Re: [squid-users] If not modified since is causing near-hits

2010-05-03 Thread David Raccah
Thanks for the help. I typed incorrectly. Essentially, we have crawlers coming to our webpage, and they are using the if-modified-since header. The system is designed in a classic L1/L2 architecture. The L1 is primarily a router and the L2 boxes contain the disk and memory cache. If the data i

[squid-users] logrotate squid files

2010-05-03 Thread Riccardo Castellani
I need to rotate these log files for Squid: store.log access.log cache.log rewrite.log (jesred log) redirect.log(jesred log) What's the suitable command (to insert among postrotate and endscript) for telling both to Squid and to Jesred to write again in .log files ? 1) test ! -

[squid-users] TIME_WAIT state

2010-05-03 Thread Ivan .
Hi I see allot of TIME_WAIT states when I run netstat -n. I imagine that this points to some tcp parameters not quite tuned correctly. Anyone have some kernel tcp tuning parameters for a Squid proxy running on RH EL5 pushing around 30Mbs? Thanks Ivan

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Dave Coventry
On 4 May 2010 05:21, Jose Ildefonso Camargo Tolosa wrote: > > Some questions: > > 1. How is your network currently configured: static IPs, dhcp, if > dhcp, is the dlink router your dhcp server? Yes. The DLink allocates IP addresses on the network. The Squid box is set to .5 static IP > 2. What i

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Dave Coventry
Thanks to everybody for the assistance. 2010/5/4 Jorge Armando Medina : > Im afraid this cannot be achieved with simple static routes, you need to > setup a interceptor proxy so outgoing http traffic is intercepted by > your router and then transparent redirec it to your squid box. Yes, I rather

Re: [squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Silamael
On 05/04/2010 01:42 AM, Brett Lymn wrote: > On Mon, May 03, 2010 at 05:08:29PM +0200, Silamael wrote: > >> Fix include order to ensure that FD_SETSIZE from the compat/fdsetsize.h is >> set >> before it is set by sys/select.h (included by stdlib.h). >> > > To be strictly correct about this, the p

Re: [squid-users] Web client not capable of SSL

2010-05-03 Thread D.Veenker
No problem at all. We are developing an application consuming a SOAP-service. The application is build in 4th dimension (www.4d.com). It's a database platform with a pretty extensive coding language. To be honest it is possible to use SSL, but not in combination with client certificates. Addi

Re: [squid-users] If not modified since is causing near-hits

2010-05-03 Thread Amos Jeffries
On Mon, 3 May 2010 13:28:21 -0700, David Raccah wrote: > Hello, > > Please excuse the newbie. I checked most of the search engines on > squid pages and could not find what I was looking for. Though it may > be because I did not use the correct keywords. > > So we have a large set of squid boxe

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Jorge Armando Medina
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 05/03/2010 09:33 PM, Amos Jeffries wrote: > On Mon, 3 May 2010 17:52:19 -0500, Luis Daniel Lucio Quiroz > wrote: >> Le lundi 3 mai 2010 17:11:00, Jorge Armando Medina a écrit : >>> Dave Coventry wrote: I need to add a proxy server to our offi

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Jose Ildefonso Camargo Tolosa
Hi! On Mon, May 3, 2010 at 5:11 PM, Dave Coventry wrote: > I need to add a proxy server to our office network. > > The router/modem is a DLink G604T and I want all requests for Internet > access to be re rerouted to a Debian box with Squid Installed. > > How do I set this up? Some questions: 1.

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Amos Jeffries
On Mon, 3 May 2010 17:52:19 -0500, Luis Daniel Lucio Quiroz wrote: > Le lundi 3 mai 2010 17:11:00, Jorge Armando Medina a écrit : >> Dave Coventry wrote: >> > I need to add a proxy server to our office network. >> > >> > The router/modem is a DLink G604T and I want all requests for Internet >> >

Re: [squid-users] Web client not capable of SSL

2010-05-03 Thread Jose Ildefonso Camargo Tolosa
Hi! On Sun, May 2, 2010 at 7:13 AM, D.Veenker wrote: > My web client is not capable of SSL and definitely no client certificates. Ok I *have* to ask, I can't help it, it is my nature I have to ask this: what web client is this, that doesn't support SSL? (https). Sorry for the "off-topi

Re: [squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Brett Lymn
On Mon, May 03, 2010 at 05:08:29PM +0200, Silamael wrote: > Fix include order to ensure that FD_SETSIZE from the compat/fdsetsize.h is set > before it is set by sys/select.h (included by stdlib.h). > To be strictly correct about this, the problem is really an OpenBSD one. There should not be an

