[squid-users] No proxy, with Captive portal and Reporting through Squid

2012-11-01 Thread Neil
Hi guys, I know this is probably a tough ask, but this question keeps being asked of us, and I don't have any answers unless clients spend thousands on proprietary devices. I need to be able to capture http(ideally https as well) without proxies being specified on the clients(IPADS, Galaxies,

Re: [squid-users] No proxy, with Captive portal and Reporting through Squid

2012-11-01 Thread Amos Jeffries
On 1/11/2012 8:02 p.m., Neil wrote: Hi guys, I know this is probably a tough ask, but this question keeps being asked of us, and I don't have any answers unless clients spend thousands on proprietary devices. I need to be able to capture http(ideally https as well) without proxies being

AW: [squid-users] Re: No Kerberos Auth

2012-11-01 Thread Jarosch, Ralph
Wonderfull now it works But i`ve got a little bit slow. Is there any limitation how many negotiate_wrapper I can start ? Actually I use 250 and everyone is still busy -Ursprüngliche Nachricht- Von: Markus Moeller [mailto:hua...@moeller.plus.com] Gesendet: Mittwoch, 31. Oktober

RE: [squid-users] Squid and SSL interception (ssl-bump)

2012-11-01 Thread Heinrich Hirtzel
You are missing the intercept flag on https_port. That is what tells Squid how to interpret the URL and TCP layer differences in the port 80 and 443 syntax traffic. I've already tried that (with 3.1.20, since 3.2.3 isn't working here at all), but the client web browser just get

AW: [squid-users] Re: No Kerberos Auth

2012-11-01 Thread Jarosch, Ralph
Hello Markus, i`ve found some answere from you in this thread http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-kerb-auth-High-CPU-load-td4569213.html where you wrote that it is better to deactivate the Kerberos replay cache by KRB5RCACHETYPE=none export KRB5RCACHETYPE So I have made

AW: [squid-users] Re: No Kerberos Auth

2012-11-01 Thread Jarosch, Ralph
OK i found the Problem, If Kerberos activated I have the following iostat Device: rrqm/s wrqm/s r/s w/srkB/swkB/s avgrq-sz avgqu-sz await svctm %util sda 0,00 1306,600,00 192,20 0,00 5779,2060,14 12,77 59,86 3,34 64,16 dm-0

[squid-users] Re: HTTPS traffic in normal transparent proxy

2012-11-01 Thread Markus
Hi, I have some similar problem. Because my tablet has no proxy support I want to realize a transparent proxy for http and https requests. Moreover, all http and https request should be routet through a parent proxy server. my squid.conf: cache_peer IP parent 8080 0 proxy-only no-query default

Re: [squid-users] Re: HTTPS traffic in normal transparent proxy

2012-11-01 Thread Eliezer Croitoru
On 11/1/2012 6:29 PM, Markus wrote: Is there a problem that the transparent https request will be routed via the parent proxy? Regards, Markus There is a problem with security using a parent proxy since while you intercept the https connection you can't use CONNECT method on a cache-peer as a

[squid-users] Problem creating cache

2012-11-01 Thread Markus Moeller
I try to create the cache with squid 3.2.2 but without success. How can I debug this ? -X does not give anything useful. # /opt/squid-3.2/sbin/squid -z -F 2012/11/01 23:56:09| WARNING: (B) '127.0.0.1' is a subnetwork of (A) '127.0.0.1' 2012/11/01 23:56:09| WARNING: because of this '127.0.0.1'

[squid-users] Re: Re: No Kerberos Auth

2012-11-01 Thread Markus Moeller
Are you sure the rcache was disabled ? Do you also use squid_kerb_ldap ? Markus Jarosch, Ralph ralph.jaro...@justiz.niedersachsen.de wrote in message news:c644cb972edfa3488cfd140b498136231b5eb...@justizcembx14.justiz.niedersachsen.de... OK i found the Problem, If Kerberos activated I have

Re: [squid-users] Squid and SSL interception (ssl-bump)

2012-11-01 Thread Amos Jeffries
On 2/11/2012 12:17 a.m., Heinrich Hirtzel wrote: You are missing the intercept flag on https_port. That is what tells Squid how to interpret the URL and TCP layer differences in the port 80 and 443 syntax traffic. I've already tried that (with 3.1.20, since 3.2.3 isn't working here at all), but