Re: [squid-users] HOWTO: Kerberos authentication and LDAP Authorization in Active Directory

2008-01-19 Thread Juraj Sakala
Excelent. I will try it. Thanks very much. Hi all, I write a simple Howto for use kerberos to authenticate a user in Active Directory and make authorization with Ldap also in AD using group membership to control the access. its at http://klaubert.wordpress.com I hope that be useful to somebody

Re: [squid-users] Tips for blocking Messenger

2008-01-23 Thread Juraj Sakala
Andrea Soccal wrote / napísal(a): Hi Yesterday i have re-configured squid and I have add an acl : Acl block url_regex “block.txt” and in the block.txt I have add the word LIVE and this word block messenger !! I hope this tips will be hel for you Bye It will overblock all URLs with LIVE

Re: [squid-users] follow x forwarder 2.6 patch doesn't work!!!

2008-03-29 Thread Juraj Sakala
Filippo Micalizzi wrote / napísal(a): Hi guys, I've successfully installed on my customer one mini linux server with ubuntu 7.10 server edition, in which thanks to squid/ntlm autentication the only the member of internet-users group in Ad could access to the web. Now we would like to introdu

Re: [squid-users] follow x forwarder 2.6 patch doesn't work!!!

2008-03-30 Thread Juraj Sakala
Filippo Micalizzi wrote / napísal(a): Juraj Sakala ha scritto: Filippo Micalizzi wrote / napísal(a): Juraj Sakala ha scritto: Filippo Micalizzi wrote / napísal(a): Hi guys, I've successfully installed on my customer one mini linux server with ubuntu 7.10 server edition, in which t

Re: [squid-users] follow x forwarder 2.6 patch doesn't work!!!

2008-03-30 Thread Juraj Sakala
Filippo Micalizzi wrote / napísal(a): Juraj Sakala ha scritto: Filippo Micalizzi wrote / napísal(a): Hi guys, I've successfully installed on my customer one mini linux server with ubuntu 7.10 server edition, in which thanks to squid/ntlm autentication the only the member of internet-

[squid-users] Squid 2.5STABLE14 did not log hierarchy tag properly

2006-05-30 Thread Juraj Sakala
Hi, I have problem with my squid. I run squid 2.5STABLE5. This squid logs hierarchy tag in access.log properly. For example: TCP_MISS/200 304 GET http://... DEFAULT_PARENT/xxx.yyy.zz text/javascript TCP_IMS_HIT/304 243 GET http://... - NONE/- image/jpeg . . . There is all OK Today I compiled squi

Re: [squid-users] Blocking access to external proxies

2006-10-17 Thread Juraj Sakala
On Monday 16 October 2006 21:54, Jaime Solorzano B wrote: > I have detected some accesses to external proxies. > These accesses are being used to void squid controls and navigate without > controls, sometimes anonymously. > > I believe that is almost impossible to know all server names to block the

Re: [squid-users] Allowing only specific ports to Internet

2006-10-17 Thread Juraj Sakala
On Monday 16 October 2006 22:46, Jaime Solorzano B wrote: > I would like to allow specific ports to Internet and deny all the others. > What changes should I do at squid configuration? > > Thanks in advance. Which ports do you want to allow? I will send you config ...

Re: [squid-users] block .ru

2006-10-17 Thread Juraj Sakala
On Tuesday 17 October 2006 10:16, Winanjaya wrote: > Dear All, > > I need to block my users to visit rusian (.ru) sites .. any idea? > > thanks & regards > Winanjaya > > *** > No virus was detected in the attachment (no filename). > > Your mail has been scanned by InterScan. > *

Re: [squid-users] Allowing only specific ports to Internet

2006-10-17 Thread Juraj Sakala
udp: 53, 69, 5060, 5061, 1, 2) > vpn (pptp, gre) > > And Incoming ports allowed: > sybase (50001) > vpn (pptp, gre) > ftp > ftp data > > Thanks again. > > - Original Message - > From: "Juraj Sakala" <[EMAIL PROTECTED]> > To: >

Re: [squid-users] two squids in the same server

2006-10-19 Thread Juraj Sakala
On Tuesday 10 October 2006 02:07, Btobew wrote: > I have one Proliant DL380G3 2 GB/RAM - 2 processors HT. 40mb/s of web > traffic. > > Now, I am running my web-cache with 2 squids ( one per IP ), one squid is > 512MB RAM + 6GB cache (rw), other 512MB RAM + 6GB same cache (ro). > > the answer is: is

