Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Amos Jeffries
On 16/10/2012 6:14 p.m., Ricardo Rios - Shorewall List wrote: Testing version 3.2.2-20121015-r11677, i see problems with the max_filedesc on OpenSuSE 11.4 x64 server:/ # ulimit -n 65535 squid.conf : max_filedesc 65535 /etc/security/limits.conf * - nofile 65535 on cache.log :

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Esteban Torres Rodríguez
2012/10/16 Ricardo Rios - Shorewall List shorew...@malargue.gov.ar: Testing version 3.2.2-20121015-r11677, i see problems with the max_filedesc on OpenSuSE 11.4 x64 server:/ # ulimit -n 65535 squid.conf : max_filedesc 65535 /etc/security/limits.conf * - nofile 65535 on

[squid-users] Re: problem with squid 3.2 as transaparent proxy

2012-10-16 Thread Giovanni Rosini
Any ideas?? Pls help. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/problem-with-squid-3-2-as-transaparent-proxy-tp4656748p4656998.html Sent from the Squid - Users mailing list archive at Nabble.com.

Re: [squid-users] http_access traffic

2012-10-16 Thread Amos Jeffries
On 15/10/2012 9:33 p.m., Ibrahim Lubis wrote: I use this line to allowed some traffic Acl vlan2 src 10.10.13.0/24 Http_access allow vlan2 Can i monitor traffic with snmp for certain vlan i allowed? Thx Not easily. Squid records statistics per-client not per-subnet. You have to find the

Re: [squid-users] http_access traffic

2012-10-16 Thread Ibrahim Lubis
Logging daemon? syslog? what do you mean by other system? -Original Message- From: Amos Jeffries Sent: 16 Oct 2012 06:47:04 GMT To: squid-users@squid-cache.org Subject: Re: [squid-users] http_access traffic On 15/10/2012 9:33 p.m., Ibrahim Lubis wrote: I use this line to allowed some

[squid-users] problem with squid 3.2 as transaparent proxy

2012-10-16 Thread jeffrey j donovan
On Oct 16, 2012, at 2:36 AM, Giovanni Rosini gioros...@libero.it wrote: Any ideas?? Pls help. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/problem-with-squid-3-2-as-transaparent-proxy-tp4656748p4656998.html Sent from the Squid - Users

[squid-users] testing adaptation_service_sets

2012-10-16 Thread E.S. Rosenberg
Hi, I set up an adaptation_service_set on a test server and I would like to see if it's working but I don't seem to be able to trigger use of the second icap server in the pool by just browsing myself, any ideas how I can test this conclusively? Thanks, Eli

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Ricardo Rios
El 2012-10-16 03:17, Amos Jeffries escribió: On 16/10/2012 6:14 p.m., Ricardo Rios - Shorewall List wrote: Testing version 3.2.2-20121015-r11677, i see problems with the max_filedesc on OpenSuSE 11.4 x64 server:/ # ulimit -n 65535 squid.conf : max_filedesc 65535 /etc/security/limits.conf *

[squid-users] Squid and PAC file

2012-10-16 Thread mbaki
Hi all,   I'm trying to use 2 squid servers and I want to use a pac file to say for all sites use the squid server 1 but for all streaming server sites (youtube, netflix, cnn video, abcnews streaming etc etc) use the othjer server. Can a PAC file based on the file extension be

[squid-users] Managing user http bandwidth with squid cache

2012-10-16 Thread Alan Dawson
Hi, I'm at an educational establishment, with approx 2500 desktops. We have had a restrictive web access policy implemented with a web cache/filtering proxy appliance. User browsers are configured by a PAC file and web proxy auto discovery. They authenticate against the appliance with NTLM We

[squid-users] Dynamic Certs Squid 3.3

2012-10-16 Thread Jesse Smith
I am having a problem where, when visiting a secure URL, the browser just hangs when using Squid. There is nothing in the logs that indicate why. The configuration is set up to use dynamic ssl certs. Can anyone see anything wrong with the configuration below, or why this may be occurring? It

