[squid-users] Object expiry

2004-10-20 Thread BusyBoy
Hello, Can we make the squid to maintain a level of cache upto 75% of HDD's or for every cache partition. My squid servers are getting overloaded with cache and I have to remove all the cache after some time. Regards, -- Nasir Mahmood Systems + Network Admin. Asia Net.

Re: [squid-users] Help for forward lookup of IP

2004-10-20 Thread Nilesh
not working dstdomain could please tell me in example --- Henrik Nordstrom [EMAIL PROTECTED] wrote: On Tue, 19 Oct 2004, Nilesh wrote: Thanks for your great help, now I am able to block messengers and sites by ACL url_regex also able to open for some users but the problem is if any one

RE: [squid-users] Object expiry

2004-10-20 Thread Elsen Marc
Hello, Can we make the squid to maintain a level of cache upto 75% of HDD's or for every cache partition. Check 'cache_swap_low' and 'cache_swap_high' directives in squid.conf.default (read the relevant comments) My squid servers are getting overloaded with cache and I have to

[squid-users] Bypassing Squid for local address destination

2004-10-20 Thread oke
Hello squid-users, I want all requests from (local) my clients to be directly forwarded to the destination, in case of local destination, in order to minimize SQUID's load. Can anybody tell me how to configure SQUID for such purpose ? -- Best regards, oke

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread oke
Hello Elsen, Wednesday, October 20, 2004, 2:49:47 PM, you wrote: EM You can't once a request is 'in' SQUID; squid has to EM deal with it. really ? I have my access.log to become very big!! How at least to overcome this problem ? EM You have to solve this at the client side. By proxy conf.

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Elsen Marc
Hello Elsen, Wednesday, October 20, 2004, 2:49:47 PM, you wrote: EM You can't once a request is 'in' SQUID; squid has to EM deal with it. really ? I have my access.log to become very big!! How at least to overcome this problem ? Use : squid -k rotate at regular times

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread apmailist
EM You can't once a request is 'in' SQUID; squid has to EM deal with it. really ? I have my access.log to become very big!! How at least to overcome this problem ? You could rotate logs more frequently. and maybe use a script to compress older logs in the same move. EM You have to

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Elsen Marc
... and always_direct allow intranet no_cache deny intranet Your contribution is confusing in the sense that these directives have no relation whatsoever. 'always_direct' tells SQUID what to do in case cache_peers are being used. It bares no result either for the users original

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread oke
Hello Elsen, Wednesday, October 20, 2004, 3:04:13 PM, you wrote: EM You can't once a request is 'in' SQUID; squid has to EM deal with it. really ? I have my access.log to become very big!! How at least to overcome this problem ? EM Use : EM squid -k rotate I am already rotating

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread apmailist
... and always_direct allow intranet no_cache deny intranet Your contribution is confusing in the sense that these directives have no relation whatsoever. 'always_direct' tells SQUID what to do in case cache_peers are being used. It bares no result either for the users

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Muthukumar
I want all requests from (local) my clients to be directly forwarded to the destination, in case of local destination, in order to minimize SQUID's load. Can anybody tell me how to configure SQUID for such purpose ? To redirect all local requests to their corresponding domain then,

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Elsen Marc
... ... Have I mistaken local servers for , say, intranet servers ? What you are telling me, is that : If I don't use cache peers, then I don't need this directive ? Yes, you don't need it. M.

Re: AW: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread oke
Hello Werner, Wednesday, October 20, 2004, 3:39:37 PM, you wrote: [EMAIL PROTECTED] etc]# ls -l /var/logs/access.log.1 -rw-r--r--1 nobody root 418721213 Oct 19 00:00 /var/logs/access.log.1 WRzc That is very big, indeed. Did you look into the file? Maybe a virus or WRzc spyware

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread oke
Hello Elsen, Wednesday, October 20, 2004, 3:24:29 PM, you wrote: EM As another user just suggested : EM Checkout the 'no_cache' directive. done. I will check out my coming access.log if things are solved :) EM Don't confuse with always_direct and never_direct these are not related EM

[squid-users] Reading about Auth LDAP in Squid 2.5

2004-10-20 Thread Lars D. Noodn
I've installed squid-2.5.STABLE7 and have started getting used to it. I noticed on the group-ldap-auth project page at Sourceforge, it mentioned that squid 2.5 shuold have this capability built in. Is this so? If so where can I find uptodate documentation on ldap-auth in squid 2.5+? Any URLs

Re: [squid-users] How to forward the client IP from Netscape Proxy3.5 to squid proxy???

