Re: [squid-users] Reverse Proxy not re-encrypt SSL

2012-12-13 Thread Jakob Curdes
Am 14.12.2012 01:23, schrieb David Touzeau: For this cache_peer i need to squid just forward SSL requests (CONNECT method) to the remote server and not re-encrypt the SSL in order to let the remote web server establishing the SSL tunnel. Is it possible to do that ? Or when settings accel 44

Re: [squid-users] Custom error page for HTTP status 400-404, 500

2012-12-13 Thread Paul Ch
Thanks Amos, this works perfectly. So cache_peer_access can block the request from even touching the peer where as http_reply_access would block it after it's been processed by the peer. Makes sence. Cheers! -- Paul Ch sima...@operamail.com On Fri, Dec 14, 2012, at 04:57 AM, Amos Jeffries

Re: [squid-users] Custom error page for HTTP status 400-404, 500

2012-12-13 Thread Amos Jeffries
On 14/12/2012 5:41 p.m., Paul Ch wrote: Hi, I am running a squid 3.2.1 server as a reverse proxy. I have several Microsoft Windows IIS servers as cache_peers. I am trying to setup a custom error page for various HTTP_STATUS codes such as 404 and 500. This is a relevant extract from my squid.c

[squid-users] Custom error page for HTTP status 400-404, 500

2012-12-13 Thread Paul Ch
Hi, I am running a squid 3.2.1 server as a reverse proxy. I have several Microsoft Windows IIS servers as cache_peers. I am trying to setup a custom error page for various HTTP_STATUS codes such as 404 and 500. This is a relevant extract from my squid.conf file: #squid config extract# acl den

Re: [squid-users] Port allow question

2012-12-13 Thread Amos Jeffries
On 14/12/2012 11:53 a.m., Paras pradhan wrote: Hi, I have 0-65536 in safe ports and it is allowed. acl Safe_ports port 0-65535 http_access deny !Safe_ports This is not an ALLOWED. This is a not-DENIED otherwise known as "check next rule". NP: there are a number of ports between 0-1024 ran

[squid-users] Reverse Proxy not re-encrypt SSL

2012-12-13 Thread David Touzeau
Dear I'm using Squid 3.2.4 in reverse mode with multiple SSL web servers I need to force squid to not use the default certificate for specific target Web servers and i did not know how to do... I'm turning around this issue... Example: http_port 80 accel vhost https_port 443 accel cert=/etc

Fw: [squid-users] access_log, squid and NTLM : HaProxy

2012-12-13 Thread David Touzeau
Dear I’m using HaProxy in order to balance with 2 squids 3.2x connected to Active Directory with NTLM The NTLM is correctly forwarded to the Squid. But in access_log, squid did not write the NTLM session username. in debug mode, i correctly see NTLM forwarded by HaProxy eg: Host: www.google-

[squid-users] Port allow question

2012-12-13 Thread Paras pradhan
Hi, I have 0-65536 in safe ports and it is allowed. acl Safe_ports port 0-65535 http_access deny !Safe_ports But I am seeing this in access.log. -- 1355433138.267 0 192.168.0.2 TCP_DENIED/403 3413 CONNECT 192.168.0.2:35357 - NONE/- text/html -- How do we allow 35357? Thanks! Paras.

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-13 Thread Amos Jeffries
On 13/12/2012 9:41 p.m., Muhammed Shehata wrote: Dear Amos, -the interrelation: the logs are from two squid similar servers that only differ in version and client at both request doesn't disconnect or anything the aborted maybe mean that squid can't get this url contains java script but what I

[squid-users] websites blocked using wccpv2 and squid2.7stable9

2012-12-13 Thread Mustafa Raji
hi i have a problem with certain websites , i'm using cisco router connecting to squid with wccpv2 configuration. the problem is one website i can't open it from the traffic that goes through the cache server, if i use the connection without the squid box i can reach the website normally, then i

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-13 Thread Eliezer Croitoru
Hey Muhammed, From my point of view if it's squid fault of making this error you are having, I and anyone else using the same version and build will have, am I right? So I am using squid 3.2.1-3 and 3.3.0.1 and I dont have any of the issues you are talking about. If you can come up with a

RE: [squid-users] 3.2.4 build problem

2012-12-13 Thread Alan Lehman
> On 13.12.2012 11:48, Alan Lehman wrote: > >> On 8/12/2012 11:02 a.m., Alan Lehman wrote: > >> > I'm having trouble building 3.2.4 on RHEL5. > >> > > >> > I configured with options : > >> > --enable-ssl --enable-useragent-log --enable-referer-log > >> > --with-filedescriptors=8192 --enable-delay-p

Re: [squid-users] ssl interception causes "zero byte replies" sometimes

2012-12-13 Thread Alex Rousskov
On 12/11/2012 02:40 AM, Sean Boran wrote: > Hi, > > It happens a few times daily that on submitting a login request to > sites like Atlassian confluence (not just at atlassian, but elsewhere > too), or Redmine, that the user gets a screen "The requested URL could > not be retriueved" and with a "

Re: [squid-users] Ideas for Squid statistics Web UI development

2012-12-13 Thread Marcello Romani
Il 19/11/2012 01:05, George Machitidze ha scritto: Hello I've started development of open sourced Web UI for gathering stats for Squid proxy server and need your help to clarify needs and resources. Where it came from: Enterprises require auditing, reporting, configuration check/visibility and

Re: [squid-users] Squid3 extremely slow for some website cnn.com

2012-12-13 Thread Muhammed Shehata
Dear Amos, -the interrelation: the logs are from two squid similar servers that only differ in version and client at both request doesn't disconnect or anything the aborted maybe mean that squid can't get this url contains java script but what I wonder of why squid can get it successfully -her

RE: [squid-users] tcp_outgoing_mark + https

2012-12-13 Thread Sébastien WENSKE
Hi Eliezer, I made the tests, and first, there is no IP in the CONNECT request: 13/Dec/2012:07:30:13.508 240535 10.4.10.25 TCP_MISS/200 14882 CONNECT www.kernel.org:443 - HIER_DIRECT/www.kernel.org - Now the debug: In HTTP, I see the ACL; 2012/12/13 08:45:03.434 kid1| ACLList::matches: checking