Re: [squid-users] cant build squid 3.3.5 with external_acl_helper ldap_group on CentOS 6.4 64bits

2013-06-04 Thread Eliezer Croitoru
Can you pastebin the script here: http://www1.ngtech.co.il/paste/ Just to put it to the eyes of the public.. Eliezer On 6/5/2013 2:48 AM, Ricardo Klein wrote: I think the problem is he squid init script from fedora/centos has less timeout then needed and fails to kill all squid processes (and

Re: [squid-users] cant build squid 3.3.5 with external_acl_helper ldap_group on CentOS 6.4 64bits

2013-06-04 Thread Ricardo Klein
I think the problem is he squid init script from fedora/centos has less timeout then needed and fails to kill all squid processes (and clean /var/run/squid/pidfiles), so when it comes back there are already some processes up, causing those errors. I have made some changes on squid init script and

Re: [squid-users] TCP_DENIED/403 for internal servers

2013-06-04 Thread Eliezer Croitoru
Sorry Satish Thareja, This post is outdated since squid is not in 2.5\6 but on 3.3. If you will share more from squid.conf lines we can try to help you. if you can share the access.log we can try to understand. please share IP etc.. if you are getting 403 it means that the server is rejecting you

Re: [squid-users] TCP_DENIED/403 for internal servers

2013-06-04 Thread Satish Thareja
Amos, The config is to allow http access for all but this case. I came across this link : http://www.linuxquestions.org/questions/linux-networking-3/so-many-tcp_denied-in-squid-access-log-469574/ but I do not have anything blocked in my configuration. Is it possible that, if the 'host' does not

Re: [squid-users] cant build squid 3.3.5 with external_acl_helper ldap_group on CentOS 6.4 64bits

2013-06-04 Thread Alex Rousskov
On 06/04/2013 06:15 AM, Ricardo Klein wrote: > about having more then 1 rock store, I dont know, I may have made > some confusion when reading about SMP and cache_dir options diferent > then "rock", The primary reason to use multiple rock cache_dirs is to utilize multiple hard drives (i.e., multi

Re: [squid-users] squid 3.2.11 in opensuse 12.3 and enabling some "vip" for radius auth.

2013-06-04 Thread Josef Karliak
Hi, thanks for help, it works :) : auth_param basic children 5 auth_param basic realm Autorized access auth_param basic credentialsttl 5 minute auth_param basic casesensitive on acl vip src "/etc/squid/vip_bypass_auth.txt" acl http proto http acl auth proxy_auth REQUIRED http_access allow ht

Re: [squid-users] cant build squid 3.3.5 with external_acl_helper ldap_group on CentOS 6.4 64bits

2013-06-04 Thread Ricardo Klein
Hi Eliezer, I dont now if 3.3.x and 3.2.x *really need* more helpers to work, I just saw here http://www.squid-cache.org/Doc/config/external_acl_type/ that now we CAN start more helper process, and as I have resources I might start more of them just to have them up if needed in some point of time.

Re: [squid-users] TCP_DENIED/403 for internal servers

2013-06-04 Thread Amos Jeffries
On 4/06/2013 11:17 p.m., Satish Thareja wrote: Hi, I have configured my squid box without restricting 'http_access' on any resource. But when I try to access a resource 'host.domain.com' using the hostname (i.e. host ) directly, I am getting TCP_DENIED/403 response code. I able to resolve 'host

[squid-users] TCP_DENIED/403 for internal servers

2013-06-04 Thread Satish Thareja
Hi, I have configured my squid box without restricting 'http_access' on any resource. But when I try to access a resource 'host.domain.com' using the hostname (i.e. host ) directly, I am getting TCP_DENIED/403 response code. I able to resolve 'host' from the squid machine directly, but http reque

Re: [squid-users] squid 3.2.11 in opensuse 12.3 and enabling some "vip" for radius auth.

2013-06-04 Thread Brendan Kearney
there is an entire wiki article to this exact topic. http://wiki.squid-cache.org/ConfigExamples/Authenticate/Bypass every matching http_access line before the required auth is unauthenticated. the http_access line requiring auth and all matching http_access lines after it are authenticated. On T

[squid-users] squid 3.2.11 in opensuse 12.3 and enabling some "vip" for radius auth.

2013-06-04 Thread Josef Karliak
Hi, I wanna let some IPs bypass radius authorization, like a server IP. Another users and theirs computers must authorized. So I've this in the squid.conf: auth_param basic program /usr/bin/basic_radius_auth -f /etc/radius_config auth_param basic children 5 auth_param basic realm Authori

Re: [squid-users] squid 3.2.11 in opensuse 12.3 and error about creating IPv6 socket

2013-06-04 Thread Josef Karliak
Hi, you're right. I've enabled IPv6. Or another way is compile squid with disabling IPv6, this is what exactly I do not wanna do :) Thanks and best regards J.K. Cituji Amos Jeffries : On 3/06/2013 7:45 p.m., Josef Karliak wrote: Good morning, In the syslog squid complains about error

[squid-users] Re: TPROXY

2013-06-04 Thread alvarogp
Thanks for the information Eliezer. I am gonna take a look to it. Alvaro -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/TPROXY-tp4658393p4660403.html Sent from the Squid - Users mailing list archive at Nabble.com.

Re: [squid-users] Re: TPROXY

2013-06-04 Thread Eliezer Croitoru
In general tproxy works on: Fedora(any version 10+) Centos(5.9+) Ubuntu(9.10+) Gentoo(for very long time) Debian(5+) Slax(XX) etc.. lots of systems works but you just don't know how to configure them... What routing settings have you used?? take a loot at this script and change the modules exists