Re: [squid-users] yooutube video caching

2013-08-19 Thread Amos Jeffries
On 19/08/2013 3:13 p.m., Manoj.K wrote: Hello folks, I want implement a squid environment that can cache youtube videos. I google a lot but i cant able get exact solution. could you please show me the right path do do this. Firstly you need to know there is no *exact* method. YouTube are

Re: [squid-users] Auth basic

2013-08-19 Thread Amos Jeffries
On 19/08/2013 5:20 p.m., Alan wrote: On Sat, Aug 17, 2013 at 3:02 AM, Oliveiros Peixoto (Netinho) wrote: Hi Jeffries! I created my own script auth_basic. This script checks the username and password, if correct it inserts the username and date in the table sessions and returns OK login =

Re: [squid-users] Re: TCP_MISS/Squid-Error: ERR_CONNECT_FAIL

2013-08-19 Thread Amos Jeffries
On 18/08/2013 4:39 a.m., SaRaVanAn wrote: Hi All, In my case, tcp connection established between browser and internet IP's with tproxy. root@debian:~# netstat -natp | grep squid tcp0 0 0.0.0.0:31280.0.0.0:* LISTEN 31895/(squid) tcp0 0 0.0.0.0:3129

Re: [squid-users] Re: can we know the ip of transparent proxy ??

2013-08-19 Thread Amos Jeffries
On 19/08/2013 5:50 p.m., Ahmad wrote: hi Eliezer , ive searched and found application called tracetcp , this tool can only tell me if there is transparent proxy or not , but not going to tell me the ip of the transparent proxy !!! is there a trick to know the ip of transparent squid ? Not

Re: [squid-users] Need help with squid snmp with PRTG Monitor MIB and Oidlib

2013-08-19 Thread Amos Jeffries
Looks like nobody who read your post knows. All we can do is provide detais of what each Squid OID presents, how you configure those OID into your monitoring software is something more for the PRTG or Oidlib help forums/goups/mailing lists. Amos

Re: [squid-users] Re: can we know the ip of transparent proxy ??

2013-08-19 Thread Amm
From: Amos Jeffries squ...@treenet.co.nz To: squid-users@squid-cache.org Sent: Monday, 19 August 2013 12:11 PM Subject: Re: [squid-users] Re: can we know the ip of transparent proxy ?? On 19/08/2013 5:50 p.m., Ahmad wrote: is there a trick to know the ip of transparent squid ? Not from the

Re: [squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Amos Jeffries
On 19/08/2013 5:46 p.m., Ahmad wrote: well , uptill now im understanding that dns on squid is needed when putting port and ip on clients browsers , but uptill now not understanding how dns queriers will be forwarded to squid when using WCCP ??? DNS is not used as part of the forwarding. It

Re: [squid-users] squid active directory integration

2013-08-19 Thread Amos Jeffries
On 17/08/2013 1:09 a.m., cheitac wrote: Hello all, Recently I tried many helpers to integrate squid with active directory. I have 2 domain controllers in my lab environment two windows 7 machines and centos 6. I'm interesting what is the best way to use squid with active directory? I need to

[squid-users] https transparent proxy

2013-08-19 Thread Mario Almeida
Hi All, Switch: WS-C3560-24PS-S, Version 12.2(44)SE5 OS: CentOS 6.4 64bit Squid Cache: Version 3.1.10 I have configure http and https transparent proxy. http is working but https I get below ssl error. Can someone help me? === ERROR === -BEGIN SSL SESSION PARAMETERS-

Re: [squid-users] squid 3.1.10 page allocation failure. order:1, mode:0x20

2013-08-19 Thread Amos Jeffries
On 17/08/2013 6:45 a.m., inittab wrote: Hello, I wanted to get some suggestions on my current setup and ask if i'm expecting too much out of my hardware for the traffic load. Sorry for the slow reply. NOTE: If you determine that it is a memory leak, please upgrade to the current Squid-3.3

Re: [squid-users] Two Potential Bugs When Using Rock Stores!

