Re: [squid-users] questions with squid-3.1

2010-02-16 Thread Amos Jeffries
Jeff Peng wrote: I just downloaded squid-3.1 source and compile install it on an ubuntu linux box. There are two questions around it: 1. # sbin/squid -k kill squid: ERROR: No running copy -k shutdown is preferred if you can. kill is quite drastic and immediate. Though squid is running

Re: [squid-users] delay pool

2010-02-16 Thread Amos Jeffries
Adnan Shahzad wrote: Thanks for reply But how can I limit speed? I have 15 MB Internet speed, and around 1200 Clients mean I want to give at least around 512 KB each client Can you help me how delay pool help me in this regard http://wiki.squid-cache.org/Features/DelayPools covers the

RE: [squid-users] RE: images occasionally don't get through

2010-02-16 Thread Folkert van Heusden
To help the debugging I also found an url that is accessible to everyone: failed: -- 192.168.0.90 - - [12/Feb/2010:15:28:21 +] GET http://www.ibm.com/common/v15/main.css HTTP/1.0 200 10015 http://www-03.ibm.com/systems/hardware/browse/linux/?c=serversintron=Linux 2001t=ad

Re: [squid-users] RE: images occasionally don't get through

2010-02-16 Thread Amos Jeffries
Folkert van Heusden wrote: To help the debugging I also found an url that is accessible to everyone: failed: -- 192.168.0.90 - - [12/Feb/2010:15:28:21 +] GET http://www.ibm.com/common/v15/main.css HTTP/1.0 200 10015

Re: [squid-users] questions with squid-3.1

2010-02-16 Thread Jeff Peng
On Tue, Feb 16, 2010 at 5:10 PM, Amos Jeffries squ...@treenet.co.nz wrote: 1) whatever is in squid.conf. 2) Whatever was built with --with-pidfile=/path/squid.pid 3) $PREFIX/var/run/squid.pid  with whatever was defined in --prefix=... 4) /usr/local/squid/var/run/squid.pid Thanks Amos.

Re: [squid-users] SquidClamAV generates twice traffic

2010-02-16 Thread Henrik K
On Tue, Feb 16, 2010 at 03:25:24AM -0800, davefu wrote: Is there a way to avoid this double traffic generation? Redirector based AV scanners are flawed and inefficient by design. Use some sane package like HAVP or C-ICAP. Google for them.

[squid-users] Re: SquidClamAV generates twice traffic

2010-02-16 Thread davefu
Ok, I'll have a look. Thanks for the quick reply! -- View this message in context: http://n4.nabble.com/SquidClamAV-generates-twice-traffic-tp1557220p1557237.html Sent from the Squid - Users mailing list archive at Nabble.com.

Re: [squid-users] SSLBump, help to configure for 3.1.0.16

2010-02-16 Thread Matus UHLAR - fantomas
On 14.02.10 18:30, Andres Salazar wrote: Iam trying to configure SSLbump so that I can use squid in transparent mode and redirect with iptables/pf port 443 and 80 to squid. Are you aware of all security concerns when intercepting HTTPS connections? ...I just wonder when will first proactive

Re: [squid-users] cache manager access from web

2010-02-16 Thread Matus UHLAR - fantomas
On 14.02.10 01:32, J. Webster wrote: Would that work with: http_access deny manager CONNECT !SSL_ports On Mon, 15 Feb 2010 15:32:30 +0100, Matus UHLAR - fantomas uh...@fantomas.sk wrote: no, the manager is not fetched by CONNECT request (unless something is broken). you need

[squid-users] [SOLVED] Re: [squid-users] Fwd: squid_ldap_auth with two or more domain-controllers?

2010-02-16 Thread Tom Tux
With the parameter -c [seconds] (on the ldap-helper), I can specify, how long the first domain-controller should tried to be contacted, before the second one will tried to reach. Regards, Tom 2010/2/5 Tom Tux tomtu...@gmail.com: I can provide more than one server, but if the first one is not

[squid-users] Difference between Authenticate_ttl and auth_param basic credentialsttl ?

2010-02-16 Thread Tom Tux
Hi all, I'm authentication with the ldap-helper squid_ldap_auth against an active directory. I can specify two credentials-ttls: One is possible in the auth_param-directive: auth_param basic credentialsttl 2 hour The other one looks like this: authenticate_ttl 1 hour What is the difference

Re: [squid-users] BYPASSED acl allowedurls url_regex /etc/squid/url.txt , help?

