

RE: [squid-users] CPU utilization performance issue

2003-08-14 Thread Adam Aube
For caching disks:- in order of preference for performance 1)volume(best, unless your data REALLY critical, then go down the list) 2)raid 1(mirror, very costly) 3)raid 5 4)raid 0(i was surprised when i first heard it, can't quite remember the reason) How can RAID0 have worse performance than

Re: [squid-users] Using Mysql as external ACL with Squid 2.5 STABLE 3???

2003-08-14 Thread Jim_Brouse/PYT
I have used webmin with squid and when you apply changes it only takes a second and squid is not restarted but the changes are applied.I am not sure how that is done, does webmin use cachemgr.cgi? Jim

RE: [squid-users] How may I block MSN Messenger...

2003-08-14 Thread Adam Aube
1) Change this acl line: acl msn_server req_mime_type ^application/x-msn-messenger The ^ makes it match on the beginning of the line, which isn't what you want in this case. Remove the ^. Scratch that - I made the silly mistake of assuming that req_mime_type would match on the entire data;

RE: [squid-users] Winbind basic authentication problems with squi d

2003-08-14 Thread FWAdmin
Yeah, wbinfo does work. No, like I said I didn't specify the path. As seen in the logs Squid is still able to find the helper though. -Original Message- From: Henrik Nordstrom [mailto:[EMAIL PROTECTED] Sent: August 5, 2003 17:55 To: FWAdmin; [EMAIL PROTECTED] Subject: Re: [squid-users]

Re: [squid-users] CPU utilization performance issue

2003-08-14 Thread Schelstraete Bart
Hello Tay, I used both on my live server. Reiser - aufs/diskd Ext3 - aufs/diskd And I'm now using Reiser with Diskd. I swhitched with this a lot of times, because the disks are the reaaal bottleneck of my squid. It slows down the trafiic almost 4 times. Direct connection= 1,6mb/s , via

Re: [squid-users] security concern

2003-08-14 Thread Tay Teck Wee
Thanks Bart for pointing out that I should change the src code. Does anyone know which part of the src code I should change? --- Tay Teck Wee [EMAIL PROTECTED] wrote: Hi, I did a telnet to my squid port 8080 and input an invalid request n got the following reply(truncated):- HTTP/1.0

Re: [squid-users] Dial Access Server Squid

2003-08-14 Thread aqil
Pada 14-Aug-2003, aqil menulis: from the proxy), I still can surf internet from a dial access... Yes, I meant surfing internet is still not possible to do from a dialling client TIA Any shares and helps would be very appreciated Regards aqil

Re: [squid-users] [ Squid Cache: Version 3.0-PRE2-20030806 ] [ SSL]

2003-08-14 Thread Imad Soltani
Hello , i continu in the same problem , -- Error message : The requested URL could not be retrieved While trying to retrieve the URL: https://rev.host-160.201.tiscali-business.fr/ The following error was

RE: [squid-users] User Authentication using NCSA module.

2003-08-14 Thread Adam Aube
I have created password file. path /usr/local/squid/etc/passwd. tried to creat username and passowd by command [EMAIL PROTECTED] root]# htpasswd #8722;bd /usr/local/squid/etc/passwd xyz ads Gets following error. You used the wrong syntax running htpasswd. The output of the error message

[squid-users] smb_auth

2003-08-14 Thread Andy Dean
Hi I`m having problems with trying to get smb_auth to work the error i get is below slox:~ # smb_auth -W link51 -U 151.151.3.202 -S /software -d adean elizabeth Domain name: link51 Pass-through authentication: no Query address options: -U 151.151.3.202 -R Domain controller IP address: ERR any

Re: [squid-users] ACL to match arbitrary reply header,in-memoryfast authentication

2003-08-14 Thread Robert Collins
On Tue, 2003-08-05 at 16:20, Joshua Brindle wrote: hrm.. spawning 2 external processes per request when thousands of requests are going through is implausible.. You are misinformed about squids model for helpers. Processes are persistent and have requests piped to them. This is how squid scales

