Re: [squid-users] Re: squid3 block all 443 ports request

2014-02-17 Thread Sachin Divekar
On Fri, Feb 14, 2014 at 9:39 PM, khadmin wrote: > Hi, > -For the client 192.168.1.53 i configure the browser not to use the proxy > and it fetch www.google.com web site > -For the local machine (the server where squid is intalled) without the > proxy i can fetch www.google.com with the proxy confi

Re: [squid-users] Seemingly incorrect behavior: squid cache getting filled up on PUT requests

2014-02-17 Thread Rajiv Desai
FWIW, from debug logs in cache.log, it seems like PUT responses are being cached. I am fairly new to using squid so I am be completely misreading these. Just trying to understand caching. So are PUT responses cached by design? or am I completely missing something simple here? :) 2014/02/17 00:06

Re: [squid-users] hier_code acl and cache allow/deny

2014-02-17 Thread Nikolai Gorchilov
Dear Amos, On Sat, Feb 15, 2014 at 3:12 PM, Nikolai Gorchilov wrote: > On Sat, Feb 15, 2014 at 1:46 PM, Amos Jeffries wrote: > > I'm trying to avoid the following scenario (excerpt from store.log): > > 1392406208.398 SWAPOUT 00 8C2B9C51268EFEEDEB33FB9EC53030A1 > 200 1392406217 138237318

Re: [squid-users] hier_code acl and cache allow/deny

2014-02-17 Thread Amos Jeffries
On 17/02/2014 10:27 p.m., Nikolai Gorchilov wrote: > Dear Amos, > > On Sat, Feb 15, 2014 at 3:12 PM, Nikolai Gorchilov wrote: >> On Sat, Feb 15, 2014 at 1:46 PM, Amos Jeffries wrote: >> >> I'm trying to avoid the following scenario (excerpt from store.log): >> >> 1392406208.398 SWAPOUT 00 00

[squid-users] negative values in mgr:info

2014-02-17 Thread Niki Gorchilov
Hello, While using Squid 3.4.3 on 64bit Ubuntu 12.04.3 with 64GB cache mem and I see negative values in some memory-related statistics: ===[cut]=== Memory usage for squid via mallinfo(): Total space in arena: -972092 KB Ordinary blocks: -974454 KB 4472 blks Small

Re: [squid-users] negative values in mgr:info

2014-02-17 Thread Kinkie
On Mon, Feb 17, 2014 at 11:15 AM, Niki Gorchilov wrote: > Hello, > > While using Squid 3.4.3 on 64bit Ubuntu 12.04.3 with 64GB cache mem > and I see negative values in some memory-related statistics: > > ===[cut]=== > Memory usage for squid via mallinfo(): > Total space in arena: -972092

Re: [squid-users] negative values in mgr:info

2014-02-17 Thread Amos Jeffries
On 17/02/2014 11:15 p.m., Niki Gorchilov wrote: > Hello, > > While using Squid 3.4.3 on 64bit Ubuntu 12.04.3 with 64GB cache mem > and I see negative values in some memory-related statistics: > > ===[cut]=== > Memory usage for squid via mallinfo(): > Total space in arena: -972092 KB >

[squid-users] squidguard on special port

2014-02-17 Thread Grooz, Marc (regio iT)
Hi Squid Usergroup, I want that a redirector like squidgard is only ask if a client connect to port 3128 and on Port 8080 the request should be passed without the rewriting. Is that possible with squid? Kind regards Marc

Re: [squid-users] squidguard on special port

2014-02-17 Thread Nikolai Gorchilov
Hi, Marc, Yes, it is possible. RTFM about myport/myportname ACL at http://www.squid-cache.org/Doc/config/acl/ Best, Niki On Mon, Feb 17, 2014 at 12:48 PM, Grooz, Marc (regio iT) wrote: > Hi Squid Usergroup, > > I want that a redirector like squidgard is only ask if a client connect to > port 3

AW: [squid-users] squidguard on special port

2014-02-17 Thread Grooz, Marc (regio iT)
My suggestion was: http_port 3128 name=squidguard url_rewrite_access allow squidguard url_rewrite_access deny all or http_port 8080 name=unfiltred url_rewrite_access allow !unfiltred Is that right? -Ursprüngliche Nachricht- Von: n...@gorchilov.com [mailto:n...@gorchilov.com] Im Auftr

Re: [squid-users] squidguard on special port

2014-02-17 Thread Nikolai Gorchilov
You haven't define myportname ACLs. Corrections embedded bellow On Mon, Feb 17, 2014 at 1:34 PM, Grooz, Marc (regio iT) wrote: > http_port 3128 name=squidguard acl squidguard myportname squidguard > url_rewrite_access allow squidguard > url_rewrite_access deny all > > or > > http_port 8080 nam

[squid-users] Squid transparent proxy with one nic access denied problem.