2004-10-20 Thread Martin Altmann
Hmm, maybe we are too dumb but we get a core dumped when trying to add that rule and restart Squid. We tried any of those (whereas the ip is just an example and Client-ip is the name of the header used in the NS Proxyserver): acl special-ip-address req_header Client-ip 123\.123\.123\.123 acl

Re: [squid-users] Help for forward lookup of IP

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Nilesh wrote: not working dstdomain could please tell me in example There is plenty of examples both in the FAQ, Users Guide and elsewhere. Show us what you have tried, and we'll correct it for you. Regards Henrik

Re: [squid-users] Help for forward lookup of IP

2004-10-20 Thread Kashif Ali Bukhari
yes it is correct On Wed, 20 Oct 2004 00:16:15 -0700 (PDT), Nilesh [EMAIL PROTECTED] wrote: Thanks for reply But I am not able to block yeah I tried dstdomain but not working acl blockweb dstdomain .yahoo.com http_access deny blockweb Is this correct? please let me know Thanks

RE: [squid-users] SQuid + AD

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Billy Kotlaroff wrote: Thanks for your help guys, So this squid_ldap_auth manual. Is this available from a certain URL? It is shipped as part of the distribution, installed when you install squid_ldap_auth. man -M /usr/local/squid/man squid_ldap_auth or cd

[squid-users] How many users single squid can support

2004-10-20 Thread Arvind Kumar Gupta
I have P4 1.5 GHz with 128 MB allocated to Squid and around 2GB disk space for cache. My question is how many concurrent users can squid support? Although memory allocated is 128 MB but it grows to 200MB. TIA, Arvind Hardwar, India

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004 [EMAIL PROTECTED] wrote: # TAG: always_direct # Usage: always_direct allow|deny [!]aclname ... # # Here you can use ACL elements to specify requests which should # ALWAYS be forwarded directly to origin servers. For example, # to always directly

Re: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, oke wrote: EM Checkout the 'no_cache' directive. done. I will check out my coming access.log if things are solved :) no_cache does not stop things from being proxied and logged by Squid, it only stops Squid from caching the reply and reusing the same reply in a later

Re: [squid-users] Object expiry

2004-10-20 Thread Kashif Ali Bukhari
http://www.squid-cache.org/Doc/FAQ/FAQ-4.html#ss4.14 see the faq in cache dir and then configur cache directories On Wed, 20 Oct 2004 12:15:52 +0500, BusyBoy [EMAIL PROTECTED] wrote: Hello, Can we make the squid to maintain a level of cache upto 75% of HDD's or for every cache partition.

Re: AW: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, oke wrote: Can you tell me which pattern to grep to checkout existence of virus or spyware? A common sign is lots of request for random IP addresses, or very high failure ratio (TCP_MISS/5XX or TCP_MISS/404) Regards Henrik

RE: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread apmailist
Have I mistaken local servers for , say, intranet servers ? No, but you have mistaken the context of the comment. The context of the comment is what Squid should do with the request once th client has sent the request to Squid, not what clients should do with the request. This is the

Re: AW: [squid-users] Bypassing Squid for local address destination

2004-10-20 Thread apmailist
Quoting Henrik Nordstrom [EMAIL PROTECTED]: On Wed, 20 Oct 2004, oke wrote: Can you tell me which pattern to grep to checkout existence of virus or spyware? A common sign is lots of request for random IP addresses, or very high failure ratio (TCP_MISS/5XX or TCP_MISS/404) Regards