Re: [squid-users] Compile WCCP module optimally

2003-08-14 Thread Henrik Nordstrom
On Wednesday 13 August 2003 04.49, Awie wrote: Anyway, should I also active the IP GRE when I use WCCP (let say ip_wccp.o module already loaded by insmod)? NO. I become confuse, some documents explained to load WCCP and GRE together at the same time. But I agree with your email said that

[squid-users] Log files too large

2003-08-14 Thread Gator
I am finding that Squid (2.5.STABLE2) will fail when the log files reach a certain size. I moved them off to access.log.2 and store.log.2 and life was fine again. 1624135928 Aug 8 10:36 access.log.2 2147483647 Aug 8 09:02 store.log.2 How do I set up these files to rotate automatically so this

RE: [squid-users] smb_auth fixed nearly

2003-08-14 Thread Adam Aube
authenticate_program /usr/local/smb_auth -W link51 -U 151.151.3.202 -S /usr/local is an odd place to have the smb_auth binary. Run which smb_auth from the command line - is it in /usr/local, or somewhere else? If it's somewhere else, change your squid.conf and try it again. Also, what are the

Re: [squid-users] always_direct dont work

2003-08-14 Thread Jordi Vidal
Hi Bart, Thank you for your reply, but it doesnt work in my version of squid: # squid -k reconfigure 2003/08/11 20:01:58| parseConfigFile: line 1717 unrecognized: 'no-cache deny local-servers' Following the docs, what I want to do is done with the directive always_direct allow

Re: [squid-users] 2003/08/13 08:20:21| httpAccept: FD 15: accept failure: (24) Too many open files

2003-08-14 Thread Brian Hechinger
On Wed, Aug 13, 2003 at 08:23:31PM +0200, Henrik Nordstrom wrote: A reasonable amount is at least 3 * number of concurrent users. In ok, so we are only guessing, but there could be anywhere from 1000-2000 concurrent users during peak times. a limit of 6000 FDs would not be unreasonable then?

[squid-users] Re: always_direct help

2003-08-14 Thread Brian Hechinger
if i correctly understand the docs, always_direct is matched before never_direct, correct? so: always_direct .penske.com never_direct www.penske.com would match the always direct for www.penske.com, no? thanks!! -brian -- You know, evil comes in many forms, be it a man-eating cow or Joseph

RE: [squid-users] AD authentication

2003-08-14 Thread Tony Melia (DMS)
Be aware that winbind is subject to any account resatrictions that AD puts on that account. FOr example, if an account is set to change password on next logon, it will fail, it will also fail if the user's account has specific workstations set in the 'logon to' tab in account. To get around that

Re: [squid-users] deny files

2003-08-14 Thread aqil
Pada 13-Aug-2003, Paras pradhan menulis: DiD as: acl hello urlpath_regex .\exe$ http_access deny hello NO luck. what i am missing.?? what if you add -i ? And what if you try \.exe$ instead of .\exe$ ? Then for your case, try : acl hello urlpath_regex -i \.exe$ And at last, as Henrik told

[squid-users] deny_info and http_reply_access

2003-08-14 Thread Joshua Brindle
after trying to use deny_info with my http_reply_access acl and being unsuccessful i searched the web and found that others had that problem and that it was a known limitation. My question is, what kind of limitation is it? one where the code just hasn't been written or is it a design limitation?

Re: [squid-users] How to cycle thru a pool of IPs for outgoing traffic?

