[squid-users] delay_pools not working

2004-07-28 Thread babar haq
Hi I have been using these settings for delay pools for quiet some time. one day i wake up and i find out that the band width restriction is just not working. here is wat i have in my squid.conf and i am running a lan of 192.168.0.0 network. acl comcept src 192.168.0.0/255.255.255.0 acl notwebpa

[squid-users] Establishing a second squid

2004-07-28 Thread Majunke, Mike
Hi, I'm trying to establish a second squid in our company lan. The first one is doing fine, but the new one is probably not able to forward the requests given to him. I receive the following message: The following error was encountered: * Unable to forward this req

[squid-users] Only show URL's in access.log

2004-07-28 Thread John
Hi, Hope somebody can point me in the right direction on this one. In the access.log file it shows every item that has been requested by a user (gifs, jpegs etc.). Is it possible to set logging so that all you see in the access log is the URL that the user requested an not every file that is downl

[squid-users] mod_gzip support

2004-07-28 Thread Rakhmat Farunuddin
hi all i have one web server running mod_gzip support, when i direct my connection to this webserver, i have my browser compress enabled, but when i use squid, my browser became not enabled data compress from the webserver is there any directive that i have to add in squid.conf -- Thanks, Rak

[squid-users] Problem: Squid3 accelerator does not cache

2004-07-28 Thread Petri Välisuo
I would like to know why my SQUID3 installation does not cache anything while configured as a http accelerator. I am trying to use squid-3.0-PRE3 as a http-accelerator, using http_port configuration: http_port 10.10.1.39:80 vhost defaultsite=10.10.3.46 It seems that all accesses are denied, u

[squid-users] problem with smb_auth! squid goes wild...

2004-07-28 Thread Luís Miguel Silva
Hello list, I just tried to configure my squid to auth against a SMB domain server. So, i added the following 3 lines: authenticate_program /usr/lib/squid/smb_auth -W ISPGAYA -U 192.168.4.140 acl users proxy_auth REQUIRED http_access allow users [Being ISPGAYA our domain and 192.168.4.140 our AU

RE: [squid-users] Establishing a second squid

2004-07-28 Thread Elsen Marc
> Hi, > > I'm trying to establish a second squid in our company lan. > The first one > is doing fine, but the new one is probably not able to forward the > requests given to him. > > I receive the following message: > > The following error was encountered: > * Unab

RE: [squid-users] Only show URL's in access.log

2004-07-28 Thread Elsen Marc
> > Hi, > > Hope somebody can point me in the right direction on this one. In the > access.log file it shows every item that has been requested > by a user (gifs, > jpegs etc.). Is it possible to set logging so that all you > see in the access > log is the URL that the user requested an not

RE: [squid-users] mod_gzip support

2004-07-28 Thread Elsen Marc
> > > hi all > > i have one web server running mod_gzip support, when i direct my > connection to this webserver, i have my browser compress enabled, > but when i use squid, my browser became not enabled data compress from > the webserver > > is there any directive that i have to add in squi

[squid-users] Check for used replacement policy

2004-07-28 Thread Altrock, Jens
Hi there, again me :) Just a short question (haven't found an answer to this yet): Is there a way to check if squid really uses the values for cache_replacement_policy and memory_replacement_policy? Regards, Jens ### Diese Nachricht wurde von F-Secure Ant

Re: [squid-users] Only show URL's in access.log

2004-07-28 Thread Raymond A. Meijer
On Wed 28 July 2004 15:20, Elsen Marc wrote: > > Is it possible to set logging so that all you > > see in the access > > log is the URL that the user requested an not every file that > > is downloaded > > with it? >http://foo.com/dog.gif > >is< an URL. Don't understand your question comp

AW: [squid-users] Only show URL's in access.log

2004-07-28 Thread Altrock, Jens
He wants to know if it is possible to just keep the visited URL, not all of the contents logged; for example you visit http://foo.com and he does not want the http://foo.com/dog.gif to appear in the access.log, so that not all files belonging to that site are shown in the log. hope that's right J

RE: [squid-users] ldap auth testing

2004-07-28 Thread Rick Whitley
I got ldapsearch to work. I used the -x option to use a simple bind. Amazing how much you find out when you read "all" the options instead of stopping at the first one you need. Thanks for all the responses. Now I know that squid can communicate with ldap, but I still can't get a response from squi

[squid-users] Strange Memory Usage...

