Re: [squid-users] Always ntlm .... Squid + AD

2007-08-30 Thread Alexandre Mackow
Henrik Nordstrom a écrit : On ons, 2007-08-29 at 17:42 +0200, Alexandre Mackow wrote: Make sure your cache_effective_user is member of the group owning the /var/run/samba/winbindd_privileged directory, and that you DO NOT specify cache_effective_group in squid.conf... (repeat: DO NOT

Re: [squid-users] Always ntlm .... Squid + AD

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 08:58 +0200, Alexandre Mackow wrote: So the log message was now : temporary disabling (Proxy Authentication Required) digest from myparent.proxy Thats a completely different thing and harmless. All the above says is that your Squid is built with cache digests support,

Re: [squid-users] acl bug (when peers configured)

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 06:02 -0300, Michel Santos wrote: There is appearently an acl bug acls do not work for peers They do work for peers, just the same as any other http client. There is nothing special about peers in the access controls. acl all src 200.152.80.0/20 Warning: Don't

Re: [squid-users] Redirect Web traffic From Linux GW to win32 squid.

2007-08-30 Thread Henrik Nordstrom
On ons, 2007-08-29 at 23:18 -0500, Rogelio Sevilla Fernandez wrote: Im working with WRT54GL and i want make somes whitelist for websites. I tried to do that with iptables +webstr but i had a lot of problems with hotmail. So i decided to install squid on a Win2k server and redirect all the web

Re: [squid-users] [Resolve]Always ntlm .... Squid + AD

2007-08-30 Thread Alexandre Mackow
Alexandre Mackow a écrit : Henrik Nordstrom a écrit : Thanks for your help The probleme was /var/run/samba/winbindd_privileged group owner... So the log message was now : temporary disabling (Proxy Authentication Required) digest from myparent.proxy Any idea... I will try

Re: [squid-users] acl bug (when peers configured)

2007-08-30 Thread Michel Santos
Henrik Nordstrom disse na ultima mensagem: On tor, 2007-08-30 at 06:02 -0300, Michel Santos wrote: There is appearently an acl bug acls do not work for peers They do work for peers, just the same as any other http client. There is nothing special about peers in the access controls. acl

[squid-users] Squid-2.6 configuration Manual

2007-08-30 Thread Visolve Squid
Hello all, We have updated our Squid configuration manual for 2.6 version. It is available at http://www.visolve.com/squid/squid26/contents.php We have included examples, wherever possible, to make understanding easier. We hope our contribution would help potential squid users. Thanks,

Re: [squid-users] acl bug (when peers configured)

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 08:27 -0300, Michel Santos wrote: *THIS* is the thing here: that any acl configured on the frontend cache is not beeing applied to any request from the peer Then check your http_access rules. You have something else in there... There is absolutely nothing special about

[squid-users] DAP Auth exclude domain

2007-08-30 Thread Mattias Olsson
Hi all! I have successfully installed some new squid servers that are validating domain users via ntlm_auth. So nice! The problem i have now is that my proxy servers are in one domain but i have another small domain that also should use them. The smaller domain is not a member of the top domain

Re: [squid-users] acl bug (when peers configured)

2007-08-30 Thread Michel Santos
Henrik Nordstrom disse na ultima mensagem: On tor, 2007-08-30 at 08:27 -0300, Michel Santos wrote: *THIS* is the thing here: that any acl configured on the frontend cache is not beeing applied to any request from the peer Then check your http_access rules. You have something else in

RE: [squid-users] Access denied - ACL problem

2007-08-30 Thread Edward Stafford
Thanks for the pointers. I will look into those directives. Meanwhile, as a temp workaround, I added an entry for servername to the hosts file on the squid server. -Original Message- From: Henrik Nordstrom [mailto:[EMAIL PROTECTED] Sent: Wednesday, August 29, 2007 6:21 PM To: Edward

Re: [squid-users] Squid-2.6 configuration Manual

2007-08-30 Thread Daniel Zilli
Congratulations guys! This is very important to everyone. Bests, Daniel Zilli -- Original Message --- From: Visolve Squid [EMAIL PROTECTED] To: squid squid-users@squid-cache.org Cc: Henrik Nordstrom [EMAIL PROTECTED], [EMAIL PROTECTED], ViSolve Web Cache Consulting Group [EMAIL