2003-08-14 Thread Schelstraete Bart
Andre Tomás wrote: I have Squid running on a machine that has a class C network bound to it. I'd like Squid to randomly cycle thru the whole range of IPs for outgoing traffic. I found how to route traffic based on ACL but that's not exactly what I need. I simply need to randomly select an address

[squid-users] Seperating request by type

2003-08-14 Thread Rully Budisatya
Hi, I have two squid proxy, let's say they're squid1 and squid2. All the users only access one proxy server which is squid1. I want to seperate the traffic depending on the type of document. I want all request which is text/html (not image or binary) always go direct without exception. And I

[squid-users] Failed to create unlinkd subprocess

2003-08-14 Thread Georg Bischof
Hi, i have a problem with squid on my linux box: 2003/08/12 17:46:15| With 1024 file descriptors available 2003/08/12 17:46:15| Performing DNS Tests... 2003/08/12 17:46:15| Successful DNS name lookup tests... 2003/08/12 17:46:15| DNS Socket created on FD 4 2003/08/12 17:46:15| Adding nameserver

Re: [squid-users] Resource temporarily unavailable tests=FROM_NAME_NO_SPACES version=2.31

2003-08-14 Thread Brian Hechinger
On Wed, Aug 06, 2003 at 12:07:19PM -0700, Adam wrote: I haven't a clue - I get a lot of storeAufsOpenDone: (#) No such file or directory errors (not at all the same as your error) but I do notice from my daily extract of errors/messages found in cache.log that the number varies roughly in

RE: [squid-users] Transparent authentication problem

2003-08-14 Thread Montervino, Mariano
Squid.conf auth_param ntlm program /usr/local/squid/libexec/wb_ntlmauth auth_param ntlm children 5 auth_param ntlm max_challenge_reuses 0 auth_param ntlm max_challenge_lifetime 2 minutes auth_param basic program /usr/local/squid/libexec/wb_auth auth_param basic children 5 auth_param basic realm

[squid-users] HTTP1.1 Pipelining...

2003-08-14 Thread Max Clements
What is the current status of HTTP 1.1 pipelining in Squid 2.5 - I cannot seem to find a definative status in the mailing list archives nor in the FAQ? Cheerio Max

[squid-users] authentication issues

2003-08-14 Thread Downing, Mark
I have been fighting with LDAP authentication for several days and now I need some help. I have finally figured out how to make the squid_ldap_auth work with an Active Directory tree that one of our divisions has setup. My problem is now how to I configure squid to work with BOTH msnt_auth and

Re: [squid-users] Squid3: vhost reverse proxy/accel bw extender

2003-08-14 Thread Jim Flowers
Yes, by definition name-based hosts use the same ip number but have different host.domain.tlds. If I use only one cache_peer line, how do I configure more than one name-based virtual host on the server with that ip address? -- Jim Flowers[EMAIL PROTECTED] -- Original Message

Re: [squid-users] want to block downloads from kazza

2003-08-14 Thread Henrik Nordstrom
On Saturday 09 August 2003 12.24, ads squid wrote: Hi, 10 % of my total users continuously download from kazza. It has totally hampered speed of other users. Are these using the Squid proxy? What shows up in access.log? acl SITE dstdomain KaZaA.com I think you want .kazaa.com there (note

Re: [squid-users] Compile WCCP module optimally

2003-08-14 Thread Henrik Nordstrom
On Thu, 14 Aug 2003, Awie wrote: Ahh so clear ! Thanks Henrik. I still wonder which document says both ip_wccp and ip_gre should be loaded at the same time. Regards Henrik

RE: [squid-users] Reverse proxy problem

2003-08-14 Thread Niti Lohwithee
Dear ALL. Additional information, when I access the web access the webmail . The messages.log display that WARNING: Forwarding loop detected for: GET / HTTP/1.0^M Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, appli cation/vnd.ms-excel, application/vnd.ms-powerpoint,

Re: [squid-users] always_direct dont work

2003-08-14 Thread Siew Wing Loon
Hi Jordi, Try to use this iptables rules: - $IPTABLES -t nat -A PREROUTING -i $DEV -p tcp ! -s $NAGIOS --dport 80 -j REDIRECT --to-port 3128 Regards, Siew --- Jordi Vidal [EMAIL PROTECTED] wrote: Hi, I'm trying to setup a rule to avoid Nagios from fetching web pages from the cache

  1   2   3   >