Re: [squid-users] Squid as load balancer

2006-10-19 Thread Juraj Sakala
On Tuesday 03 October 2006 08:32, Arvind Kumar Gupta wrote: > My organisation has two Internet leased line from diffrent ISPs (2 Mbps > from each). I am running Symantec web security proxy server as frontend > and Squid as backend. So at a time I am able to connect to one ISP and > other one is idl

[squid-users] cahce_peer_access directive doesn't use x_forwarded_for header

2007-03-06 Thread Juraj Sakala
cache_peer_access SECOND allow all Without DansGuardian and x_forwarded_for header was all OK, but now it doesn't work Can someone help me please? Is it bug Regards Juraj Sakala

Re: [squid-users] Dansguardian + SQUID

2007-03-07 Thread Juraj Sakala
You have to compile squid with --enable-follow-x-forwarded-for option an use this directives in squid.conf follow_x_forwarded_for allow all acl_uses_indirect_client on log_uses_indirect_client on On Saturday 24 February 2007 13:42, Pratchaya Chatuphian wrote: > Dansguardian + SQUID > ==

Re: [squid-users] Advert blocking question

2007-03-09 Thread Juraj Sakala
Hi I think good for you will be DansGuardian or SquidGuard. Both of them can use blacklists. I use DansGuardian with blacklists from urlblacklist.com and I am very satisfied. It blocks advert very well and it can blocks much more. DansGuardian uses also bayes filters and scans body of website f

Re: [squid-users] Forwarding https request to parent proxy

2007-03-13 Thread Juraj Sakala
check proxy configuration in firefox. where do you have cache_peer_access directive? On Tuesday 13 March 2007 08:38, chteh wrote: > Dear All, > > I know this is not a new issue in this mailing list, and im sorry to arise > this issue again. I have a private network which only has private Ipv4 > a

Re: [squid-users] Block Site in search

2007-04-10 Thread Juraj Sakala
Try to use DansGuardian as preliminary proxy. It solves your needs On Friday 23 March 2007 13:58, netmail wrote: > Hi > I want block the google search of search adult sites > Which is the acl ? Is url_regex ?

Re: [squid-users] sibling hits

2007-04-10 Thread Juraj Sakala
On Tuesday 10 April 2007 07:17, Zak Thompson wrote: > Alright so I'm seeing A LOT of > > TCP_MISS:CD_SIBLING_HIT > > And > > TCP_MISS:SIBLING_HIT > > > Squid 2.6 is there a way to get these to be hits and not tcp_misses? Or is > it doing its job and working and I'm oblivious to this message. SIB

[squid-users] "unknown" in x-forwarded-for heder

2007-05-30 Thread Juraj Sakala
Hi, please can someone explain me why the value unknown is in x-forwarded-for header? Many thanks Regards Juraj

Re: [squid-users] "unknown" in x-forwarded-for heder

2007-05-30 Thread Juraj Sakala
On Wednesday 30 May 2007 10:36, you wrote: > Juraj Sakala escribió: > > Hi, > > > > please can someone explain me why the value unknown is in x-forwarded-for > > header? > > Do you have enabled the forwarded_for directive in squid.conf? yes, i have > > Thanks > Emilio C.

Re: [squid-users] "unknown" in x-forwarded-for heder

2007-05-30 Thread Juraj Sakala
On Wednesday 30 May 2007 18:58, Matus UHLAR - fantomas wrote: > > On Wednesday 30 May 2007 10:36, you wrote: > > > Juraj Sakala escribió: > > > > Hi, > > > > > > > > please can someone explain me why the value unknown is in > > > &

Re: [squid-users] "unknown" in x-forwarded-for heder

2007-05-31 Thread Juraj Sakala
> > I think it is all ok, but squid1, squid2, squid3 sometimes (for example > > when i use monitorurl in directive cache_peer) send "unknown" in > > x-forwarded-for header and therefor dansguardian is not able resolve > > correct ip and sends to squid4 in header 127.0.0.1. I just need to know > > w

Re: [squid-users] Anonymous Proxyies

2007-06-01 Thread Juraj Sakala
On Friday 01 June 2007 05:44, Munawar Zeeshan wrote: > Hi. > > I am using Squid Guard to block unwantws sites. But my users now using > anonymous proxies to by pass my squid guard restriction. > > There are a lot of anonymous proxy websites.i have manually blocked > some of them but mu users search