[squid-users] poor performance

2007-08-30 Thread Lutieri G.
Hi! Today i'm running squid 2.5stable9 in a debian sarg box SUN v20z. All works very nice. Although, i need to migrate squid to a new server SUN x4100 running FreeBSD. And now begin my problems. I was talking about my performance problems with freebsd mailing list. But we can't find a solution

Re: [squid-users] poor performance

2007-08-30 Thread [EMAIL PROTECTED]
Hi, Please make sure your squid is not using SWAP or it will definitely slow down the system. Post your top. Regards Lutieri G. wrote: Hi! Today i'm running squid 2.5stable9 in a debian sarg box SUN v20z. All works very nice. Although, i need to migrate squid to a new server SUN x4100

[squid-users] url_rewrite_program

2007-08-30 Thread alexus
hi i'm having some issues with url_rewrite_program in squid, and i was wondering if someone can give me a hand here... first of all i'd like to specify somehow (probably through acl) which urls i want to send for rewrite at the first place, since i dont want my url_rewrite_program to process

Re: [squid-users] poor performance

2007-08-30 Thread Lutieri G.
# top -d 1 last pid: 4183; load averages: 0.03, 0.01, 0.00 up 0+01:17:41 12:44:54 76 processes: 1 running, 75 sleeping CPU states: 0.0% user, 0.0% nice, 0.0% system, 0.0% interrupt, 100% idle Mem: 57M Active, 19M Inact, 44M Wired, 16K Cache, 27M Buf, 3708M

Re: [squid-users] url_rewrite_program

2007-08-30 Thread Marcus Kool
Alexus, A shell script has interpretation of special character that might be in a URL (e.g. ' ` | ) I recommend to use echoif access is allowed (empty line means OK) and to use quotes around anything that you echo. Marcus alexus wrote: hi i'm having some issues with

Re: [squid-users] poor performance

2007-08-30 Thread Adrian Chadd
You need more stats than that! * install munin; its always a good thing to do when wanting stats from a unix box * learn to read 'vmstat 1' and 'systat -vmstat 1' * graph the squid stats via SNMP too You need more statistics to diagnose this problem. We're not magicians. :) Adrian On

Re: [squid-users] DAP Auth exclude domain

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 14:44 +0200, Mattias Olsson wrote: Hi all! I have successfully installed some new squid servers that are validating domain users via ntlm_auth. So nice! The problem i have now is that my proxy servers are in one domain but i have another small domain that also

Re: [squid-users] url_rewrite_program

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 11:26 -0400, alexus wrote: first of all i'd like to specify somehow (probably through acl) which urls i want to send for rewrite at the first place, since i dont want my url_rewrite_program to process every single url. See url_rewrite_access #!/bin/sh read i ; echo $i

Re: [squid-users] Squid and WCCP

2007-08-30 Thread Ian
Hi Henrik, We got it working in the end after debugging on the cisco we saw that the traffic was coming from the ADSL PPPoE's IP and not from the routers LAN address. We changed the tunnel to be 10.10.250.1 - 41.x.x.x and it then worked fine. Thanks :) Ian On 8/30/07, Henrik Nordstrom [EMAIL

RE: [squid-users] Via off

2007-08-30 Thread Nicole
On 29-Aug-07 My Secret NSA Wiretap Overheard Vadim Pushkin Saying : I did this, and it works: header_access Via deny all header_access X-Forwarded-For deny all .vp Excellent! Thank You to all who responded on this! Nicole From: Sekar [EMAIL PROTECTED] Hello

Re: [squid-users] poor performance

2007-08-30 Thread Tek Bahadur Limbu
Hi Lutieri, Lutieri G. wrote: Hi! Today i'm running squid 2.5stable9 in a debian sarg box SUN v20z. All works very nice. Although, i need to migrate squid to a new server SUN x4100 running FreeBSD. And now begin my problems. I was talking about my performance problems with freebsd mailing

RE: [squid-users] poor performance

2007-08-30 Thread Nicole
On 30-Aug-07 My Secret NSA Wiretap Overheard Lutieri G. Saying : Hi! Today i'm running squid 2.5stable9 in a debian sarg box SUN v20z. All works very nice. Although, i need to migrate squid to a new server SUN x4100 running FreeBSD. And now begin my problems. I was talking about my

Re: [squid-users] Squid and WCCP

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 19:15 +0200, Ian wrote: Hi Henrik, We got it working in the end after debugging on the cisco we saw that the traffic was coming from the ADSL PPPoE's IP and not from the routers LAN address. We changed the tunnel to be 10.10.250.1 - 41.x.x.x and it then worked fine.

