Re: [squid-users] squid as reverse proxy

2005-11-17 Thread squidrunner support
Access Denied. Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect. Can you post acl and http_access related settings in squid.conf configuration file. grep -Ev '^#|^$' squid.conf |

[squid-users] HOWTO increase HIT Ratio

2005-11-17 Thread Wennie V. Lagmay
Hi all, Can anybody help me how to increase or improve MEM_HIT , IMS_HIT and REFRESH_HIT, correct be if I'm wrong, but if I'm not mistaken improving these HITS will help a lot on subscriber side. Thank you very much, Wennie

[squid-users] cache-control header causes site to fail

2005-11-17 Thread Graeme Bisset
Hi, I'm trying to access the site http://www.kinderopvang-plein.nl It works without going through squid but when I do I get a 403 forbidden error. I've tracked this down to the cache-control header that squid adds (and more precisely the value it specifies) by running the following wget

RE: [squid-users] cache-control header causes site to fail

2005-11-17 Thread Graeme Bisset
Ah I've found another thread with the same problem... http://www.squid-cache.org/mail-archive/squid-users/200509/0204.html Is the refresh pattern still the only way to fix this issue? Thanks, Graeme -Original Message- From: Graeme Bisset [mailto:[EMAIL PROTECTED] Sent: 17 November

[squid-users] rare auth

2005-11-17 Thread Efren Bravo
Hi, Please take a look to this network layout: (Enterprise LAN) | || | |+Squid to internet and Users Auth | +LAN PCs | router | router | (Enterprise Substation LAN) || |+Squid +LAN PCs The Enterprise's Squid has all the users who has access to internet including all

[squid-users] Question about NTLM authentication

2005-11-17 Thread lmarcilly
Hi all, i have some questions about NTLM authentication. Actually i use DansGuardian with Ident to authenticate user in order to filter traffic according to the username. But there is a problem with Ident : deployment. Installing Ident on all clients takes time so i want to find an other

Re: [squid-users] How to block shoutcast streams?

2005-11-17 Thread Boniforti Flavio
Odhiambo Washington wrote: He said that it will allow you to see the clients used in you access.log, not that you need that for the rules to work ;) And yes, if you enable that option, log file size will increase. So here I got the bad useragent at work: 1132242131.462 5761 10.167.211.62

[squid-users] Java Plugin With Client Cert Auth and Keepalive

2005-11-17 Thread Seth Milder
Hi, I have a Java Applet that connects to a site requiring client side certificates. The site is running Apache 2.0.54 with a keepalive timeout of 15 minutes. As a result the applet prompts the user for a client side certificate on its inital connection and does not prompt again unless the

Re: [squid-users] How to block shoutcast streams?

2005-11-17 Thread Kinkie
On Thu, 2005-11-17 at 16:50 +0100, Boniforti Flavio wrote: Odhiambo Washington wrote: He said that it will allow you to see the clients used in you access.log, not that you need that for the rules to work ;) And yes, if you enable that option, log file size will increase. So here I got

Re: [squid-users] Question about NTLM authentication

2005-11-17 Thread Kinkie
On Thu, 2005-11-17 at 15:27 +, [EMAIL PROTECTED] wrote: Hi all, i have some questions about NTLM authentication. Actually i use DansGuardian with Ident to authenticate user in order to filter traffic according to the username. But there is a problem with Ident : deployment.

[squid-users] intoduce authentication without changing policies

2005-11-17 Thread Pim Zandbergen
Hi, On one of the systems under my control, I'd like to use ntlm authentication, just for the purpose of getting as many usernames as can be collected, into the logfiles. I don't want to introduce any actual changes in the existing policies, which now do not take authentication status as a

Re: [squid-users] intoduce authentication without changing policies

2005-11-17 Thread Kinkie
On Thu, 2005-11-17 at 18:12 +0100, Pim Zandbergen wrote: Hi, On one of the systems under my control, I'd like to use ntlm authentication, just for the purpose of getting as many usernames as can be collected, into the logfiles. I don't want to introduce any actual changes in the existing

Re: [squid-users] Question about NTLM authentication

2005-11-17 Thread Serassio Guido
Hi Kinkie, At 18.11 17/11/2005, Kinkie wrote: Does it? I don't know about Windows identd implementations, but on Unix identd usually returns the name of an user owning the TCP socket (unless otherwise configured) As I know, on Windows there are some incomplete identd implementation reporting

Re: [squid-users] rare auth

2005-11-17 Thread Christoph Haas
On Thursday 17 November 2005 17:26, Efren Bravo wrote: Please take a look to this network layout: (Enterprise LAN) | |+Squid to internet and Users Auth | +LAN PCs router | (Enterprise Substation LAN) |+Squid +LAN PCs The Enterprise's Squid has all the users who has access

Re: [squid-users] Access to single site

2005-11-17 Thread Christoph Haas
On Thursday 17 November 2005 20:26, [EMAIL PROTECTED] wrote: Is there a way to allow entire network access to the internet but then deny a single ip in this subnet access to the internet except for one site? Yes. Read about ACLs in the documentation. What might also help:

RE: [squid-users] squid as reverse proxy

2005-11-17 Thread Thomas Steimann
Hi there, My settings: acl QUERY urlpath_regex cgi-bin \? acl all src 0.0.0.0/0.0.0.0 acl manager proto cache_object acl localhost src 127.0.0.1/255.255.255.255 acl to_localhost dst 127.0.0.0/8 acl SSL_ports port 443 563 acl Safe_ports port 80 # http acl Safe_ports port 21 #

[squid-users] Problem getting NSCA working on FreeBSD

2005-11-17 Thread Francisco Lopes
Hello, So I'm trying to get Squid working for myself only, on a remote FreeBSD server I have. I'm using this configuration file: http_port 9876 tcp_outgoing_address 66.43.83.13 hierarchy_stoplist cgi-bin ? php asp acl QUERY urlpath_regex cgi-bin \? php asp no_cache deny QUERY

[squid-users] how to write this delay pool rule ?

2005-11-17 Thread huang mingyou
hello,list. I have a squid server work with acceleration mode. Now I want limit the internet to a mirror site(ip is 10.0.2.2)'s speed. but don't limit other site. So,I want use the delay pool to do this,but I don't know how to write the acl rule for it . please help me!

[squid-users] Re: how to write this delay pool rule ?

2005-11-17 Thread huang mingyou
oh,I done it like this. acl mirror dst 10.0.2.2/32 delay_pools 1 delay_class 1 2 delay_access 1 allow mirror delay_access 1 deny all delay_parameters 1 -1/-1 102400/204800 delay_initial_bucket_level 50 hmy

Re: [squid-users] Problem getting NSCA working on FreeBSD

2005-11-17 Thread Odhiambo Washington
* On 17/11/05 22:45 -0200, Francisco Lopes wrote: Hello, So I'm trying to get Squid working for myself only, on a remote FreeBSD server I have. I'm using this configuration file: http_port 9876 tcp_outgoing_address 66.43.83.13 hierarchy_stoplist cgi-bin ? php asp acl QUERY

[squid-users] Pipeline between two caches

2005-11-17 Thread Pieter De Wit
Hello List, I have two proxy (one remote - both squid). I was wondering if I can pipeline the two, or at least get the number of connections between the two down. Can they be connected via a single TCP connection ? Thanks, Pieter “This e-mail is sent on the Terms and Conditions that can be