2014-02-17 Thread Spyros Vlachos
Hello! Thank you in advance for your help. I have a fairly simple home network setup. I have a modem (192.168.2.254) that connects to the internet. Connected to that modem through its own wan port I have an openwrt router (192.168.1.1). My internal network is the 192.168.1.0/24 one. On the router I

[squid-users] Upgrade to 3.4.3 and TCP Connections to parent failing more often

2014-02-17 Thread Paul Carew
Hi I have recently upgraded our Squid servers from 3.3.11 to 3.4.3 and am seeing the following error every few minutes in the cache log. 2014/02/17 13:43:02 kid1| TCP connection to wwwproxy02.domain.local/8080 failed I have 2 servers configured on the LAN which handle connections over a private

Re: [squid-users] squid 3.4.3 on Solaris Sparc

2014-02-17 Thread Monah Baki
Hi, I did find /usr/lib/libdb.so but no results for libdb.a Thanks On Mon, Feb 17, 2014 at 12:42 AM, Francesco Chemolli wrote: > > On 17 Feb 2014, at 01:15, Monah Baki wrote: > >> uname -a >> SunOS proxy 5.11 11.1 sun4v sparc SUNW,SPARC-Enterprise-T5220 >> >> Here are the steps before it fai

[squid-users] Re: squid3 block all 443 ports request

2014-02-17 Thread khadmin
Hi, I want to thank you all for your efforts, finally it works i have to disable IPV6 protocole on clients and it works perfectly. Thank you again Regards, Khalil -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/squid3-block-all-443-ports-request-tp4664735

[squid-users] block domains based on LDAP group and force re-authentication every 30 minutes

2014-02-17 Thread Wim Ramakers
I’m trying to configure squid3 (on Debian server) to block certain (mostly social media) websites based on the LDAP (age) group the users are in. The devices are apple ipads, safari is used as web browser, and apps are installed with the Mobile Iron multiuser platform. The device will be shared

Re: [squid-users] block domains based on LDAP group and force re-authentication every 30 minutes

2014-02-17 Thread Scott Mayo
On Mon, Feb 17, 2014 at 9:45 AM, Wim Ramakers wrote: > I’m trying to configure squid3 (on Debian server) to block certain (mostly > social media) websites based on the LDAP (age) group the users are in. > The devices are apple ipads, safari is used as web browser, and apps are > installed with t

Re: [squid-users] block domains based on LDAP group and force re-authentication every 30 minutes

2014-02-17 Thread Wim Ramakers
I forgot to paste the line in the first post, I’ve set authenticate_cache_garbage_interval 5 minutes. Even after an hour I stayed authenticated, so I’ve changed it also to a lower value. Wim

Re: [squid-users] block domains based on LDAP group and force re-authentication every 30 minutes

2014-02-17 Thread Scott Mayo
On Mon, Feb 17, 2014 at 10:39 AM, Wim Ramakers wrote: > I forgot to paste the line in the first post, I’ve set > authenticate_cache_garbage_interval 5 minutes. > > Even after an hour I stayed authenticated, so I’ve changed it also to a lower > value. I am curious to this also then. I wonder

Re: [squid-users] squid 3.4.3 on Solaris Sparc

2014-02-17 Thread Kinkie
That should be enough. Check (you can use the "nm -s" tool) that libdb.so contains the symbols db_create and db_env_create. It may be that the file is corrupted, a wrong version or a stub. Alternatively, if you don't need the session helper, use squid's configure flags to skip building it. On Mon,

[squid-users] cache.log Warnings

2014-02-17 Thread Scott Mayo
Just curious if these are anything that I should really worry about, or just need to keep an eye on my log file? 2014/02/16 03:08:01| helperOpenServers: Starting 40/40 'squid_ldap_auth' processes 2014/02/16 03:08:01| helperOpenServers: Starting 5/5 'squid_ldap_group' processes 2014/02/17 08:59:13|

[squid-users] Re: Squid transparent proxy with one nic access denied problem.

2014-02-17 Thread Spyros Vlachos
Hello! Sorry but I am new to this list and I don't know if I have sent the mail correctly and iff anyone can see this. Is this the case? Sorry and thank you! On Mon, Feb 17, 2014 at 2:24 PM, Spyros Vlachos wrote: > Hello! Thank you in advance for your help. > I have a fairly simple home network s

Re: [squid-users] squid 3.4.3 on Solaris Sparc

2014-02-17 Thread Monah Baki
I hope this is the right output. root@proxy:~# nm -s /usr/lib/libdb.so | grep db_create [2332] |214036| 716|FUNC |GLOB |0|.text |__bam_db_create [1495] | 1098492| 2172|FUNC |GLOB |0|.text |__db_create_internal [2052] |395884| 216|FUNC |GLOB |0|.tex

[squid-users] Re: cache.log Warnings

2014-02-17 Thread Scott Mayo
On Mon, Feb 17, 2014 at 2:31 PM, Scott Mayo wrote: > Just curious if these are anything that I should really worry about, > or just need to keep an eye on my log file? > > 2014/02/16 03:08:01| helperOpenServers: Starting 40/40 > 'squid_ldap_auth' processes > 2014/02/16 03:08:01| helperOpenServers:

Re: [squid-users] Re: Squid transparent proxy with one nic access denied problem.

