Re: [squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-22 Thread Francesco
What happens if you leave Squid running but terminate the TCP connections open between Squid and the AD server? Or just the TCP connections client-Squid for the one user who is looping? Hello Amos, could you please explain latest question, i did not understand! Thank you again! Francesco

[squid-users] slow browsing in centos 6.3 with squid 3 !!

2013-02-22 Thread Ahmad
hi , i have server delr720 . i have centos 6.3 x68_64 bit , with kernel 3.7.5 compiled with tproxy support i have ram 32 Giga . i have 4 hardsiks as follow: hardisk#1==opertaing system 170 giga ssd hardsik with name sda hardsik#2 , hardsik#3 , hardsik#4 , ===had been as raid 0 with name sdb

RE: [squid-users] slow browsing in centos 6.3 with squid 3 !!

2013-02-22 Thread Anders.Larsson
As I remember when adding some blacklist in squidguard I get bad performance..that was to big to parse.. I use the ufdbguard today.. Works very vell. Running 5000 users and SSO with kerbauth for the users and clam/havp to scan semless everything that downloads Try to disable some of the big

[squid-users] Re: slow browsing in centos 6.3 with squid 3 !!

2013-02-22 Thread Ahmad
hi , i want to say that the problem exist in the presence and absense of squidguard . i note that the storing on the hardsik is slow relative to the users pumped to squid !! did u have a look on squid.conf file ? i think it need some modification enhacements . with my best regards --

[squid-users] Re: slow browsing in centos 6.3 with squid 3 !!

2013-02-22 Thread Ahmad
my squidguard version [root@squid ~]# squidGuard -v SquidGuard: 1.4 Berkeley DB 4.7.25: (April 4, 2012) with it help regards -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/slow-browsing-in-centos-6-3-with-squid-3-tp4658635p4658638.html Sent from the

Re: [squid-users] Re: squid kerberos authenticators spamming AD and locking out users

2013-02-22 Thread Francesco
For the first problem, is it possible to set the casesensitive off directive? It seems possible only for basic authentication. Thank you! Francesco

Re: [squid-users] HAVP alternative for traffic scanning?

2013-02-22 Thread Henri Wahl
Does anybody have experience with dansguardian + clamav or dansguardian + commandline av scanner? Regards -- Henri Wahl IT Department Leibniz-Institut für Festkörper- u. Werkstoffforschung Dresden tel: (03 51) 46 59 - 797 email: h.w...@ifw-dresden.de http://www.ifw-dresden.de Nagios status

[squid-users] Kerberos/NTLM Issue

2013-02-22 Thread JC Putter
I followed the guide below as a starting point for my squid proxy, however authentication fails after a day or so (i think due to account reset) I am using squid 3.2.6 with msktutil ERROR: Negotiate Authentication validating user. Error returned 'BH NT_STATUS_ACCESS_DENIED' I am running a

[squid-users] Pragma: no-cache

2013-02-22 Thread FredB
Hello, With latest version squid 3.2.7, pragma: no-cache seem doesn't work like before, it's very annoying with some admin page ... Sites with this values are in cache, with previous version no. Hypertext Transfer Protocol HTTP/1.1 200 OK Server: nginx/0.7.6 Date: Fri, 22 Feb 2013

[squid-users] Re: Re: squid kerberos authenticators spamming AD and locking out users

2013-02-22 Thread Markus Moeller
Brett Lymn brett.l...@baesystems.com wrote in message news:20130221233448.ga...@baea.com.au... On Thu, Feb 21, 2013 at 11:23:32PM +, Markus Moeller wrote: I don't think this has to do with squid and Kerberos. Reasonably sure it does - for a start the machine that AD says is causing

[squid-users] Re: Kerberos/NTLM Issue

2013-02-22 Thread JC Putter
If I rejoin the account using net ads join the RPC trust is established as soon as you do a msktutil update the trust fails... Anyone know of a workaround ? On Fri, Feb 22, 2013 at 1:25 PM, JC Putter jcput...@gmail.com wrote: I followed the guide below as a starting point for my squid proxy,

RE: [squid-users] Redirect Youtube out second ISP

2013-02-22 Thread Stinn, Ryan
Using this: http://www.squid-cache.org/Doc/config/tcp_outgoing_tos/ To mark the TOS on traffic to youtube. Then using what to redirect them out the different link? Iptables? Ryan Stinn Holy Trinity Catholic School Division -Original Message- From: Amos Jeffries

Re: [squid-users] tproxy configuration

2013-02-22 Thread Roman Gelfand
Thanks for taking time to help me out. If I understood you correctly, I think I made the changes you mentioned including iptables -A FORWARD -i eth0 -j ACCEPT line. still no luck. Below, is the is the diagnostics. Chain PREROUTING (policy ACCEPT 13 packets, 8499 bytes) pkts bytes target

[squid-users] Re: Kerberos/NTLM Issue

2013-02-22 Thread Markus Moeller
If you use Kerberos and NTLM do not use the same AD account. Samba will update the AD account (e.g. change account password after x days) and msktutil does the same. So you will always have a problem if you do not use seperate AD accounts and there is nor reason to use the same. Markus JC

Re: [squid-users] Transparent Proxy and Authentication

2013-02-22 Thread Roman Gelfand
Please, consider the network topology below. I could always configure outgoing http traffic on the firewall to authenticate with firewall user. How is this different from having squid authenticate in transparent mode? WAN

Re: [squid-users] Transparent Proxy and Authentication

2013-02-22 Thread Amos Jeffries
On 23/02/2013 8:48 a.m., Roman Gelfand wrote: Please, consider the network topology below. I could always configure outgoing http traffic on the firewall to authenticate with firewall user. How is this different from having squid authenticate in transparent mode? That is a good question.

[squid-users] About bottlenecks (Max number of connections, etc.)

2013-02-22 Thread Manuel
Hi, We are having problems with our Squid servers during traffic peaks. We had problems in the past and we got different error such as Your cache is running out of filedescriptors, syncookies errors, etc. but nowadays we have optimized that and we are not getting those errors anymore. The problem

Re: [squid-users] Pragma: no-cache

2013-02-22 Thread Amos Jeffries
On 23/02/2013 2:53 a.m., FredB wrote: Hello, With latest version squid 3.2.7, pragma: no-cache seem doesn't work like before, it's very annoying with some admin page ... Sites with this values are in cache, with previous version no. Hypertext Transfer Protocol HTTP/1.1 200 OK

Re: [squid-users] Redirect Youtube out second ISP

2013-02-22 Thread Amos Jeffries
On 23/02/2013 4:13 a.m., Stinn, Ryan wrote: Using this: http://www.squid-cache.org/Doc/config/tcp_outgoing_tos/ To mark the TOS on traffic to youtube. Then using what to redirect them out the different link? Iptables? Yes. Whatever TCP QoS functionality your system provides for routing based

[squid-users] Caching online game patches and updates

2013-02-22 Thread Firas Mubarak
Hi all, I work for a small online gaming place, my customers are playing online games there such as WOW or LOL.. As those games has lots of updates I decided to install a squid proxy. It works fine caching downloaded files and pages but not caching the game updates. So whenever a new update is

Re: [squid-users] Re: slow browsing in centos 6.3 with squid 3 !!

2013-02-22 Thread Amos Jeffries
On 22/02/2013 9:57 p.m., Ahmad wrote: hi , i want to say that the problem exist in the presence and absense of squidguard . i note that the storing on the hardsik is slow relative to the users pumped to squid !! Yes. You are using RAID. http://wiki.squid-cache.org/SquidFaq/RAID RAID-0