Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amos Jeffries
On 7/03/2013 7:22 p.m., Amm wrote: - Original Message - From: Amos Jeffries On 7/03/2013 5:30 p.m., Amm wrote: - Original Message - From: Amos Jeffries On 7/03/2013 2:03 a.m., Amm wrote: I just tried 443 port interception with sslbump and is working perfectly.

[squid-users] Is it possible use Squid and virtualization(xen or kvm) have a good performance ?

2013-03-06 Thread 金 戈
Hi, everyone! Last week, we start our plan to migrate all of our application server to the virtualization group. We use Squid as our cache system, we want to use xen as the host and use debian PV as guest. And the hardware info below: CPU : Intel(R) Xeon(R) CPU E5506 @ 2.13GHz X 2

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amm
- Original Message - > From: Amos Jeffries > To: squid-users@squid-cache.org > Cc: > Sent: Thursday, 7 March 2013 11:19 AM > Subject: Re: [squid-users] Bypassing SSL Bump for dstdomain > > On 7/03/2013 5:30 p.m., Amm wrote: >> - Original Message - >>> From: Amos Jeffries >>>

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amos Jeffries
On 7/03/2013 5:30 p.m., Amm wrote: - Original Message - From: Amos Jeffries On 7/03/2013 2:03 a.m., Amm wrote: I just tried 443 port interception with sslbump and is working perfectly. If sslbump none applies for request then it passes requests as is: Log shows something like th

[squid-users] Known memory leaks in 3.2.7?

2013-03-06 Thread Nathan Hoad
Hi folks, Are there are any known memory leaks in Squid 3.2.7? I'm running a configuration involving ntlm auth, and I've noticed in particular that AVG smashes Squid when it can't authenticate - this has caused Squid to consume all the available memory and eventually crash. I've reproduced this

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amm
- Original Message - > From: Amos Jeffries > To: squid-users@squid-cache.org > Cc: > Sent: Thursday, 7 March 2013 4:11 AM > Subject: Re: [squid-users] Bypassing SSL Bump for dstdomain > > On 7/03/2013 2:03 a.m., Amm wrote: >>> >> I just tried 443 port interception with sslbump and

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amos Jeffries
On 7/03/2013 2:03 a.m., Amm wrote: - Original Message - From: Amos Jeffries On 6/03/2013 1:40 p.m., Alex Rousskov wrote: On 03/05/2013 03:09 AM, Amos Jeffries wrote: Squid tunnel functionality requires a CONNECT wrapper to generate outgoing connections. It is not yet setup t

Re: [squid-users] CLOSE_WAIT

2013-03-06 Thread Steve Hill
On 23.01.13 05:12, Amos Jeffries wrote: IIRC we tried that but it resulted in early cloure of CONNECT tunnels and a few other bad side effects on the tunnelled traffic. Due to the way tunnel.cc and client_side.cc code interacts (badly) the client-side code cannot know whether the tunnel is still

[squid-users] Squid Tproxy WCCPV2 Centos

2013-03-06 Thread Juan C. Crespo R.
Guys I've been trying to build a solution using Squid in Centos, but there is something missing. the WCCPV2 service is adquired by the router, but after a while it stop redirecting the request, so I guest there is something missing at the gre config, could you send me a good example how t

Re: [squid-users] Squid 3.3.2 is available

2013-03-06 Thread Helmut Hullen
Hallo, Amos, Du meintest am 02.03.13: > The Squid HTTP Proxy team is very pleased to announce the > availability of the Squid-3.3.2 release! Compiling it on one of my machines stopped with depbase=`echo peer_proxy_negotiate_auth.o | sed 's|[^/]*$|.deps/ &|;s|\.o$||'`;\ g++ -DHAVE_CONFIG_H -DDE

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Christos Tsantilas
On 03/06/2013 06:15 AM, Amm wrote: >> On 03/04/2013 10:11 PM, Amm wrote: >> # Let user specify domains to avoid decrypting, such as internet >> banking acl bump-bypass dstdomain .commbank.com.au ssl_bump none bump-bypass ssl_bump server-first all >> >> >>> This will

Re: [squid-users] Bypassing SSL Bump for dstdomain

2013-03-06 Thread Amm
- Original Message - > From: Amos Jeffries > To: squid-users@squid-cache.org > Cc: > Sent: Wednesday, 6 March 2013 11:36 AM > Subject: Re: [squid-users] Bypassing SSL Bump for dstdomain > > On 6/03/2013 1:40 p.m., Alex Rousskov wrote: >> On 03/05/2013 03:09 AM, Amos Jeffries wrote:

Re: [squid-users] localhost multicast

2013-03-06 Thread Amos Jeffries
On 6/03/2013 8:20 p.m., jiluspo wrote: http://www.squid-cache.org/Doc/config/udp_incoming_address/ was been buggy and been around in ubuntu bug report. udp_incoming_address doesn't work. The only bug I see in Ubuntu about that directive is that it causes DNS packets to go to the address confi