2014-02-17 Thread Nikolai Gorchilov
Hi Spyros, Seems you're experiencing request loops, that are unrelated to your ACLs Looking at the logs, we can clearly see pairs of requests for same url. Like this: 1392590890.301 0 192.168.1.20 TCP_MISS/403 4158 GET http://www.tvxs.gr/ - HIER_NONE/- text/html 1392590890.302 1 192.168

Re: [squid-users] Seemingly incorrect behavior: squid cache getting filled up on PUT requests

2014-02-17 Thread Rajiv Desai
I think I found the problem. This applies only to HTTPs traffic being cached with ssl-bump. Basically HttpRequest::maybeCacheable() does not check for PROTO_HTTPS Following patch fixes it: diff --git a/squid-3.HEAD-20140127-r13248/src/HttpRequest.cc b/squid-3.HEAD-20140127-r13248/src/HttpRequest

[squid-users] Re: cache.log Warnings

2014-02-17 Thread Scott Mayo
Nevermind on the memory usage. Looks like it is fine by looking at my buffers/cache in "free -m". I am curious if any of the messages in the log look like something I should worry about though. Thanks. Scott On Mon, Feb 17, 2014 at 5:20 PM, Scott Mayo wrote: > On Mon, Feb 17, 2014 at 2:31 PM,

Re: [squid-users] Re: cache.log Warnings

2014-02-17 Thread Carlos Defoe
http://wiki.squid-cache.org/KnowledgeBase/QueueCongestion You're probably using aufs, those messages are normal. On the restart log, I never saw the AuthUserHashPointer ones, but since squid exits and starts normally, I don't think that is a problem. I was going to ask how are you checking your

Re: [squid-users] Seemingly incorrect behavior: squid cache getting filled up on PUT requests

2014-02-17 Thread Amos Jeffries
On 18/02/2014 1:23 p.m., Rajiv Desai wrote: > I think I found the problem. This applies only to HTTPs traffic being > cached with ssl-bump. > Basically HttpRequest::maybeCacheable() does not check for PROTO_HTTPS > > Following patch fixes it: > > > diff --git a/squid-3.HEAD-20140127-r13248/src/H

Re: [squid-users] Re: squid3 block all 443 ports request

2014-02-17 Thread Amos Jeffries
On 17/02/2014 8:55 p.m., khadmin wrote: > Hi Amos, > > Thank you for the response, actually i'am working with IPV4 on my network > architecture. While Squid appears to be trying to use the half-working IPv6 network you have available. Not that your Squid is apparently *successfully* performing t

Re: [squid-users] Re: cache.log Warnings

2014-02-17 Thread Scott Mayo
On Mon, Feb 17, 2014 at 6:35 PM, Carlos Defoe wrote: > http://wiki.squid-cache.org/KnowledgeBase/QueueCongestion > > You're probably using aufs, those messages are normal. Yes, just changed that yesterday. > > On the restart log, I never saw the AuthUserHashPointer ones, but > since squid exits

Re: [squid-users] Re: squid3 block all 443 ports request

2014-02-17 Thread Amos Jeffries
On 18/02/2014 4:45 a.m., khadmin wrote: > Hi, > > I want to thank you all for your efforts, finally it works i have to disable > IPV6 protocole on clients and it works perfectly. That is wrong. The clients were already working perfectly and disabling IPv6 breaks more than just this one small pro

[squid-users] squid-3.4.3-20140203-r13087 can not compile on freebsd 10-stable

2014-02-17 Thread k simon
Hi,List, The squid-3.4.3-20140203-r13087 can not compile on freebsd 10-stable. When issue "./configure",it report "configure: Native pthreads support disabled. DiskThreads module automaticaly disabled." And compile can not finished, it report "/usr/include/c++/v1/cstdio:139:9: error: no mem

Re: [squid-users] cache.log Warnings

2014-02-17 Thread Amos Jeffries
On 18/02/2014 9:31 a.m., Scott Mayo wrote: > Just curious if these are anything that I should really worry about, > or just need to keep an eye on my log file? > > 2014/02/16 03:08:01| helperOpenServers: Starting 40/40 > 'squid_ldap_auth' processes > 2014/02/16 03:08:01| helperOpenServers: Startin

Re: [squid-users] Re: cache.log Warnings

2014-02-17 Thread Amos Jeffries
On 18/02/2014 1:35 p.m., Carlos Defoe wrote: > http://wiki.squid-cache.org/KnowledgeBase/QueueCongestion > > You're probably using aufs, those messages are normal. > > On the restart log, I never saw the AuthUserHashPointer ones, but > since squid exits and starts normally, I don't think that is