2013-08-19 Thread Golden Shadow
Hi Amos, Thanks a lot for your help! Unfortunately I had to switch back to aufs stores instead of rock stores, as I encountered another problem. I started to get: Worker I/O push queue overflow: communication with disker may be too slow or disrupted  Therefore, I added max-swap-rate and

[squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Ahmad
WELL , nice explanation , but u put a red line on something , === going to step 3b) if no, the clients destination IP is used. = did u mean that it will not cache , store the client request in this case ???

[squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Ahmad
i think this security mechanism similar somehow to Microsoft active directory . - Mr.Ahmad -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/General-Question-in-DNS-with-squid-tp4661528p4661621.html Sent from the Squid - Users mailing list archive at

Re: [squid-users] yooutube video caching

2013-08-19 Thread Eliezer Croitoru
Hey there, Since I have been working on youtube caching and content de-duplication quite some time I can tell you in one sentence my conclusion which was verified and tested in the past. Youtube is a very complex and advanced piece of technology which actually can be used to share video content.

[squid-users] Re: yooutube video caching

2013-08-19 Thread babajaga
YouTube are constantly changing their site, both to improve their service and to fight back against admin caching the content. May be, this is the reason, that not so much info about caching YT videos is available on the web. The Ones in the Know might have the impression, in case the info about

[squid-users] handling Proxy-Authorization field

2013-08-19 Thread Attila Gömbös
Hi guys! I have the following setup: LAN - UTM firewall with transparent proxy - Squid - WAN The UTM is taking care of user authentication (SSO). I need to pass the user ID to Squid. We need to have AD-group based rules on Squid as well. But the UTM is able to add only this field to the HTTP

Re: [squid-users] Re: TCP_MISS/Squid-Error: ERR_CONNECT_FAIL

2013-08-19 Thread SaRaVanAn
Hi Amos, Thanks a lot for your help. There is an issue in web-server connectivity which has been solved as you suggested. I could able to connect the webserver via squid successfully. But there is an issue in caching webpages . I am always getting TCP/MISS 200 messages from squid. I could not

Re: [squid-users] https transparent proxy

2013-08-19 Thread Amos Jeffries
On 19/08/2013 7:22 p.m., Mario Almeida wrote: Hi All, Switch: WS-C3560-24PS-S, Version 12.2(44)SE5 OS: CentOS 6.4 64bit Squid Cache: Version 3.1.10 I have configure http and https transparent proxy. http is working but https I get below ssl error. Can someone help me? Please upgrade to 3.3

Re: [squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Amos Jeffries
On 19/08/2013 9:14 p.m., Ahmad wrote: i think this security mechanism similar somehow to Microsoft active directory . Huh? Amos

Re: [squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Amos Jeffries
On 19/08/2013 9:08 p.m., Ahmad wrote: WELL , nice explanation , but u put a red line on something , === going to step 3b) if no, the clients destination IP is used. = did u mean that it will not cache ,

Re: [squid-users] Re: General Question in DNS with squid

2013-08-19 Thread Amos Jeffries
On 19/08/2013 9:14 p.m., Ahmad wrote: i think this security mechanism similar somehow to Microsoft active directory . The security system I am talking about is described here: http://wiki.squid-cache.org/KnowledgeBase/HostHeaderForgery As far as I know ActiveDirectory does not do traffic

Re: [squid-users] https transparent proxy

2013-08-19 Thread Mario Almeida
Hi Amos, Tried with 3.3.8 but same issue. On Mon, Aug 19, 2013 at 3:44 PM, Amos Jeffries squ...@treenet.co.nz wrote: On 19/08/2013 7:22 p.m., Mario Almeida wrote: Hi All, Switch: WS-C3560-24PS-S, Version 12.2(44)SE5 OS: CentOS 6.4 64bit Squid Cache: Version 3.1.10 I have configure

Re: [squid-users] handling Proxy-Authorization field

2013-08-19 Thread Amos Jeffries
On 19/08/2013 10:20 p.m., Attila Gömbös wrote: Hi guys! I have the following setup: LAN - UTM firewall with transparent proxy - Squid - WAN The UTM is taking care of user authentication (SSO). Meaning it is not transparent. Transparent proxies *cannot* do authentication. The reason is