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Luis Daniel Lucio Quiroz
Le lundi 3 mai 2010 17:11:00, Jorge Armando Medina a écrit : > Dave Coventry wrote: > > I need to add a proxy server to our office network. > > > > The router/modem is a DLink G604T and I want all requests for Internet > > access to be re rerouted to a Debian box with Squid Installed. > > Im afra

Re: [squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Jorge Armando Medina
Dave Coventry wrote: > I need to add a proxy server to our office network. > > The router/modem is a DLink G604T and I want all requests for Internet > access to be re rerouted to a Debian box with Squid Installed. > Im afraid this cannot be achieved with simple static routes, you need to setup

Re: [squid-users] Web client not capable of SSL

2010-05-03 Thread Henrik Nordström
mån 2010-05-03 klockan 22:34 +0200 skrev D.Veenker: > cache_peer www.binsearch.info sibling 443 0 no-query default ssl > sslflags=DONT_VERIFY_DOMAIN proxy-only That should be a parent, and you also need the originserver flag. cache_peer www.binsearch.info parent 443 0 originserver no-query defa

[squid-users] Slightly OT: Configuring a router for Squid.

2010-05-03 Thread Dave Coventry
I need to add a proxy server to our office network. The router/modem is a DLink G604T and I want all requests for Internet access to be re rerouted to a Debian box with Squid Installed. How do I set this up? I notice that the Router has an advanced option called 'Routing' which defines the Routi

Re: [squid-users] Web client not capable of SSL

2010-05-03 Thread D.Veenker
Well, I'm almost there. My config now looks like this ... --- http_port 8080 http_access allow all cache_peer www.binsearch.info sibling 443 0 no-query default ssl sslflags=DONT_VERIFY_DOMAIN proxy-only acl binsearch dstdomain www.binsearch.info never_direct allow binsearch

[squid-users] If not modified since is causing near-hits

2010-05-03 Thread David Raccah
Hello, Please excuse the newbie. I checked most of the search engines on squid pages and could not find what I was looking for. Though it may be because I did not use the correct keywords. So we have a large set of squid boxes sitting in front of some slow running code. The data is mostly stat

RE: [squid-users] Squid3 and authenticating users SASL/MYSQL

2010-05-03 Thread Simon Brereton
> From: Amos Jeffries > Sent: Saturday, May 01, 2010 2:16 AM > > Finally, I opted for editing basic_db_auth (I would have opened it > up even if I didn't need to change the @PERL@ and when I saw the my > options in there, I figured that would be easiest route). However - > and this may not be r

[squid-users] redirect from http to https with url_rewrite

2010-05-03 Thread Peter Vereshagin
I know St. Peter won't call your name, squid-users! I have the redirector to rewrite arbitrary url to the https url. I use redirector feature for this and everything is just fine with HTTP/302 feature use or with rewriting to the same but http url either. Rewrite is as follows ( in the case of a

Re: [squid-users] SSH not working With Squid3.0

2010-05-03 Thread John Doe
From: "a...@gmail" > Before I installed Squid3.0 I could access every host's > ssh server, but not since no matter what I do I simply cannot access the back > end SSH servers First, it would help if you described your configuration... Only problem I could guess is that you intercept ALL (ssh in

Re: [squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Silamael
On 05/03/2010 02:04 PM, Amos Jeffries wrote: > Thanks for the thought, but... > > Code in Squid is NOT permitted to include system headers before the > FD_* compat code. Kernel defines will be allocated with incompatible > size and overflows happen. > > Can you provide a full compiler trace of t

Re: [squid-users] SSH not working With Squid3.0

2010-05-03 Thread Jeff Pang
2010/5/3 a...@gmail : > Hello All, > > I have posted this already but haven't seen any reply > > I am using Squid3.0 > Only one SSH account works in my entire netwoirk, I can only access the SSH > that is running on the same machine as the Squid > Despite the fact I forward requets to all other SSH

[squid-users] Peer cache behavior with expired objects

2010-05-03 Thread Paul.Buchanan
Hi, I'm experimenting with 2 Squid 3.1.1 instances in reverse proxy mode. They are configured to be peers of each other using ICP. I'm not using digests. When a cached resource has not yet expired, each instance will successfully contact the other to retrieve the resource. However, when the res

[squid-users] SSH not working With Squid3.0

2010-05-03 Thread a...@gmail
Hello All, I have posted this already but haven't seen any reply I am using Squid3.0 Only one SSH account works in my entire netwoirk, I can only access the SSH that is running on the same machine as the Squid Despite the fact I forward requets to all other SSH servers in my network absolutely