2010-02-16 Thread Andres Salazar
Hello, acl allowedurls dstdomain /etc/squid/url.txt works better. However now the problem is that its not evaluating https sites that use the CONNECT method. So pretty much I can enter any https in the browser. Is there anyway to control this? Andres On Sun, Feb 14, 2010 at 2:07 PM, Amos

[squid-users] help please

2010-02-16 Thread David C. Heitmann
hello, i get no connection to msn throw squid! (client) my iptables are stopped! can somebody help me please.. windows live messenger 2009 squid 3.1.0.16 iptables 2.1.4 (deactivate for testing) squid.conf konfiguration: http://debianforum.de/forum/viewtopic.php?f=18t=118306# |# ICQ

Re: [squid-users] SSLBump, help to configure for 3.1.0.16

2010-02-16 Thread K K
On Tue, Feb 16, 2010 at 7:17 AM, Matus UHLAR - fantomas uh...@fantomas.sk wrote: On 14.02.10 18:30, Andres Salazar wrote: Iam trying to configure SSLbump so that I can use squid in transparent mode and redirect with iptables/pf port 443 and 80 to squid. Why transparent? Are you aware of all

[squid-users] Tunneling HTTPS and Grant access

2010-02-16 Thread Carlos Lopez
Hi all, I'am new to squid and I was wondering if it is possible to tunnel https request from authenticated users and then via script block/allow access to https address, but depending of what's the result of the script, let's say: user1 and user2 user1, have access to check yahoo mail only

[squid-users] POST denied?

2010-02-16 Thread Bill Stephens
All, I'm attempting to configure squid to proxy my requests to a Web Service. I can access via a GET request in my browser but attempting to submit a request via Java that has been configured to use squid as my proxy: Execute:Java13CommandLauncher: Executing

[squid-users] Reverse proxy Basic Accelerator

2010-02-16 Thread don Paolo Benvenuto
Hi! I'm trying to configure a basic reverse proxy accelerator for mediawiki, and I found the instructions at http://wiki.squid-cache.org/ConfigExamples/Reverse/BasicAccelerator but unfortunately they don't work with squid 2.7. When trying to run squid I get: ACL name 'all' not defined! FATAL

[squid-users] Re: SSLBump, help to configure for 3.1.0.16

2010-02-16 Thread Andres Salazar
Hello, Iam still having issues with SSLBump .. apparently iam now getting this error when I visit an https site with my browser explicity configured to use the https_port . 2010/02/16 14:31:14| clientNegotiateSSL: Error negotiating SSL connection on FD 8: error:1407609B:SSL

[squid-users] Squid restarts because of icap problem

2010-02-16 Thread akinf
In squid logs , i get the following error. I configured squid to connect to a java based applicaiton through icap. But squid gets error for some requests and restarts when it gets the following errro. Please help assertion failed: BodyPipe.cc:339: checkout.checkedOutSize == currentSize

Re: [squid-users] Re: slow performance 1 user : 3.1.0.16 on default config

2010-02-16 Thread Andres Salazar
Amos, Odd enough the same config and same squid/OS build in another box worked without any problems. Something happened in that Dual Atom 1GB box that squid didnt like. Below is the output of cache.log on the fast machine FYI in case there is some kind of obscure bug. 2010/02/16 14:39:13|

Re: [squid-users] help please

2010-02-16 Thread Amos Jeffries
David C. Heitmann wrote: hello, i get no connection to msn throw squid! (client) my iptables are stopped! can somebody help me please.. windows live messenger 2009 squid 3.1.0.16 iptables 2.1.4 (deactivate for testing) squid.conf konfiguration:

Re: [squid-users] NTLM Authentication and Connection Pinning problem

2010-02-16 Thread Jeff Foster
Henrik/Amos, Did you get the tcpdumps? Is there anything else I can do to help debug this problem? Jeff F 2010/2/14 Jeff Foster I am sending 2 tcpdump files as attachments to you, Henrik, and Amos plus the mail list. I expect the mailing list will remove the attachments so I hope you both

[squid-users] all traffic over squid an auth.

2010-02-16 Thread Christian Weiligmann
I have a problem, I would like to get all my questions from the internal network to the internet over squid proxy, with using delegated authentication. (SQL,NTLM...). Is that possible? I know that the transparency function is not be able to authenticate. But what can i do? For example: Ipsec

Re: [squid-users] all traffic over squid an auth.