2004-07-28 Thread Altrock, Jens
Again... once more. I am playing around with squid config though atm, and got a strange phenomena (maybe just strange to me). When looking at the cache.log file I see the following: Maximum Resident Size: 0 KB Page faults with physical i/o: 356 Memory usage for squid via mallinfo(): total

RE: [squid-users] can i use SQUID for Caching Only..

2004-07-28 Thread Chris Perreault
1) no, can't 2) cache_peer In question 1 you state you don't want to proxy and in question 2 you ask how to pass requests to your apache proxy box. The definition of a proxy is something that performs a function on behalf of someone else. "pass requests at the squid boxto proxy box" *is* pro

RE: [squid-users] Only show URL's in access.log

2004-07-28 Thread Elsen Marc
> > > He wants to know if it is possible to just keep the > visited URL, not all of the contents logged; for example > you visit http://foo.com and he does not want the > http://foo.com/dog.gif to appear in the access.log, so that > not all files belonging to that site are shown in the log. >

Re: [squid-users] Fw: Re: Re: Re: More NTLM Problems

2004-07-28 Thread Tim Neto
Could this be a iptables (lokkit) issue? The access denied could be a clue. Try stripping all control ACLs from your squid.conf file. Run Squid as just an open proxy relay for a moment to test. See if Squid is the "access" denied or is there another service in the OS causing the access denied

Re: [squid-users] ldap auth testing

2004-07-28 Thread Tim Neto
A little trick not in the man pages or the docs. When testing squid_ldap_auth or squid_ldap_group from the unix (Linux) shell, you must pipe the username and password information into the program. This is what Squid itself does. This stumped me for a bit early on. echo " " | squid_ldap_auth

RE: [squid-users] Establishing a second squid

2004-07-28 Thread Majunke, Mike
I am using the cache_peer_access command. cache_peer_access 194.25.57.61 allowACLNAME1 ACLNAME2 cache_peer_access 194.25.60.201 allow ACLNAME3 cache_peer_access 194.25.60.201 allow !ACLNAME1 !ACLNAME2 It seems as if the proxy is trying to verify the url (e.g.

RE: [squid-users] Check for used replacement policy

2004-07-28 Thread Elsen Marc
> > Hi there, again me :) > Just a short question (haven't found an answer to this yet): > Is there a way to check if squid really uses the values for > cache_replacement_policy and > memory_replacement_policy? > Cachemgr -> Store Directory Stats Although the info seems 'partial' M.

Re: [squid-users] Only show URL's in access.log

2004-07-28 Thread John
Hi Marc, Yes you are absolutely spot on with your description. Regards John - Original Message - From: "Elsen Marc" <[EMAIL PROTECTED]> To: "Altrock, Jens" <[EMAIL PROTECTED]> Cc: "Squid-Users Mailing List (E-Mail)" <[EMAIL PROTECTED]> Sent: Wednesday, July 28, 2004 1:41 PM Subject: RE:

[squid-users] squid headers control

2004-07-28 Thread איל לוי
Hello. I have some squids as web accelerators for my web site, And I would like to improve the pages upload by controlling the http headers from the squid. Does anyone know a way to control the headers sending from the Squid to users? (I can't use "header_replace" because I need different heade

RE: [squid-users] Establishing a second squid

2004-07-28 Thread Elsen Marc
> I am using the cache_peer_access command. > > > cache_peer_access 194.25.57.61 allowACLNAME1 ACLNAME2 > cache_peer_access 194.25.60.201 allow ACLNAME3 > cache_peer_access 194.25.60.201 allow !ACLNAME1 !ACLNAME2 > > It seems as if the proxy is trying to verify

RE: [squid-users] Squid HTTP headers

2004-07-28 Thread איל לוי
I was hopping for better answer :) Massing with the bits and bites was my last option. Is there a program for such as squirm (for redirect) that control the headers. Eyal -Original Message- From: Henrik Nordstrom [mailto:[EMAIL PROTECTED] Sent: Monday, July 26, 2004 8:42 AM Cc: [EMAIL P

