[squid-users] ssl interception causes "zero byte replies" sometimes

2012-12-11 Thread Sean Boran
Hi, It happens a few times daily that on submitting a login request to sites like Atlassian confluence (not just at atlassian, but elsewhere too), or Redmine, that the user gets a screen "The requested URL could not be retriueved" and with a "zero sized reply". It does not happen every time. If

RE: RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammad Shehata
Dears, sorry but I've an urgent case, is there any Ideas about the JS issues in squid3 From: Muhammad Shehata Sent: Tuesday, December 11, 2012 9:32 AM To: Eliezer Croitoru; squ...@treenet.co.nz Cc: squid-users@squid-cache.org Subject: RE: [squid-users] Squi

Re: RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread 叶雨飞
Try lowering MTU to 1400 on squid's system , sometime that's a non-obvious problem. On Tue, Dec 11, 2012 at 1:58 AM, Muhammad Shehata wrote: > Dears, > sorry but I've an urgent case, is there any Ideas about the JS issues in > squid3 > > > From: Muhammad

[squid-users] access_log, squid and NTLM : HaProxy

2012-12-11 Thread David Touzeau
Dear I’m using HaProxy in order to balance with 2 squids 3.2x connected to Active Directory with NTLM The NTLM is correctly forwarded to the Squid. But in access_log, squid did not write the NTLM session username. in debug mode, i correctly see NTLM forwarded by HaProxy eg: Host: www.google-an

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Marcus Kool
I have problems with optimizely.com for a long time. When I use a proxy in the USA, retrieving websites is OK but when I stop using the proxy in the USA it fails to load. I live in Brazil and you have a problem being in Egypt so my guess is that optimizely.com hangs when you are in a country for

RE: RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammad Shehata
Dear Sunyconq, Thanks for your update, but actually I modified the MTU and there is no diferrence at all I think it's related to java script handling method in squid2 and squid3 as the squid2 get it but squid 3 abort it which cause the slowness Best regards, Muhammed Shehata IT

RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammad Shehata
Dear Macus, Actually I don't think so as It being get on squid2 as below TCP_MISS/200 17298 GET http://cdn.optimizely.com/js/128727546.js - DIRECT/23.50.196.211 /javascript Best regards, Muhammed Shehata IT Network Security Engineer TE Data Building A11- B90, 2nd floor Smart Village, Cai

RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammad Shehata
Dear Macus, Actually I don't think so as It being get on squid2 as below TCP_MISS/200 17298 GET http://cdn.optimizely.com/js/128727546.js - DIRECT/23.50.196.211 /javascript Best regards, Muhammed Shehata IT Network Security Engineer TE Data Building A11- B90, 2nd floor Smart Village, Ca

[squid-users] tcp_outgoing_mark + https

2012-12-11 Thread Sébastien WENSKE
Hi List, I'm trying the "tcp_outgoing_mark" feature with dstdomain acls in order to "route" web traffic on several WAN links, but I noticed that it doesn't works with https requests. Does someone know how to achieve this? Many Thanks. Sebastien smime.p7s Description: S/MIME cryptographic sign

Re: [squid-users] tcp_outgoing_mark + https

2012-12-11 Thread Eliezer Croitoru
Hey Sebastien, Are you using ssl-bump at all? or just plain CONNECT requests? Else then the problem If you can explain more about the situation or the goal in more the just ROUTE web traffic over WAN connections. Do you have preference for specific routes? maybe you just want to load-balance?

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Eliezer Croitoru
Hey Muhammad, I do understand your problem but the issue you are having is most likely not due to any squid preferences. In most cases squid handles the request in the basic level of headers and then pipe the request to the client directly(maybe using a buffer). The only case which squid will

[squid-users] RE : [squid-users] tcp_outgoing_mark + https

2012-12-11 Thread Sébastien WENSKE
Hi Eliezer, I'm not using SSL-Bump, I have a 100Mbit/s fiber connection and an SDSL 4Mbit/s. By default, all traffic goes through the SDSL except traffic to our production and VPN site-to-site. Squid running on the same box where I use shorewall to route marked packets and is directly connecte

[squid-users] RE: cachemgr.cgi "Store Directory Stats" with multiple cache_dir lines

2012-12-11 Thread Mike Mitchell
I think my problem with "Store Directory Stats" and Rock store is related to bug #3694, http://bugs.squid-cache.org/show_bug.cgi?id=3694 I also am hitting bug #3640 http://bugs.squid-cache.org/show_bug.cgi?id=3640 when I rotate the logs. I'm working around the bug by using logfile_rotate

[squid-users] Re: RE : [squid-users] tcp_outgoing_mark + https

2012-12-11 Thread Eliezer Croitoru
Hey Sébastien, What linux and what squid version? It's different if your logic is "all to 100Mbit connection" to "just these to 100Mbit connection". If you can share your squid.conf and remove the sensitive data it will maybe give us more info. Regards, Eliezer On 12/11/2012 7:47 PM, Sébasti

RE: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammad Shehata
Dear Eliezer, Thanks for your replay But actually it is the same user behavior (me only trying request cnn.com and waiting to get it on my browser ) using the same browser through the same squid proxy with the same configuration and same network devices before and after them the only difference

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Eliezer Croitoru
What linux? RH ? On 12/11/2012 10:00 PM, Muhammad Shehata wrote: Dear Eliezer, Thanks for your replay But actually it is the same user behavior (me only trying request cnn.com and waiting to get it on my browser ) using the same browser through the same squid proxy with the same configuration

[squid-users] Authentication of non-standard methods

2012-12-11 Thread Trever L. Adams
Hello Everyone, I am looking at Shibboleth. I have seen one example (http://www.switch.ch/aai/support/presentations/opcom-201105/AAI-OpCom-AAI_for_mandatory_authentication_and_proxy_usage.pdf) for using it with Squid. I am afraid it makes no sense to me. I am afraid I do not know much about Shibb

Re: [squid-users] Authentication of non-standard methods

2012-12-11 Thread Amos Jeffries
On 12.12.2012 11:33, Trever L. Adams wrote: Hello Everyone, I am looking at Shibboleth. I have seen one example (http://www.switch.ch/aai/support/presentations/opcom-201105/AAI-OpCom-AAI_for_mandatory_authentication_and_proxy_usage.pdf) for using it with Squid. I am afraid it makes no sense to

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-11 Thread Muhammed Shehata
Eliezer, squid2 > centos 5.2 final squid3 > centos 6.3 final Mshehata IT NS On 12/11/2012 10:03 PM, Eliezer Croitoru wrote: What linux? RH ? On 12/11/2012 10:00 PM, Muhammad Shehata wrote: Dear Eliezer, Thanks for your replay But actually it is the same user behavior (me only trying request

RE: [squid-users] Re: RE : [squid-users] tcp_outgoing_mark + https

2012-12-11 Thread Sébastien WENSKE
Eliezer, I'm running Debian 6 with a 3.6.9 kernel, Shorewall is v4.5.9.3 and Squid 3.2.3 (I had some troubles to compile 3.2.4) Indeed, "just these to 100Mbit connection" is what I need :) squid.conf