[squid-users] Testing squid-3.1.0.16 .| idnsSendQuery: FD 8: sendto: (51) Network is unreachable

2010-02-08 Thread Dimitri Syuoul
Hello, I have installed the latest beta (16) on a box that does not have a firewall. I have confirmed that with a prompt iam able to resolve domain names.. but for some reason squid complaints it cant. Is there any option i need to edit so that it uses either 127.0.0.1 to resolve or any other publ

Re: [squid-users] SSL Bump progress on beta 3.1.0.16?

2010-02-08 Thread Dimitri Syuoul
On Mon, Feb 8, 2010 at 8:25 PM, Alex Rousskov wrote: > I believe the basic SSL Bump feature in Squid v3.1 is relatively well > tested. It has been around for a while. I am not aware of any open bugs > (but have not checked recently). Its usability is rather limited because > of the frequent certi

[squid-users] SSL Bump progress on beta 3.1.0.16?

2010-02-08 Thread Dimitri Syuoul
Greetings, I want to give a show to the SSL Bump feature that we have long awaited on 3.1 . Id like to know how advanced/tested this feature is in currently to know if there is a chance I can begin using it on production environment. Thanks. Dimitri

[squid-users] Re: [Snort-users] Commercial Advanced Packet Sniffers, how do they do this? Application signatures?

2010-01-22 Thread Dimitri Syuoul
On Fri, Jan 22, 2010 at 2:42 PM, Richard Bejtlich wrote: > > [1] http://taosecurity.blogspot.com/2006/09/port-independent-protocol.html > [2] http://bro-ids.org/wiki/index.php/DynamicProtocolDetection > Interesting enough the L7-filter and IPP2P projects seem to be dead. http://bro-ids.org/wi

[squid-users] Re: CHALLENGE: LAN -> TRANSPARENT PROXY -> MULTIPLE VPNS. How to put it together?

2010-01-22 Thread Dimitri Syuoul
I apologize for the repeated email... got sent before time. To finish on the example: LanUser1 makes an http request -> The HTTP request is processed on a BOX that acts as a gateway --> That same box has squid installed and filters the http request (Normal ACLs) --> Depending on the private IP of

[squid-users] Re: CHALLENGE: LAN -> TRANSPARENT PROXY -> MULTIPLE VPNS. How to put it together?

2010-01-22 Thread Dimitri Syuoul
Hello all, This is a question combining squid with firewall rule manipulation (both need to get along well...). I have a LAN and a GATEWAY BOX that serves as a NAT for all of the users behind the LAN. MY goal is to make the box filter all http requests and once they are clean route the traffic t

[squid-users] CHALLENGE: LAN -> TRANSPARENT PROXY -> MULTIPLE VPNS. How to put it together?

2010-01-22 Thread Dimitri Syuoul
Hello all, This is a question combining squid with firewall rule manipulation (both need to get along well...). I have a LAN and a GATEWAY BOX that serves as a NAT for all of the users behind the LAN. MY goal is to make the box filter all http requests and once they are clean route the traffic t

Re: [squid-users] SSLBump.. could it be used for transparent proxying?

2010-01-19 Thread Dimitri Syuoul
? Thank you. Dimitri On Tue, Jan 19, 2010 at 5:38 PM, Alex Rousskov wrote: > On 01/13/2010 10:30 AM, Dimitri Syuoul wrote: >> Hello, >> >> Ive been reading over this new feature. It is unclear to me if this >> can be used for transparently proxying SSL (by this I mean n

Re: [squid-users] Re: SSBump.. could it be used for transparent proxying?

2010-01-16 Thread Dimitri Syuoul
ith > transparent caching. If it is, I would love to make use of it as well. > > Nick > > > -Original Message- > From: Dimitri Syuoul [mailto:dsyu...@gmail.com] > Sent: Sat 1/16/2010 5:30 PM > To: squid-users > Subject: [squid-users] Re: SSBump.. could it

[squid-users] Re: SSBump.. could it be used for transparent proxying?

2010-01-16 Thread Dimitri Syuoul
Hello, I submitted the response below but for some reason nobody appears to have commented on this. Is this feature still in beta mode that there isnt much doc about it? Thank you Dimitri On Wed, Jan 13, 2010 at 11:30 AM, Dimitri Syuoul wrote: > Hello, > > Ive been reading over

[squid-users] SSBump.. could it be used for transparent proxying?

2010-01-13 Thread Dimitri Syuoul
Hello, Ive been reading over this new feature. It is unclear to me if this can be used for transparently proxying SSL (by this I mean not configuring any proxy in the computers of the clients.. it is ok if clients get cert warnings). Thank you. Dimitri

[squid-users] Re: half_closed_clients Policy Change

2009-10-25 Thread Dimitri Syuoul
Hi there, In response to this policy change submitted by AmosĀ  for Squid 3.0 http://www.nabble.com/half_closed_clients-Policy-Change-td19578737.html Iam a squid-2.7.STABLE6 , and iam very curious as to why the twist ? Ive been noticing that sometimes when the users surf the internet the browser o

[squid-users] Set tcp_outgoing_address to take effect on the cache_peer

2009-10-25 Thread Dimitri Syuoul
Hello, I have a squid installation on my LAN, it forwards all requests to the remote cache_peer. My question is... would there be a way for me to specify to the cache_peer that an acl user should use a specific tcp_outgoing_address that is bound to that remote box? Id like to be able to manage tha