[squid-users] DNS config - squid

2010-09-14 Thread viswa
Hi All is it possible to configure squid to use different DNS server for different clients ? example if request from 172.16.1.25 then DNS response from dns-server-1, otherwise is dns-server-2 ? Thanks in advance. Cheers -Viswa

Re: [squid-users] WCCP + Squid with Cisco 2811. Not working

2010-09-14 Thread Amos Jeffries
On Tue, 14 Sep 2010 14:09:52 -0400, "Chris Abel" wrote: > Amos Jeffries writes: >> >>I'm trying to remember how we debugged these issues previously. >> * It sounds a lot like rp_filter deleting the packets in its >>anti-spoofing security. A cache.log trace with debug_options 5,9 89,9 >>should sho

Re: [squid-users] ntlm and internet explorer

2010-09-14 Thread Amos Jeffries
On Tue, 14 Sep 2010 08:25:02 -0500, Terry wrote: > On Tue, Sep 14, 2010 at 1:52 AM, Isaac NickAein > wrote: >> How about Digest authentication? >> >> Does digest is as weak as NTLM? Digest has security-level extensions that can be dialed from "session" equivalent to a slightly safer Basic auth,

Re: [squid-users] Trouble between Squid and SSL proxied host

2010-09-14 Thread Amos Jeffries
On Tue, 14 Sep 2010 17:40:53 -0700 (PDT), mikek wrote: > Hi There > > I've just setup a Squid proxy hosted on EC2 between my users and a Google > AppEngine application. (Google AppEngine currently doesn't support custom > domain SSL, so this is the only way to do it.) > > (I was following the

Re: [squid-users] RE: squid/3.0.STABLE7 - File Desc issues

2010-09-14 Thread Amos Jeffries
On Tue, 14 Sep 2010 18:48:23 -0500, Jordon Bedwell wrote: > On 09/14/2010 03:38 PM, donald.daw...@bakerbotts.com wrote: >> I had the same issue. We are running Squid 3.1.4 installed via yum. We >> can increase our FDs. On our compiled Squid servers, our only option is >> to recompile with a larg

[squid-users] Trouble between Squid and SSL proxied host

2010-09-14 Thread mikek
Hi There I've just setup a Squid proxy hosted on EC2 between my users and a Google AppEngine application. (Google AppEngine currently doesn't support custom domain SSL, so this is the only way to do it.) (I was following the instructions here: http://blog.earlystageit.com/2010/07/10/gae-proxy/

Re: [squid-users] RE: squid/3.0.STABLE7 - File Desc issues

2010-09-14 Thread Jordon Bedwell
On 09/14/2010 03:38 PM, donald.daw...@bakerbotts.com wrote: > I had the same issue. We are running Squid 3.1.4 installed via yum. We > can increase our FDs. On our compiled Squid servers, our only option is > to recompile with a larger FD amount. > > If you have a yum or install from an rpm, you

[squid-users] RE: squid/3.0.STABLE7 - File Desc issues

2010-09-14 Thread donald.dawson
I had the same issue. We are running Squid 3.1.4 installed via yum. We can increase our FDs. On our compiled Squid servers, our only option is to recompile with a larger FD amount. If you have a yum or install from an rpm, you can edit your /etc/init.d/squid startup script add set the ulimit bef

[squid-users] Re: squid client authentication against AD computer account

2010-09-14 Thread Markus Moeller
"Manoj Rajkarnikar" wrote in message news:aanlktingxtowx+aysrvgoaseiqrs1qrmx2vym8t5i...@mail.gmail.com... Hi all. I've been trying to setup this squid box with authentication to AD 2003 server. The need in our situation is to allow the workstation allow access to internet and not the user sin

Re: [squid-users] WCCP + Squid with Cisco 2811. Not working

2010-09-14 Thread Chris Abel
Amos Jeffries writes: > >I'm trying to remember how we debugged these issues previously. > * It sounds a lot like rp_filter deleting the packets in its >anti-spoofing security. A cache.log trace with debug_options 5,9 89,9 >should show the connections arriving at Squid. I've used the following com

Re: [squid-users] ntlm and internet explorer

2010-09-14 Thread Terry
On Tue, Sep 14, 2010 at 1:52 AM, Isaac NickAein wrote: > How about Digest authentication? > > Does digest is as weak as NTLM? > > and another question: > > Is it possible to use Kerberos (actually Negotiate) protocol for squid > user authentication in a network without any Active Directory or > Do