Re: [squid-users] https site denial only loads a part of the defined error message

2009-03-25 Thread Truth Seeker
Amos, In firefox, the complete ERROR message is displaying for both http and https. But for IE, http is showing the full error message, but https is just showing the headings of the error messages. Is there any work around for this??? --- On Wed, 3/25/09, Amos Jeffries wrote: > From: Amos

Re: [squid-users] Limitting particular group to specific sites (not working perfectly)

2009-03-25 Thread Truth Seeker
Thanks a lot Amos its working fine now... Alhamdulillahhh - -- --- Always try to find truth!!! ***---***--*** Its always nice to know that people with no understanding of technologies want to evaluate technical professionals based on their

Re: [squid-users] Squid daily releases

2009-03-25 Thread Amos Jeffries
> Using 3.1.0.6 > > What has changed between 0308 and today? > > I compiled today's release and got no access complains and had to switch > back > to 20090308? > > What happened? Sorry about that. We can only assure that is builds. The run-time behavior is not as well auto-tested as we would like.

[squid-users] Squid daily releases

2009-03-25 Thread The Doctor
Using 3.1.0.6 What has changed between 0308 and today? I compiled today's release and got no access complains and had to switch back to 20090308? What happened? -- Member - Liberal International This is doc...@nl2k.ab.ca Ici doc...@nl2k.ab.ca God, Queen and country! Beware Anti-Christ rising!

Re: [squid-users] https site denial only loads a part of the defined error message

2009-03-25 Thread Amos Jeffries
> > > For certain groups, we are giving access to public mail servers like > gmail/yahoo etc based on time only. When they are trying to access any > http mail site, they are getting the complete error message which i > defined, but when they are accessing any https:// mail site, they are > getting

Re: [squid-users] squid TPROXY and empty access.log

2009-03-25 Thread Amos Jeffries
> On Wed, Mar 25, 2009 at 12:00 PM, Amos Jeffries > wrote: >> Sounds like a bug, but there are a few things below you need to clear up >> before you can be sure its not them... > > Thank you for your fast reply. I tried your suggestion but it didn't > work. Here some details: > >> "Obsolete --enab

Re: [squid-users] Squid, Symantec LiveUpdate, and HTTP 1.1 versus HTTP 1.0

2009-03-25 Thread Marcus Kool
The story about Squid and HTTP 1.1 is long... To get your LiveUpdate working ASAP you might want to fiddle with the firewall rules and to NOT redirect port 80 traffic of Symantec servers to Squid, but simply let the traffic pass. Nathan Eady wrote: Okay, we've got port 80 traffic going transpar

[squid-users] Squid, Symantec LiveUpdate, and HTTP 1.1 versus HTTP 1.0

2009-03-25 Thread Nathan Eady
Okay, we've got port 80 traffic going transparently to a Squid proxy here, and I need to make a small configuration change, and I can't seem to find, either in the man pages nor on the web, the documentation on how to do it. It's probably one little line in squid.conf, but I can't find it. Here's

[squid-users] https site denial only loads a part of the defined error message

2009-03-25 Thread Truth Seeker
For certain groups, we are giving access to public mail servers like gmail/yahoo etc based on time only. When they are trying to access any http mail site, they are getting the complete error message which i defined, but when they are accessing any https:// mail site, they are getting the same

Re: [squid-users] squid exceptionally slow to forward when direct is not possible

2009-03-25 Thread Hunter Fuller
Excellent, thanks all. hackmiester > > > > 2009/3/25 Kinkie : >> On Wed, Mar 25, 2009 at 6:10 AM, Hunter Fuller wrote: >>> 2009/3/24 Hunter Fuller : > Alternatively you could be using dst acls or > something else that requires DNS lookups. I was using a dst ACL!! I disabled it. I

RE: [squid-users] Are there benefits increasing read_ahead_gap in reverse proxy with collapsed_forwarding?