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 20:53:52 +0100, Christian Weiligmann christian.weiligm...@weiligmann-net.de wrote: I have a problem, I would like to get all my questions from the internal network to the internet over squid proxy, with using delegated authentication. (SQL,NTLM...). Is that possible? I

Re: [squid-users] cache manager access from web

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 14:20:15 +0100, Matus UHLAR - fantomas uh...@fantomas.sk wrote: On 14.02.10 01:32, J. Webster wrote: Would that work with: http_access deny manager CONNECT !SSL_ports On Mon, 15 Feb 2010 15:32:30 +0100, Matus UHLAR - fantomas uh...@fantomas.sk wrote: no, the manager

Re: [squid-users] BYPASSED acl allowedurls url_regex /et c/squid/url.txt , help?

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 08:35:15 -0600, Andres Salazar ndrsslz...@gmail.com wrote: Hello, acl allowedurls dstdomain /etc/squid/url.txt works better. However now the problem is that its not evaluating https sites that use the CONNECT method. So pretty much I can enter any https in the browser.

Re: [squid-users] Difference between Authenticate_ttl and auth_param basic credentialsttl ?

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 14:51:19 +0100, Tom Tux tomtu...@gmail.com wrote: Hi all, I'm authentication with the ldap-helper squid_ldap_auth against an active directory. I can specify two credentials-ttls: One is possible in the auth_param-directive: auth_param basic credentialsttl 2 hour The

Re: [squid-users] Tunneling HTTPS and Grant access

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 07:42:09 -0800 (PST), Carlos Lopez the_spid...@yahoo.com wrote: Hi all, I'am new to squid and I was wondering if it is possible to tunnel https request from authenticated users and then via script block/allow access to https address, but depending of what's the result of

Re: [squid-users] POST denied?

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 10:45:50 -0500, Bill Stephens grape...@gmail.com wrote: All, I'm attempting to configure squid to proxy my requests to a Web Service. I can access via a GET request in my browser but attempting to submit a request via Java that has been configured to use squid as my

Re: [squid-users] Reverse proxy Basic Accelerator

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 20:21:52 +0100, don Paolo Benvenuto paolobe...@gmail.com wrote: Hi! I'm trying to configure a basic reverse proxy accelerator for mediawiki, and I found the instructions at http://wiki.squid-cache.org/ConfigExamples/Reverse/BasicAccelerator but unfortunately they don't

Re: [squid-users] How can I cache most content

2010-02-16 Thread Landy Landy
Thanks for replying. As Marcus suggested, I added the following lines to squid.conf: acl blockanalysis01 dstdomain .scorecardresearch.com .google-analytics.com acl blockads01 dstdomain .rad.msn.com ads1.msn.com ads2.msn.com ads3.msn.com ads4.msn.com acl blockads02

[squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Tory M Blue
I'm starting to lose my mind here. New hardware test bed including a striped set of SSD's Same hardware, controller etc as my other squid servers, just added SSD's for testing. I've used default threads and I've built with 24 threads. And what's blowing my mind is I get the error immediately upon

Re: [squid-users] Squid restarts because of icap problem

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 11:56:08 -0800 (PST), akinf fatih.a...@turkcellteknoloji.com.tr wrote: In squid logs , i get the following error. I configured squid to connect to a java based applicaiton through icap. But squid gets error for some requests and restarts when it gets the following errro.

[squid-users] Squid reverse with two web servers in different TCP ports

2010-02-16 Thread Alejandro Facultad
Dear all, I have Squid 2.7 configured with reverse mode. I have two web sites: OWA (webmail): 10.2.2.1 in port 80 Intranet: 10.2.2.2 in port 44000 Squid with OWA is working perfectly, but when I add to the squid.conf the lines for Intranet, the Intranet site does not respond (requests

Re: [squid-users] How can I cache most content

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 14:25:39 -0800 (PST), Landy Landy landysacco...@yahoo.com wrote: Thanks for replying. As Marcus suggested, I added the following lines to squid.conf: acl blockanalysis01 dstdomain .scorecardresearch.com .google-analytics.com acl blockads01 dstdomain