RE: [squid-users] Connection timed out

2004-10-20 Thread Elsen Marc
Dear all, I am facing problem of connection timeout what could be the reason. Opening http://groups.yahoo.com/ gives me below error. From the start i have this option. echo 0 /proc/sys/net/ipv4/tcp_ecn ERROR The requested URL could not be retrieved while trying to

RE: [squid-users] Connection timed out

2004-10-20 Thread Joel n.solanki
Hi all, I cant ping groups.yahoo.com from squid box. But according to u it seems pinging. Yes i can ping www.yahoo.com But i have my other ips directly connected to router. from that ip also i cant ping groups.yahoo.com I can easily open groups.yahoo.com from that ip connected from router. But

[squid-users] store.log

2004-10-20 Thread Varun
Hello, What is function of store.log file. It has become to big in size. /var is getting short of space. I cannot resinstall now. Thanks Varun

[squid-users] Odd redirect? denied.

2004-10-20 Thread Wyatt, Jon
Hi, We're having a problems with a strange URL and I'd wonder if anyone can help. This is the URL. https://www.btwholesale.com:8443/bbtcr/login.jsp?serverURL=http://reportserv er.nat.bt.com:8000 And this is the error message that's produced. TCP_DENIED/403 1004 CONNECT www.btwholesale.com:8443

RE: [squid-users] Connection timed out

2004-10-20 Thread Elsen Marc
Hi all, I cant ping groups.yahoo.com from squid box. But according to u it seems pinging. Yes i can ping www.yahoo.com But i have my other ips directly connected to router. from that ip also i cant ping groups.yahoo.com I can easily open groups.yahoo.com from that ip connected from

Re: [squid-users] store.log

2004-10-20 Thread Muthukumar
What is function of store.log file. It will tell what objects with size are stored in squid cache directory. See more on squid.conf.default file cache_store_log TAG. It has become to big in size. /var is getting short of space. It is good to make cache_store_log none there in

RE: [squid-users] store.log

2004-10-20 Thread Elsen Marc
Hello, What is function of store.log file. It has become to big in size. /var is getting short of space. I cannot resinstall now. store.log is a record of Squid's decisions to store and remove objects from the cache. Use : % squid -k rotate

RE: [squid-users] Odd redirect? denied.

2004-10-20 Thread Elsen Marc
Hi, We're having a problems with a strange URL and I'd wonder if anyone can help. This is the URL. https://www.btwholesale.com:8443/bbtcr/login.jsp?serverURL=htt p://reportserv er.nat.bt.com:8000 And this is the error message that's produced. TCP_DENIED/403 1004 CONNECT

[squid-users] Problems with Authenticator

2004-10-20 Thread Udo Pokojski
Hello, I am trying develop an authticator for basic authentication. According to the documentation, the authenticator returns OK if the user has authenticated himself. If the authentication fails, the authenticator returns ERR. My first try is this dummy-authenticator: #include stdio.h char

[squid-users] Which log analyzer to use with emulate_httpd_log on?

2004-10-20 Thread Mark Hellman
For some strange reason, usernames are not being logged in the ident column of my access.log. But when I switch emulate_httpd_log on, usernames are logged... Maybe this has something to do with the fact I am using mysql_auth authenticator module. I don't mind using emulate_httpd_log only if there

RE: [squid-users] Odd redirect? denied.

2004-10-20 Thread Wyatt, Jon
-Original Message- From: Elsen Marc [mailto:[EMAIL PROTECTED] Sent: 20 October 2004 12:39 To: Wyatt, Jon; [EMAIL PROTECTED] Subject: RE: [squid-users] Odd redirect? denied. It works here for the complete url, through SQUID and I get the login page.

RE: [squid-users] Odd redirect? denied.

2004-10-20 Thread Elsen Marc
Yes. Must be something else in our configuration which is causing the problem then. How odd. Yes , because the 407 TCP_DENIED means that SQUID does not allow the request. Check acl blocking e.d. Perhaps the site is accidently blocked in your SQUID acl,http_access,...