[squid-users] TCP_DENIED/403

2012-10-16 Thread Mike Muir
Hello, I'm getting a TCP DENIED/403 in the access log when trying to access all HTTPS sites via web browser. The browser displays: Error 111 (net::ERR_TUNNEL_CONNECTION_FAILED): Unknown error. I've included the following in my squid.conf (I'm using Squid 2.7) which to my understanding should

RE: [squid-users] TCP_DENIED/403

2012-10-16 Thread Andrew Krupiczka
Have you specified https_port 443 ... cert= http://www.squid-cache.org/Versions/v2/2.7/cfgman/https_port.html Regards, Andrew -Original Message- From: Mike Muir [mailto:mm...@uniqueltd.com] Sent: Tuesday, October 16, 2012 3:41 PM To: squid-users@squid-cache.org Subject: [squid-users]

Re: [squid-users] TCP_DENIED/403

2012-10-16 Thread Eliezer Croitoru
On 10/16/2012 9:41 PM, Mike Muir wrote: Hello, I'm getting a TCP DENIED/403 in the access log when trying to access all HTTPS sites via web browser. The browser displays: Error 111 (net::ERR_TUNNEL_CONNECTION_FAILED): Unknown error. I've included the following in my squid.conf (I'm using Squid

Re: [squid-users] TCP_DENIED/403

2012-10-16 Thread Mike Muir
My acl section and http_access: acl manager proto cache_object COAP acl localhost src 127.0.0.1/32 ::1 acl Whitelist dstdomain /etc/squid/whitelist_sites acl ncsa_users proxy_auth REQUIRED acl SSL_ports port 443 acl Safe_ports port 80 acl CONNECT method CONNECT acl all src all # cachemgr access

Re: [squid-users] testing adaptation_service_sets

2012-10-16 Thread Amos Jeffries
On 17.10.2012 02:51, E.S. Rosenberg wrote: Hi, I set up an adaptation_service_set on a test server and I would like to see if it's working but I don't seem to be able to trigger use of the second icap server in the pool by just browsing myself, any ideas how I can test this conclusively? Thanks,

Re: [squid-users] TCP_DENIED/403

2012-10-16 Thread Amos Jeffries
On 17.10.2012 09:49, Mike Muir wrote: My acl section and http_access: acl manager proto cache_object COAP acl localhost src 127.0.0.1/32 ::1 acl Whitelist dstdomain /etc/squid/whitelist_sites acl ncsa_users proxy_auth REQUIRED acl SSL_ports port 443 acl Safe_ports port 80 acl CONNECT method

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Amos Jeffries
On 17.10.2012 03:02, Ricardo Rios wrote: El 2012-10-16 03:17, Amos Jeffries escribió: On 16/10/2012 6:14 p.m., Ricardo Rios - Shorewall List wrote: Testing version 3.2.2-20121015-r11677, i see problems with the max_filedesc on OpenSuSE 11.4 x64 server:/ # ulimit -n 65535 squid.conf :

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread George Herbert
I still find this behavior slightly bizarre, that the ulimit in the build environment can affect the prod envt. And it keeps biting other people... -george On Tue, Oct 16, 2012 at 2:42 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 17.10.2012 03:02, Ricardo Rios wrote: El 2012-10-16 03:17,

Re: [squid-users] Squid and PAC file

2012-10-16 Thread Amos Jeffries
On 17.10.2012 03:21, mbaki wrote: Hi all, I'm trying to use 2 squid servers and I want to use a pac file to say for all sites use the squid server 1 but for all streaming server sites (youtube, netflix, cnn video, abcnews streaming etc etc) use the othjer server. Can a PAC file based on the