Re: [squid-users] Anonymous Proxyies

2007-06-01 Thread Juraj Sakala
On Friday 01 June 2007 11:47, Munawar Zeeshan wrote: > > try to use blacklists for squidguard, for example from > > http://urlblacklist.com/ > > but this doesnt contain any black list for web-based anonymous proxies.. > > i think i am right.!! Yes, it does, see http://urlblacklist.com/?sec=

Re: [squid-users] Problem with Sibling squids

2007-06-04 Thread Juraj Sakala
Hi, > Here's my config: > > acl RedPlaid src 208.XX.XX.0/255.255.255.0 > acl squid1 src 208.74.XX.XX > acl squid2 src 208.74.XX.XX > acl squid3 src 208.74.XX.XX > acl squid4 src 208.74.XX.XX > acl squid5 src 208.74.XX.XX > acl AllowedSites dstdomain "/etc/squid/allowed_sites" > acl DeniedSites ur

Re: [squid-users] Problem with Sibling squids

2007-06-05 Thread Juraj Sakala
> Added that line and didn't help :(. > > This is what happens: > > 1) Squids were configured without sibling. > 2) Configured sibling on each squid as showed before (4 cache_peer > lines per squid, total 5 squids). > 3) Reloaded (not restarted) squid. Sibling started working After a > while (~

Re: [squid-users] proxy avoidance

2007-06-24 Thread Juraj Sakala
Jigar Raval wrote: Hello to all, How to block proxy avoidance in squid. Is there a url database available for download i.e. malware url database is available. Warm Regards Jigar Jigar Raval Engineer-SC (Computer) Computer Center Physical Research Laboratory Ahmedabad-380009. Tel. No.: +91-0

Re: [squid-users] limit conn

2007-06-24 Thread Juraj Sakala
ArioS wrote: Dear, Is it possible to apply limit conn in squid ? ex : i want to limit only accept 10 connection each ip. Thx b4 see manual acl aclname maxconn number

Re: [squid-users] limit conn

2007-06-24 Thread Juraj Sakala
Tek Bahadur Limbu wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mon, 25 Jun 2007 12:02:01 +0700 "ArioS" <[EMAIL PROTECTED]> wrote: Dear, Is it possible to apply limit conn in squid ? ex : i want to limit only accept 10 connection each ip. Hi ArioS, I don't think that

Re: [squid-users] aufs is broken too in 2.6 (and badly)

2007-06-25 Thread Juraj Sakala
Michel Santos wrote: Henrik Nordstrom disse na ultima mensagem: And yes, I don't care much for diskd. Never have. My main focus is on aufs and ufs. But how swap.state is maintained should be the same in all three "ufs" based cache_dir types. And with current FreeBSDs also fully capable of us

Re: [squid-users] Advise on what to monitor using MRTG

2007-06-29 Thread Juraj Sakala
Ralf Hildebrandt wrote: * Tek Bahadur Limbu <[EMAIL PROTECTED]>: I have the following set of graphs: http://www.henriknordstrom.net/code/squid_statistics/ the rrdtool scripts collecting the graphs is found in the code Sorry, but I'm probably blind: Where *IS* the code? http:

Re: [squid-users] Detecting and blocking child proxy servers

2007-07-25 Thread Juraj Sakala
On Tuesday 24 July 2007 12:56, Tek Bahadur Limbu wrote: > Is this possible? In other words, I want my proxy servers to detect > squid or other proxy severs which are being used or operated by others > besides me. May it is bepossible: - if you know your network you can use header x_forwarded_for t

Re: [squid-users] Detecting and blocking child proxy servers

2007-07-25 Thread Juraj Sakala
On Wednesday 25 July 2007 14:42, Tek Bahadur Limbu wrote: > Juraj Sakala wrote: > > On Tuesday 24 July 2007 12:56, Tek Bahadur Limbu wrote: > >> Is this possible? In other words, I want my proxy servers to detect > >> squid or other proxy severs which are being

Re: [squid-users] Detecting and blocking child proxy servers

2007-07-26 Thread Juraj Sakala
> Thanks once again for sharing light on this. Do you have any examples > where I can use req_header to detect if my clients have their own proxy > servers? > > Any clue, web links or posts will highly be appreciated. > > Also is req_header the only option whereby we can detect child proxies? > Or