Re: [squid-users] Problems with Authenticator

2004-10-20 Thread Muthukumar
has authenticated himself. If the authentication fails, the authenticator returns ERR. It is correct. My first try is this dummy-authenticator: When I use this authenticator, I am prompted for a username and password. After authenticating with any username and password, the proxy says:

RE: [squid-users] Connection timed out

2004-10-20 Thread Joel n.solanki
Hi, Thanks...I atlast found that something is wrong with my ip. Yahoo have blocked access to groups.yahoo.com to my squid ip. I cant telnet on groups.yahoo.com 80 but with other ip i can do it. I even cross checked my firewall setting but all things are ok. Problem is from yahoo side. So i need

Re: [squid-users] Multiple http servers behind a single squid

2004-10-20 Thread Jim Nachlin
Henrik Nordstrom wrote: On Tue, 19 Oct 2004, Jim Nachlin wrote: This now works, using an entry in the proxy machine's hosts file for each one of the web servers behind the proxy. Thanks again. Now, if I want to run the servers behind the proxy on a different port (not port 80), is there a way

[squid-users] need to cache a soap service

2004-10-20 Thread Ferrarese Leopoldo
Hi, hi need to cache a soap service to reduce the load averege, but I'm not able to cache. When I call the page in the access.log I read very time the MISS... How I can force squid to cache the soap service? thank you very much, Leopoldo Ferrarese

[squid-users] Cacheing CGI pages and the Expires and Last-modified headers

2004-10-20 Thread Jim Nachlin
Hi, I know that this has been covered here quite a bit, but I'm having trouble getting squid to cache a dynamiacally generated page. The idea is to limit the number of times a dynamically generated page gets regenerated. I have a test page generated by this CGI:

[squid-users] High CPU usage

2004-10-20 Thread Russ Uhte
I've done a lot of reading, and I can't seem to figure out what's going on. OS FreeBSD 4.10-RELEASE-p2. Squid is Version 2.5.STABLE6. There are 4 15k 18GB drives being used for the cache. It has a 3.0 GHz HT Intel processor, and 2 GB of RAM. This install has been running since Monday. I

[squid-users] Squid being slow at some points

2004-10-20 Thread Bruno Lopes de Souza Benchimol
Ok, here is my problem, my squid runs extremely slow in this situation: When I open any yahoo page (yahoo.com.br or yahoo.com, doesn't matter), its works fine. I join webmail, its still fast. But once I click on Compose, its takes me over a minute to open it up, but other

Re: [squid-users] High CPU usage

2004-10-20 Thread Russ Uhte
Russ Uhte wrote: I've done a lot of reading, and I can't seem to figure out what's going on. OS FreeBSD 4.10-RELEASE-p2. Squid is Version 2.5.STABLE6. There are 4 15k 18GB drives being used for the cache. It has a 3.0 GHz HT Intel processor, and 2 GB of RAM. This install has been running

Re: [squid-users] How to forward the client IP from Netscape Proxy3.5 to squid proxy???

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Martin Altmann wrote: Hmm, maybe we are too dumb but we get a core dumped when trying to add that rule and restart Squid. We tried any of those (whereas the ip is just an example and Client-ip is the name of the header used in the NS Proxyserver): acl special-ip-address

RE: [squid-users] Connection timed out

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Joel n.solanki wrote: But i have my other ips directly connected to router. from that ip also i cant ping groups.yahoo.com I can easily open groups.yahoo.com from that ip connected from router. But i cant open groups.yahoo.com from the ip connected to squid box. Most likely

RE: [squid-users] SQuid + AD

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Henrik Nordstrom wrote: On Wed, 20 Oct 2004, Billy Kotlaroff wrote: Thanks for your help guys, So this squid_ldap_auth manual. Is this available from a certain URL? It is shipped as part of the distribution, installed when you install squid_ldap_auth. man -M

Re: [squid-users] Odd redirect? denied.

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Wyatt, Jon wrote: Hi, We're having a problems with a strange URL and I'd wonder if anyone can help. This is the URL. https://www.btwholesale.com:8443/bbtcr/login.jsp?serverURL=http://reportserv er.nat.bt.com:8000 You need to add port 8443 to both Safe_ports and SSL_ports.