Re: [squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Silamael
On 05/03/2010 02:04 PM, Amos Jeffries wrote: > Silamael wrote: >> Hello! >> >> I'm getting some error when compiling Squid 3.1.3 on OpenBSD 4.6 due to >> a redefinition of FD_SETSIZE in compat/fdsetsize.h. >> Patch attached which fixed this for me. >> >> Greetings, >> Matthias >> > > Thanks for th

Re: [squid-users] Squid not redirecting to squidGuard

2010-05-03 Thread Landy Landy
> I'm not  sure you should use redirector_bypass on, > turn it off. > If that doesnt works, then: I had it turned off before and it still didn't work. > Just to be 100% sure, add this line > url_rewrite_access allow all Looks like this did it. Thanks. Now I have to make sure it really works sin

Re: [squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Amos Jeffries
Silamael wrote: Hello! I'm getting some error when compiling Squid 3.1.3 on OpenBSD 4.6 due to a redefinition of FD_SETSIZE in compat/fdsetsize.h. Patch attached which fixed this for me. Greetings, Matthias Thanks for the thought, but... Code in Squid is NOT permitted to include system hea

Re: [squid-users] client_lifetime

2010-05-03 Thread Amos Jeffries
Ivan . wrote: Hi I chain from two internal Clearswift appliances to a Squid box in a DMZ. I have noticed quite a few WARNING: Closing client connection due to lifetime timeout The client_lifetime is set at default, but I was wondering if I should stretch that right out to 365 days or alike, s

[squid-users] OpenBSD 4.6: Squid 3.1.3 compilation error (patch attached)

2010-05-03 Thread Silamael
Hello! I'm getting some error when compiling Squid 3.1.3 on OpenBSD 4.6 due to a redefinition of FD_SETSIZE in compat/fdsetsize.h. Patch attached which fixed this for me. Greetings, Matthias Fix redefinition error for FD_SETSIZE on OpenBSD 4.6. --- compat/fdsetsize.h.orig Mon May 3 12:56:05

Re: [squid-users] make squid-3.1.1

2010-05-03 Thread Amos Jeffries
lieven wrote: Thank you Henrik. I just tried your suggestion and emptied the base64.c file. It did solve one problem but a new one arises. I took following actions: make clean ./configure make and now it stops like this: Maybe I can just compile the squid_kerb_auth helper and install the

Re: [squid-users] Authentication Reverse Proxy

2010-05-03 Thread Amos Jeffries
GIGO . wrote: Hi, What is the behaviour/mechanism of authentication if using squid proxy for both as forward proxy and reverse proxy. I have successfully setup it for a forward proxy using the Helper files by Markus and the following tutorial; http://wiki.squid-cache.org/ConfigExamples/Authent

Re: [squid-users] Squid not redirecting to squidGuard

2010-05-03 Thread Amos Jeffries
Landy Landy wrote: Hello all. I've been trying to get squidguard to work but, I'm having a problem: I noticed is squid is not redirecting any traffic to squidguard. When I do a dry-run with squidGuard: echo "http://www.playboy.com - - GET" | /usr/local/squidGuard/bin/squidGuard -c /usr/local/

Re: [squid-users] wedged (newbie question)

2010-05-03 Thread Matus UHLAR - fantomas
> On Thu, Apr 22, 2010 at 10:55 PM, Glenn English wrote: > > Squid started taking a very long time to supply web pages. Switching > > Firefox to 'no proxy' worked, so I restarted squid. All better now > > (proxy back on). Do I need to set up a cron job to restart squid every > > few weeks? On 22.

Re: [squid-users] Getting Source-IP

2010-05-03 Thread Matus UHLAR - fantomas
> On Thu, Apr 22, 2010 at 8:57 PM, Andreas Müller wrote: > > So I thought that the is an option to inject custom headers into the > > request. But if this is not possible than I have to do the best out of > > X_FORWARDED_FOR. On 22.04.10 21:31, Jeff Pang wrote: > From my experience, never much be

Re: [squid-users] make squid-3.1.1

2010-05-03 Thread lieven
Thank you Henrik. I just tried your suggestion and emptied the base64.c file. It did solve one problem but a new one arises. I took following actions: make clean ./configure make and now it stops like this: gcc -g -O2 -Wall -Wextra -Werror -Wcomment -Wpointer-arith -Wcast-align -Wwrite-str

Re: [squid-users] SQUID3: Access denied connecting to one site

2010-05-03 Thread Matus UHLAR - fantomas
>> Alexandr Dmitriev wrote: >>> Ok, the headers are broken, but there is a way to make squid ignore >>> them? >>> About ssl - they also have another domain www.airbaltic.com which is >>> not accessible either. > 22.04.2010 8:29, Amos Jeffries пишет: >> Part of the point was that they are not e