Re: [squid-users] ldap auth testing

2004-07-28 Thread Rick Whitley
Thanks for the tip, but I can't seem to make it work. I know that the id and password are correct because I use them from another system (radius) to authenticate via ldap. Here is what I am getting: proxy2:echo "ctdlaptop f0ulb3ast" | /usr/local/squid/libexec/squid_ldap_auth -b "ou=academics,o=dbu

RE: [squid-users] ldap auth testing

2004-07-28 Thread Chris Perreault
I typed the username password at the command prompt after running the options. It was a little confusing, as was adding in the -x, because the -x wasn't needed in ldapsearch queries. As Rick found, reading the docs helped. Chris -Original Message- From: Tim Neto [mailto:[EMAIL PROTECTED]

Re: [squid-users] Only show URL's in access.log

2004-07-28 Thread John
Hi Ray, Yes you are right - just the http://www.foo.com and not all the associated http://www.foo.com/image.dif etc. associated with the site. Is it possible to screen these out of the access log and just have the web page as requested by the user appear in the log? Regards John - Original M

Re: [squid-users] Fw: Re: Re: Re: More NTLM Problems

2004-07-28 Thread Johnny Doe
I'm not sure if this is right but this is what my squid.conf looks like. Let me know what you want me to do with it. Thanks hierarchy_stoplist cgi-bin ? acl QUERY urlpath_regex cgi-bin \? no_cache deny QUERY auth_param basic children 5 auth_param basic realm Squid proxy-caching web server auth_p

[squid-users] Issue with IIS Integrated Authentication

2004-07-28 Thread McDonald, Rob
I have a box setup with Squid 2.5 STABLE and Dansguardian 2.6.1-3. I have Squid setup for transparent proxying..and I am redirecting all 80 traffic to it in the DMZ via my openbsd 3.5 fw. We have an outside website that is IIS 6..and the SharePoint website uses windows integrated authentication.

Re: [squid-users] ldap auth testing

2004-07-28 Thread Tim Neto
Hello Rick, I went back and double checked my notes. squid_ldap_auth expect the following input. echo "userPassword: " | /squid_ldap_auth -h -p -P -b -f "uid=" You may have other options for squid_ldap_auth than what I use. Like "-x" for example. This should help though. Tim -

[squid-users] Forbidden error

2004-07-28 Thread Bhat, Satish
Hi, I've setup squid something like this: browser -> squid-1 (as edge sever) -> IIS server -> squid-2 -> app server(tomcat). When I send some requests from browser, I get a '403-Forbidden' error from the 'App server'! If I don't connect the edge server, squid-1, then everything is f

RE: [squid-users] Issue with IIS Integrated Authentication

2004-07-28 Thread Wayne . Fielder
Hey Rob, I'm having something of a similiar problem although there are no firewalls or anything inbetween my squid and my webserver. This server normally(sans squid) prompts for userid/password and lets you right in. Running through squid you get prompted for every GET. I'm sure there's

RE: [squid-users] RE: User with Chinese LDAP CN does not work

2004-07-28 Thread Henrik Nordstrom
On Wed, 28 Jul 2004, Huang, David wrote: > user filter '(&(sAMAccountName=yke0155)(objectclass=user))', searchbase > 'dc=mtuzhuhai,dc=com' > attempting to bind to user 'CN=???,OU=IT,DC=mtuzhuhai,DC=com' > ERR Ok. so the search of the users DN works just fine, but then it can not bind to this DN

RE: [squid-users] Squid HTTP headers

2004-07-28 Thread Henrik Nordstrom
On Wed, 28 Jul 2004, [utf-8] איל לוי wrote: > I was hopping for better answer :) > Massing with the bits and bites was my last option. > Is there a program for such as squirm (for redirect) that control the headers. There is no existing interface to Squid where an external program can modify the

Re: [squid-users] Fw: Re: Re: Re: More NTLM Problems

2004-07-28 Thread Johnny Doe
Just a update. I finally got it to work. My problem was in the acl's. I am now trying to get squid to work with dansguardian with ntlm auth. Thanks for all the help. If anybody has any pointers on getting dansguardian to work with ntlm let me know. Thanks alot!!! --- Tim Neto <[EMAIL PROTECTED

[squid-users] 2 second pause with forwarded_for off

2004-07-28 Thread Steven Rice
Hello, I'm experincing a 2 seconds pause when forwarded_for is turned off as show in the ethereal output below. I don't want internal address to be passed, so how do I disable forwarded_for without experincing this delay? Thanks, --- 0.323465 205.152.0.20 -> 66.