Re: [squid-users] need to cache a soap service

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Ferrarese Leopoldo wrote: hi need to cache a soap service to reduce the load averege, but I'm not able to cache. When I call the page in the access.log I read very time the MISS... See the cacheability check engine to diagnose why. How I can force squid to cache the soap

Re: [squid-users] Cacheing CGI pages and the Expires and Last-modified headers

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Jim Nachlin wrote: If I tail the /tmp/testSquidRefresh.out, I can see that every time the page is refreshed, the cgi is executing. The squid access.log says: TCP_REFRESH_HIT/304, which doesn't do what I want, because it has to execute the script to get the header. How are

Re: [squid-users] Cacheing CGI pages and the Expires and Last-modified headers

2004-10-20 Thread Jim Nachlin
Henrik Nordstrom wrote: On Wed, 20 Oct 2004, Jim Nachlin wrote: If I tail the /tmp/testSquidRefresh.out, I can see that every time the page is refreshed, the cgi is executing. The squid access.log says: TCP_REFRESH_HIT/304, which doesn't do what I want, because it has to execute the script to

[squid-users] need to make cache bypassed for some requests

2004-10-20 Thread Primoz
I have a strange request for cache behaviour and would like to know if it's doable without too much coding. Having cca 70% requests served to anonymous users (which all return same for same URL) and 30% requests served to a class of users identified by a presence of one or two cookies (everybody

Re: [squid-users] Cacheing CGI pages and the Expires and Last-modified headers

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Jim Nachlin wrote: 1098307846.311 21 127.0.0.1 TCP_REFRESH_HIT/304 220 GET http://192.168.2.75/test-rec.cgi - DIRECT/192.168.2.75 - [Host: 192.168.2.75\r\nUser-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.5) Gecko/20031021\r\nAccept:

Re: [squid-users] need to make cache bypassed for some requests

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Primoz wrote: Having cca 70% requests served to anonymous users (which all return same for same URL) and 30% requests served to a class of users identified by a presence of one or two cookies Generally it is not adviseable to provide public and restricted information on the

Re: [squid-users] How to forward the client IP from Netscape Proxy3.5 to squid proxy???

2004-10-20 Thread Henrik Nordstrom
On Wed, 20 Oct 2004, Martin Altmann wrote: Hmm, maybe we are too dumb but we get a core dumped when trying to add that rule and restart Squid. Please file a bug report on this issue. http://www.squid-cache.org/Versions/v2/2.5/bugs/ Regards Henrik

[squid-users] squid_ldap_group with SASL and GSSAPI support

2004-10-20 Thread Diego Woitasen
This patch add support for SASL GSSAPI to squid_ldap_group, feature required if you want check group membership from a W2003 Active Directory or openldap with kerberos authentication. Patch created from squid 2.5-STABLE7. To Compile with GSSAPI support: cd helpers/external_acl/ldap_group make

Re: [squid-users] Cacheing CGI pages and the Expires and Last-modified headers

2004-10-20 Thread James Nachlin
You are quite right. Is there a squid configuration setting that will let me get around this problem? Even though that header is probably sent in every request, still some content is getting sent back without a check to the original server, or so it seems, because I commonly see TCP_HIT in

[squid-users] hostname instead of ip address

2004-10-20 Thread Glen H. Supan
help anyone, is it possible in squid to log the hostname of the requesting client/s in our lan instead of their ipaddress? thanks, glen

[squid-users] Write Error for aspx file

2004-10-20 Thread Niti Lohwithee
Dear Squid Group, My squid box is redhat kernal 2.4.18-3 with squid2.5 stable 1. I have facing some problem when i access a website. Please refer the below for error from browser and access.log . ***Display from Mozilla1.4 ERROR The requested URL could not be retrieved

[squid-users] X-Forwarded-For

2004-10-20 Thread Scott Mayo
I am trying to patch squid with X-Forwarded-For and run into all kinds of trouble. I downloaded squid-2.5.STABLE4 and the patch listed here: http://squid.sourceforge.net/follow_xff/ but when I do the patch and then run bootstrap.sh, I get all kinds of ERRORS and WARNINGS. Is there a newer