Re: [squid-users] Cache manager analysis

2010-02-16 Thread Chris Robertson
J. Webster wrote: Ok - thanks. 2.HEAD - has this been included in the CentOS repository yet? It doesn't look to even be in the CentOSPlus repos. I believe CentOS only has 2.6 Using the packaged software is fine if you are willing to accept the compromises that have been made. RHEL 5

Re: [squid-users] Squid reverse with two web servers in different TCP ports

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 20:02:34 -0300, Alejandro Facultad alejandro_facul...@yahoo.com.ar wrote: Dear all, I have Squid 2.7 configured with reverse mode. I have two web sites: OWA (webmail): 10.2.2.1 in port 80 Intranet: 10.2.2.2 in port 44000 Squid with OWA is working perfectly, but when I

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 14:30:06 -0800, Tory M Blue tmb...@gmail.com wrote: I'm starting to lose my mind here. New hardware test bed including a striped set of SSD's Same hardware, controller etc as my other squid servers, just added SSD's for testing. I've used default threads and I've built

Re: [squid-users] Different port per ip

2010-02-16 Thread Chris Robertson
cio...@gmail.com wrote: Is it possible to restrict access to each ip but with a different port for each ip? for example: user1 has access to ip1 port 8000 user2 has access to ip2 port 8001 Given proper declaration of the acls user1, user2, ip1, ip2, port8000 and port8001... http_access

Re: [squid-users] Creating ip exception

2010-02-16 Thread Chris Robertson
Jose Ildefonso Camargo Tolosa wrote: On Mon, Feb 15, 2010 at 12:34 AM, Martin Connell mconn...@richmondfc.com.au wrote: Dear Squid, I am a new squid user, and I¹ve been relegated the task of creating a couple of exceptions based on IP address. So basically, we have our squid setup so

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Tory M Blue
2010/02/16 14:18:15| squidaio_queue_request: WARNING - Queue congestion 2010/02/16 14:18:26| squidaio_queue_request: WARNING - Queue congestion What can I look for, if I don't believe it's IO wait or load (the box is sleeping), what else can it be. I thought creating a new build with 24

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 16:24:22 -0800, Tory M Blue tmb...@gmail.com wrote: 2010/02/16 14:18:15| squidaio_queue_request: WARNING - Queue congestion 2010/02/16 14:18:26| squidaio_queue_request: WARNING - Queue congestion What can I look for, if I don't believe it's IO wait or load (the box is

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Tory M Blue
On Tue, Feb 16, 2010 at 4:45 PM, Amos Jeffries squ...@treenet.co.nz wrote: On Tue, 16 Feb 2010 16:24:22 -0800, Tory M Blue tmb...@gmail.com wrote: 2010/02/16 14:18:15| squidaio_queue_request: WARNING - Queue congestion 2010/02/16 14:18:26| squidaio_queue_request: WARNING - Queue congestion

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Amos Jeffries
On Tue, 16 Feb 2010 17:00:33 -0800, Tory M Blue tmb...@gmail.com wrote: On Tue, Feb 16, 2010 at 4:45 PM, Amos Jeffries squ...@treenet.co.nz wrote: On Tue, 16 Feb 2010 16:24:22 -0800, Tory M Blue tmb...@gmail.com wrote: 2010/02/16 14:18:15| squidaio_queue_request: WARNING - Queue congestion

Re: [squid-users] Reverse proxy Basic Accelerator

2010-02-16 Thread Jeff Peng
On Wed, Feb 17, 2010 at 3:21 AM, don Paolo Benvenuto paolobe...@gmail.com wrote: Hi! I'm trying to configure a basic reverse proxy accelerator for mediawiki, and I found the instructions at http://wiki.squid-cache.org/ConfigExamples/Reverse/BasicAccelerator but unfortunately they don't work

Re: [squid-users] squidaio_queue_request: WARNING - Queue congestion

2010-02-16 Thread Tory M Blue
 /usr/local/squid/etc/squid/squid.conf ?? So it's really odd. Not getting anything to stdin/stdout But don't want to get too into the config piece when the big deal seems to be the congestion. Why more congestion with faster disks and I'm just thinking if there is actually another config

[squid-users] Re: Squid restarts because of icap problem

2010-02-16 Thread akinf
Thank you for reply, but what is rtfm? -- View this message in context: http://n4.nabble.com/Squid-restarts-because-of-icap-problem-tp1557855p1558274.html Sent from the Squid - Users mailing list archive at Nabble.com.