2009-03-25 Thread Charlie Killian
Hi Chris. Thanks for the very informative response. > Setting this to 500MB is IMO overkill and will lead to memory > starvation issues (remember, this is the maximum buffer size *per > object*) if you hit a decent number of simultaneous cache misses of > large objects. > > If the origin se

Re: [squid-users] squid TPROXY and empty access.log

2009-03-25 Thread Jack Daniels
On Wed, Mar 25, 2009 at 12:00 PM, Amos Jeffries wrote: > Sounds like a bug, but there are a few things below you need to clear up > before you can be sure its not them... Thank you for your fast reply. I tried your suggestion but it didn't work. Here some details: > "Obsolete --enable-tproxy opt

[squid-users] R: Re: [squid-users] squid and ICAP

2009-03-25 Thread projpr...@libero.it
Alway thanks for your quick answer!!! In theory Clamav doesn´t support directly Icap: it needs a little "help" from an icap server and in linux is eventually available with c-icap. The problem is that c-icap doesn´t exist for windows (or at list I didn´t find a icap server for windows). Now I cho

Re: [squid-users] Tow squid on ths same computer

2009-03-25 Thread Amos Jeffries
Merdouille wrote: Hi! I need 2 squid on a computer with 2 differents ports (80 for the first and 81 for the others. I have 2 different config, 2 different cache dir and only a single user for squid 1& 2 First i use a init.d sqcipt with a littlle modification : append -f $CONFIGFILE to prevent

Re: [squid-users] squid and ICAP

2009-03-25 Thread Amos Jeffries
projpr...@libero.it wrote: Hi, I try to manage this situation: squid+safesquid+clamav My aim was to have proxy (squid) with scanning for virus and malware. Squid works perfectly, Safesquid also, Clamav also. Now the question is: How do I set squid to "pass" the request to Safesquid to let anal

Re: [squid-users] Limitting particular group to specific sites (not working perfectly)

2009-03-25 Thread Amos Jeffries
Truth Seeker wrote: In my squid.conf, i am trying to grant access ONLY to a set of predefined sites for a group of users (those who are member of limitedsurfers). They are not allowed to access any other thing from the Internet. The following is the acl which i created All my other rules ar

Re: [squid-users] TPROXY Issues

2009-03-25 Thread Amos Jeffries
Jamie Orzechowski wrote: I am back trying to solve my tproxy issues. Running Ubuntu server with Kernel 2.6.28-11-server, iptables v1.4.3.1, squid 3.1.0.6 I am able to browse transparently but proxy test sites still detect the cache. http://www.whatismyip.com says the following Your IP Add

Re: [squid-users] Issues with Tproxy setup

2009-03-25 Thread Amos Jeffries
trasor wrote: First let me apologize for the repost as not finding a place to post a reply. Second there was a typo in my previous message, Amos pointed out, should have been iptables 1.4.0 with patch. That said, I dumped the entire OS this morning for a clean start. Downloaded, compiled, m

Re: [squid-users] squid TPROXY and empty access.log

2009-03-25 Thread Amos Jeffries
Jack Daniels wrote: Hello, I've a problem to log client request activities when Squid is in TPROXY mode. In squid.conf I have 'access_log /var/log/squid/access.log squid', this file is correctly created but results empty. # ls -la /var/log/squid/ -rw-r- 1 proxy proxy 0 24 mar 16:09 acc

Re: [squid-users] java web start jars won't be cached

2009-03-25 Thread Thibault Ketterer
> This request is determined to NOT get get a cached copy of this file. > Cache-control: no-cache, Pragma: no-cache, If-Modified-Since Dec 1969... > But the request only affects whether the request is satisfied from cache. > Whether or not the object is cached at all is (in part) determined by t

[squid-users] Tow squid on ths same computer

2009-03-25 Thread Merdouille
Hi! I need 2 squid on a computer with 2 differents ports (80 for the first and 81 for the others. I have 2 different config, 2 different cache dir and only a single user for squid 1& 2 First i use a init.d sqcipt with a littlle modification : append -f $CONFIGFILE to prevent a squid -k message

[squid-users] squid and ICAP

2009-03-25 Thread projpr...@libero.it
Hi, I try to manage this situation: squid+safesquid+clamav My aim was to have proxy (squid) with scanning for virus and malware. Squid works perfectly, Safesquid also, Clamav also. Now the question is: How do I set squid to "pass" the request to Safesquid to let analyze those by Clamav? Exist

Re: [squid-users] squid exceptionally slow to forward when direct is not possible

2009-03-25 Thread Kinkie
On Wed, Mar 25, 2009 at 6:10 AM, Hunter Fuller wrote: > 2009/3/24 Hunter Fuller : >>> Alternatively you could be using dst acls or >>> something else that requires DNS lookups. >> >> I was using a dst ACL!! I disabled it. I hope this was the problem; we >> shall see tonight at midnight. > > This w

[squid-users] Limitting particular group to specific sites (not working perfectly)

2009-03-25 Thread Truth Seeker
In my squid.conf, i am trying to grant access ONLY to a set of predefined sites for a group of users (those who are member of limitedsurfers). They are not allowed to access any other thing from the Internet. The following is the acl which i created All my other rules are working perfectly..