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Amos Jeffries
On 17.10.2012 10:48, George Herbert wrote: I still find this behavior slightly bizarre, that the ulimit in the build environment can affect the prod envt. And it keeps biting other people... It's not ulimit in the build environment particularly. Although the build environment might need

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread George Herbert
On Tue, Oct 16, 2012 at 3:00 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 17.10.2012 10:48, George Herbert wrote: I still find this behavior slightly bizarre, that the ulimit in the build environment can affect the prod envt. And it keeps biting other people... It's not ulimit in the

Re: [squid-users] max_filedesc on squid 3.2.2

2012-10-16 Thread Ricardo Rios
On 17.10.2012 03:02, Ricardo Rios wrote: El 2012-10-16 03:17, Amos Jeffries escribió: On 16/10/2012 6:14 p.m., Ricardo Rios - Shorewall List wrote: Testing version 3.2.2-20121015-r11677, i see problems with the max_filedesc on OpenSuSE 11.4 x64 server:/ # ulimit -n 65535 squid.conf :

Re: [squid-users] Managing user http bandwidth with squid cache

2012-10-16 Thread Amos Jeffries
On 17.10.2012 04:47, Alan Dawson wrote: Hi, I'm at an educational establishment, with approx 2500 desktops. We have had a restrictive web access policy implemented with a web cache/filtering proxy appliance. User browsers are configured by a PAC file and web proxy auto discovery. They

Re: [squid-users] Dynamic Certs Squid 3.3

2012-10-16 Thread Amos Jeffries
For starters 3.3 is not quite in beta yet, which means all questions need to be sent to squid-dev mailing list. This is a users list. Amos On 17.10.2012 06:04, Jesse Smith wrote: I am having a problem where, when visiting a secure URL, the browser just hangs when using Squid. There is

[squid-users] Testing squid 3.2.2-20121015-r11677

2012-10-16 Thread Ricardo Rios
So far i being using 3.2.2-20121015-r11677 today with about 20-40mb traffic for like 9 hours without any big problem, but just now i saw the traffic go down and up, checking logs and i see this : 2012/10/16 21:00:50 kid1| WARNING: An error inside Squid has caused an HTTP reply without Date:.

Re: [squid-users] Testing squid 3.2.2-20121015-r11677

2012-10-16 Thread Ricardo Rios
El 2012-10-16 21:11, Ricardo Rios escribió: So far i being using 3.2.2-20121015-r11677 today with about 20-40mb traffic for like 9 hours without any big problem, but just now i saw the traffic go down and up, checking logs and i see this : 2012/10/16 21:00:50 kid1| WARNING: An error inside

[squid-users] Trouble filtering/denying HTTPS traffic

2012-10-16 Thread Cameron Charles
Hi all, I am currently trying to setup basic url/domain level filtering on HTTPS traffic using an external acl, i can see clearly in the access log that the information i require is there and the external acl finds and filters it as desired, returning the correct response for deny/allow and i can

[squid-users] SSL Attacks against Squid in reverse proxy mode

2012-10-16 Thread Will Roberts
Hi, I'm using squid 3.1.20 as a reverse proxy to provide an SSL frontend as well as caching. I'm looking for configuration directives that would allow me to prevent squid from being susceptible to CRIME. Is there a way to pass a flag to the SSL library to disable compression (CRIME)?

Re: [squid-users] Trouble filtering/denying HTTPS traffic

2012-10-16 Thread Amos Jeffries
On 17/10/2012 4:08 p.m., Cameron Charles wrote: Hi all, I am currently trying to setup basic url/domain level filtering on HTTPS traffic using an external acl, i can see clearly in the access log that the information i require is there and the external acl finds and filters it as desired,

Re: [squid-users] Trouble filtering/denying HTTPS traffic

2012-10-16 Thread Cameron Charles
Thank you for the prompt and very informing reply, does this mean then that filtering https connections at the level i desire is not possible at all (using squid)?, also for information purposes firefox and safari do a similar job of handling, or not handling this situation, infact they provide