Re: [squid-users] Auth basic

2013-08-19 Thread Oliveiros Peixoto (Netinho)
Hi, Squid Cache: Version 3.1.20 Em 19/08/2013 03:22, Amos Jeffries escreveu: On 19/08/2013 5:20 p.m., Alan wrote: On Sat, Aug 17, 2013 at 3:02 AM, Oliveiros Peixoto (Netinho) wrote: Hi Jeffries! I created my own script auth_basic. This script checks the username and password, if correct it

[squid-users] squid and url_regex. Not working

2013-08-19 Thread ranmanh
Hi I am not sure what I am missing with my configuration. I just want to deny access to some specific URL to some IPs. so : So I am trying to deny access to ip :192.168.1.20 when reaching url: http://www2.ul.ie/web/WWW/Services/Research/Research_at_UL allowing anyone else. it does not matter

Re: [squid-users] squid and url_regex. Not working

2013-08-19 Thread Amos Jeffries
On 20/08/2013 1:35 a.m., ranmanh wrote: Hi I am not sure what I am missing with my configuration. You did not include the configuration details with your message so neither do we ;-) I just want to deny access to some specific URL to some IPs. so : So I am trying to deny access to ip

Re: [squid-users] Re: TCP_MISS/Squid-Error: ERR_CONNECT_FAIL

2013-08-19 Thread Amos Jeffries
On 19/08/2013 11:29 p.m., SaRaVanAn wrote: Hi Amos, Thanks a lot for your help. There is an issue in web-server connectivity which has been solved as you suggested. I could able to connect the webserver via squid successfully. But there is an issue in caching webpages . I am always getting

[squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread ranmanh
Apologies I corrected the original post a few minutes after posting it Now details included in the initial message. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-and-url-regex-Not-working-tp4661633p4661636.html Sent from the Squid - Users

Re: [squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread Amos Jeffries
On 20/08/2013 2:20 a.m., ranmanh wrote: Apologies I corrected the original post a few minutes after posting it Now details included in the initial message. This is an email mailing list. You cannot correct initial posts like that. Please post the details. Amos

Re: [squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread Amm
- Original Message - From: Amos Jeffries squ...@treenet.co.nz To: squid-users@squid-cache.org On 20/08/2013 2:20 a.m., ranmanh wrote: Apologies I corrected the original post a few minutes after posting it Now details included in the initial message.   This is an email

[squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread ranmanh
Original Configuration: The configuration as follows: acl manager proto cache_object acl localhost src 127.0.0.1/32 ::1 acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1 acl localnet src 10.0.0.0/8 # RFC1918 possible internal network acl localnet src 172.16.0.0/12 # RFC1918 possible

[squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread ranmanh
I have also tried the following example using http_access as well suggested: acl special_client src 192.168.0.0/16 acl special_client src 127.0.0.0/8 acl special_url url_regex -i ^http://wiki.squid-cache.org/SquidFaq$ http_access deny special_client special_url http_access allow special_url The

[squid-users] Cache Windows Updates ONLY

2013-08-19 Thread HillTopsGM
Hi All. I've been doing lots of reading and I believe I am understanding the basic concept of how to use Squid. /I've posted the hardware that I am using at the bottom of the post/. I have about 12 windows machines running at any one time and I was hoping to start using Squid to speed up the

[squid-users] My own mails to the list

2013-08-19 Thread Alfredo Rezinovsky
When I send a mail to squid-users I don't see mi own mails, only the answers. There's a way to have my own mails with the [squid-users] subject prefix? -- Alfrenovsky

[squid-users] kerberos keytab

2013-08-19 Thread Carlos Defoe
Hello, What is the best strategy to use a keytab file within multiple servers? By now i'm using a NFS share to export the keytab. Every day msktutil runs to update the file if necessary. The job is schedule in one server only. Also, after the update of the keytab file, is it necessary to reload

Re: [squid-users] kerberos keytab

2013-08-19 Thread Helmut Hullen
Hallo, Carlos, Du meintest am 19.08.13: What is the best strategy to use a keytab file within multiple servers? By now i'm using a NFS share to export the keytab. Every day msktutil runs to update the file if necessary. The job is schedule in one server only. Also, after the update of the

[squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread ranmanh
Guys This only works if I do something like the following (full squid.cfg file) - is there anyway of appending such a rule under the general rules? Otherwise the access will be always allowed for what it seems.. Any idea? Many thanks -- View this message in context:

[squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread ranmanh
Sorry guys, I was posting from nabble and I got lost in translation with the mailing list and Nabble.. trying to get it done right. Apologies. -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squid-and-url-regex-Not-working-tp4661633p4661648.html Sent from

Re: [squid-users] handling Proxy-Authorization field

2013-08-19 Thread Attila Gömbös
Thanks Amos! Since the firewall in the middle uses an agent for SSO, the firewall itself is not even aware of the user's password. That's why it doesn't send it. I found the basic_fake_auth in 3.3: auth_param basic program /usr/lib/squid3/basic_fake_auth This way the username submitted by the

[squid-users] mac acl is not really mac based?

2013-08-19 Thread Attila Gömbös
Hi guys! As far as I see the MAC-address based ACL is not really based on MAC address. - Squid checks the IP address of the HTTP request. - Looks up the ARP table, and searches for the allowed MAC address. - If the IP has got an ARP entry with the allowed MAC address it will let it through. This

[squid-users] Re: mac acl is not really mac based?

2013-08-19 Thread Attila Gömbös
Well, maybe that's why it is called ARP acl, and not MAC acl. My bad:) On Mon, Aug 19, 2013 at 9:06 PM, Attila Gömbös attila.gom...@gmail.com wrote: Hi guys! As far as I see the MAC-address based ACL is not really based on MAC address. - Squid checks the IP address of the HTTP request. -

Re: [squid-users] Reverse Proxy - Multiple domains - Multiple wildcard certs?

2013-08-19 Thread Kinkie
On Mon, Aug 19, 2013 at 1:53 AM, PSA sima...@operamail.com wrote: I can't figure out how to serve multiple domains with a single squid server/single IP address. I am currently serving: api.domain.com www.domain.com status.domain.com with a *.domain.com ssl certificate. I now want

Re: [squid-users] kerberos keytab

2013-08-19 Thread Carlos Defoe
thanks, Helmut. i made one script to check the file change and run squid -k reconfigure. i'll wait till next change to see if it works correctly. thank you On Mon, Aug 19, 2013 at 2:11 PM, Helmut Hullen hul...@t-online.de wrote: Hallo, Carlos, Du meintest am 19.08.13: What is the best

Re: [squid-users] Cache Windows Updates ONLY

2013-08-19 Thread Amos Jeffries
On 20/08/2013 4:31 a.m., HillTopsGM wrote: Hi All. I've been doing lots of reading and I believe I am understanding the basic concept of how to use Squid. /I've posted the hardware that I am using at the bottom of the post/. I have about 12 windows machines running at any one time and I was

Re: [squid-users] My own mails to the list

2013-08-19 Thread Amos Jeffries
On 20/08/2013 4:32 a.m., Alfredo Rezinovsky wrote: When I send a mail to squid-users I don't see mi own mails, only the answers. There's a way to have my own mails with the [squid-users] subject prefix? It would seem to be a problem with yoru mailer or something outside of the Squid

Re: [squid-users] Re: squid and url_regex. Not working

2013-08-19 Thread Amos Jeffries
On 20/08/2013 6:42 a.m., ranmanh wrote: Guys This only works if I do something like the following (full squid.cfg file) - is there anyway of appending such a rule under the general rules? Otherwise the access will be always allowed for what it seems.. Any idea?

Re: [squid-users] Re: mac acl is not really mac based?

2013-08-19 Thread Amos Jeffries
On 20/08/2013 7:06 a.m., Attila Gömbös wrote: Well, maybe that's why it is called ARP acl, and not MAC acl. My bad:) Yes. To be completely pedantic it is an EUI access control. Since it handles ARP MAC/EUI-48 in IPv4 traffic and SLAAC EUI-64 in IPv6 traffic. We source the information

Re: [squid-users] Auth basic

2013-08-19 Thread Oliveiros Peixoto
Yes, this is a bug! I compiled versions 2.7, 3.4 and work perfect. Thanks guys! Enviado via iPhone Em 19/08/2013, às 03:22, Amos Jeffries squ...@treenet.co.nz escreveu: On 19/08/2013 5:20 p.m., Alan wrote: On Sat, Aug 17, 2013 at 3:02 AM, Oliveiros Peixoto (Netinho) wrote: Hi Jeffries!