Re: [squid-users] url_rewrite_program

2007-08-30 Thread alexus
i dont understand what is rest parameter for on whlie line? that is just to seperate url from the rest of the line? On 8/30/07, Henrik Nordstrom [EMAIL PROTECTED] wrote: On tor, 2007-08-30 at 11:26 -0400, alexus wrote: first of all i'd like to specify somehow (probably through acl) which

Re: [squid-users] url_rewrite_program

2007-08-30 Thread Henrik Nordstrom
On tor, 2007-08-30 at 15:53 -0400, alexus wrote: i dont understand what is rest parameter for on whlie line? that is just to seperate url from the rest of the line? Yes http://wiki.squid-cache.org/SquidFaq/SquidRedirectors

Re: [squid-users] criticism against squid

2007-08-30 Thread Nicole
On 29-Aug-07 My Secret NSA Wiretap Overheard john allspaw Saying : Varnish shows a lot of promise. I do believe that there's a good amount of trash talking in those comments, especially given that squid would for sure have been designed differently if it set out to be a fast accelerator,

Re: [squid-users] fatal error: url_rewriter helpers are crashing too rapidly (?)

2007-08-30 Thread Amos Jeffries
Hello, I've been running squid-2.6stable6 quite happily for some time on a 32bit RHEL5 server. Today squid crashed and refused to come back up, even after a reboot, with the error FATAL: the url_rewriter helpers are crashing too rapidly, need help! snip Where can I start trying to figure

Re: [squid-users] url_rewrite_program

2007-08-30 Thread alexus
can i somehow (maybe use urlgroup) to identify some urls/domains that i want to feed into url_rewrite_program and everything else leave it alone? in ideal scenario i'd want some (not all) urls to be fed to url_rewrite_program and my url_rewrite_program would after it rewrite url would also switch

Re: [squid-users] Squid and WCCP

2007-08-30 Thread Adrian Chadd
On Thu, Aug 30, 2007, Henrik Nordstrom wrote: On tor, 2007-08-30 at 19:15 +0200, Ian wrote: Hi Henrik, We got it working in the end after debugging on the cisco we saw that the traffic was coming from the ADSL PPPoE's IP and not from the routers LAN address. We changed the tunnel to be

Re: [squid-users] criticism against squid

2007-08-30 Thread Mark Nottingham
On 2007/08/31, at 7:04 AM, Nicole wrote: On 29-Aug-07 My Secret NSA Wiretap Overheard john allspaw Saying : Varnish shows a lot of promise. I do believe that there's a good amount of trash talking in those comments, especially given that squid would for sure have been designed

[squid-users] How to enable these FEATURES in SQUID

2007-08-30 Thread Indunil Jayasooriya
Hi, I want to enable below fetures in SQUID. features are, when users access Internet with nsca_auth featue, They are asked to type username and password. Can I set a life time (5 days or 2 weeks like that) to that password .when that time period expires, Users SHOULD change their passwords.

Re: [squid-users] Via off

2007-08-30 Thread Logu
I did this, and it works: header_access Via deny all header_access X-Forwarded-For deny all .vp Should the documentation on the configuration file be fixed ?. It says If set, Squid will include a Via header in requests and replies.. But reply seems to have the Via header when the

Re: [squid-users] Squid and WCCP

2007-08-30 Thread Ian
Hi Juan, Thanks for the tip, could you possibly explain a little more about the loopback ip, im a little confused :) Thanks On 8/30/07, Juan C. Crespo R. [EMAIL PROTECTED] wrote: You should use one loopback ip instead of one adquiring from a dhcp server, remember if the Wan ip changes, your