RE: [squid-users] Squid HTTP headers

2004-07-28 Thread Chris Perreault
Stay tuned...We are contracting The Linux Box to do just this. Work started on it today. Why? Our scenario for squid is in a reverse proxy mode. We have multiple back end servers, which we are making look like one big server. Ie: inside.ourcompany.com/app1 points to the app1 internal webserver.

[squid-users] Re: Issue with IIS Integrated Authentication

2004-07-28 Thread Adam Aube
McDonald, Rob wrote: > I have a box setup with Squid 2.5 STABLE and Dansguardian 2.6.1-3. > > I have Squid setup for transparent proxying..and I am redirecting all 80 > traffic to it in the DMZ via my openbsd 3.5 fw. > > We have an outside website that is IIS 6..and the SharePoint website uses >

RE: [squid-users] Re: Issue with IIS Integrated Authentication

2004-07-28 Thread Wayne . Fielder
Okay...so MS Integrated Authentication can't be proxied. Nit picking question, if I'm not caching anything(only using squid for logging), does your statement still apply? -Original Message- From: Adam Aube [mailto:[EMAIL PROTECTED] Sent: Wednesday, July 28, 2004 2:54 PM To: [EMAIL PROTECT

Re: [squid-users] caching specific sites

2004-07-28 Thread Muthukumar
>> We can do caching or non-caching of objects in a fixed manner > Who is 'we' ? I did not get ur(marc) question!? Regards, Muthukumar. --- === It is a "Virus Free Mail" === Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.718 / Virus Databas

Re: [squid-users] USERS WITH MAC

2004-07-28 Thread Muthukumar
> > i want to make ACL in which users access via there > > MAC address (not IP > > address) and user name and password. You have to compile the squid with -enable-arp-acl. If you successfully compile the squid,then you are having the capability of doing arp based acl setup. Refer: http://www.squ

[squid-users] RE: Re: Issue with IIS Integrated Authentication

2004-07-28 Thread Adam Aube
[EMAIL PROTECTED] wrote: > Okay...so MS Integrated Authentication can't be proxied. Nit picking > question, if I'm not caching anything(only using squid for logging), does > your statement still apply? Yes - you are still proxying, even if you aren't caching. Adam

[squid-users] Re: 2 second pause with forwarded_for off

2004-07-28 Thread Adam Aube
Steven Rice wrote: > I'm experincing a 2 seconds pause when forwarded_for is turned off as show > in the ethereal output below. > 0.323465 205.152.0.20 -> 66.135.202.135 HTTP GET > /ws/ebayISAPI.dll?MyeBay > HTTP/1.0 > 0.465554 66.135.202.135 -> 205.152.0.20 TCP http > 44968 [ACK] Seq=1 >

RE: [squid-users] Forbidden error

2004-07-28 Thread Elsen Marc
> > Hi, > I've setup squid something like this: > browser -> squid-1 (as edge sever) -> IIS server -> squid-2 -> > app server(tomcat). > > When I send some requests from browser, I get a > '403-Forbidden' error > from the 'App server'! > If I don't connect the edge server, squid

[squid-users] squid and outlook express problem

2004-07-28 Thread Anuradha Kalyan
Hi, Sorry for asking a well known question. My squid configuration seems to be fine. but the outlook express at client machine is not working. My configuration: eth0: 192.168.1.97 (My Public IP) eth1: 192.168.5.1 (My Lan IP) I have declared 25 and 110 as the safe ports also but still :(( Base

RE: [squid-users] squid and outlook express problem

2004-07-28 Thread Elsen Marc
> Hi, > > Sorry for asking a well known question. My squid > configuration seems to be fine. but the outlook express at > client machine is not working. > > My configuration: > > eth0: 192.168.1.97 (My Public IP) > eth1: 192.168.5.1 (My Lan IP) > > I have declared 25 and 110 as the safe po