[squid-users] Interpreting a sarg report

2009-06-18 Thread Paul Cocker
onnections) and for BYTES whether this is referring to the amount squid downloaded, or the amount of information passed to the clients, in other words can it be taken as an indication of traffic coming down my Internet pipe? Thanks for any guidance you guys can offer. P

[squid-users] Bungled squid.conf due to cache_dir

2007-09-14 Thread Paul Cocker
version, it shouldn't matter anyway should it? I tried changing localhost to localhost:3129 just in case, but it made no difference. Can this be made to work in a configuration where there are spaces in the directory names? Many thanks, Paul Cocker IT Systems Administrator IT Security Officer

RE: [squid-users] Compiling Squid to auth on ldap server

2007-09-17 Thread Paul Cocker
uid2614/libexec/mswin_ntlm_auth.exe auth_param ntlm children 5 auth_param ntlm keep_alive on # If not you'll need to list your auth_param of choice Hope this helps :) Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business

RE: [squid-users] Compiling Squid to auth on ldap server

2007-09-18 Thread Paul Cocker
Just a reminder to copy in the squid-users group, otherwise you're not going to get much of a response ;) Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY -Ori

[squid-users] Java authentication under SquidNT 2.6 STABLE 14 using NTLM

2007-09-18 Thread Paul Cocker
web.site.com:443 - NONE/- text/html I note from the logs that where we register NONE, there should be the username of the individual in question. Any help would be much appreciated. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside

[squid-users] FW: Java authentication under SquidNT 2.6 STABLE 14 using NTLM

2007-09-18 Thread Paul Cocker
solution, or merely a workaround. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY -Original Message- From: Paul Cocker Sent: 18 September 2007 19:52 To: squid-users@squid

RE: [squid-users] Java authentication under SquidNT 2.6 STABLE 14using NTLM

2007-09-19 Thread Paul Cocker
How so? I didn't see anything in the change logs which jumped out at me. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY -Original Message- From: Henrik Nord

RE: [squid-users] Java authentication under SquidNT 2.6 STABLE14using NTLM

2007-09-19 Thread Paul Cocker
Apologies for the duplicate, I received a "failed delivery" message. What classifies as a "messenger" under squid then? Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane

[squid-users] SquidNT - Compressing rotated logs

2007-09-20 Thread Paul Cocker
't want to rely on people remembering to compress them again after. Anyone know of a built in method I can use to do this? Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY

RE: [squid-users] Java authentication under SquidNT 2.6STABLE14using NTLM

2007-09-20 Thread Paul Cocker
Many thanks, I guess I'll move us to STABLE 16. I'm tempted to copy the .conf, but I note the changelog talks about a .conf re-ordering, so I guess it'll be best to just copy my custom lines over. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post

RE: [squid-users] SquidNT - Compressing rotated logs

2007-09-20 Thread Paul Cocker
Yes, but this then requires a 3rd party utility to create the ZIP, and I was looking first for a "Windows only" method. "Compressed folder" is just how Windows refers to a ZIP archive, be it of a file or a folder or anything. Paul Cocker IT Systems Administrator IT Securi

RE: [squid-users] Java authentication under SquidNT2.6STABLE14using NTLM

2007-09-20 Thread Paul Cocker
Initially I did it that way, being used to the BSDs working in the same fashion, but I changed it back simply due to the documentation recommending an exact copy. I think you're right though, clean config for the win ;) Paul Cocker IT Systems Administrator IT Security Officer 01628 81

RE: [squid-users] Java authentication underSquidNT2.6STABLE14using NTLM

2007-09-20 Thread Paul Cocker
copy since you start from a blank anyway. So it could just be my interpretation of their meaning. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY -Original Message---

RE: [squid-users] Java authentication under SquidNT 2.6 STABLE 14using NTLM

2007-09-20 Thread Paul Cocker
Java app the access.log recorded the following: TCP_DENIED/407 2035 CONNECT web.site.com:443 - NONE/- text/html Same as before :( Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL

RE: [squid-users] SquidNT - Compressing rotated logs

2007-09-21 Thread Paul Cocker
So simple I'm disgusted I didn't think of it. Thanks. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY -Original Message- From: Henrik Nordstrom [mai

[squid-users] User failing to authenticate over NTLM

2007-09-25 Thread Paul Cocker
ain\user NONE/- text/html I had him change his password in case the machine was using a cached password and it was out-of-sync with the domain, but the problem remains. Unsure how to proceed, the permissions look fine and the NTLM authentication is working for everyone else. Paul Cocker IT Syst

[squid-users] How often is mswin_check_lm_group.exe Can't find DC for user's domain logged?

2007-10-15 Thread Paul Cocker
n for a single connection? Basically, how severe is this error? Are one or two expected? Should I only worry when I see a cache.log swamped with them? Or is this a major concern? Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Busi

RE: [squid-users] Squid on DualxQuad Core 8GB Rams - Optimization - Performance - Large Scale - IP Spoofing

2007-10-16 Thread Paul Cocker
For the ignorant among us can you clarify the meaning of "devices"? Paul Cocker IT Systems Administrator IT Security Officer -Original Message- From: Adrian Chadd [mailto:[EMAIL PROTECTED] Sent: 15 October 2007 10:28 To: Tek Bahadur Limbu Cc: Haytham KHOUJA (devnull); squid-u

[squid-users] /mswin_check_lm_group.exe NetUserGetGroups() failed

2007-10-22 Thread Paul Cocker
Since the message never specifies, what is the cause of this failure in scenarios whereby this command works 95% of the time? Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post (Doordrop Media) Ltd. 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY

[squid-users] Domain & URL blacklists

2007-11-01 Thread Paul Cocker
omething I have time for at the moment, so I am trying to plug in what I can without crippling performance (and what is the likely performance impact?). Do I call both files via acl {aclname} dstdomain {filepath}, or should IP lists be called using a different command? Paul Cocker IT Systems Adm

RE: [squid-users] Domain & URL blacklists

2007-11-01 Thread Paul Cocker
My bad, in fact from further analysis it seems that the domain files are the mysite.com listings and URLs are things like mysite.com/something/?somethingelse.htm. Does the later have any relevance or use within Squid? Paul Cocker IT Systems Administrator -Original Message- From: Paul

RE: [squid-users] Domain & URL blacklists

2007-11-01 Thread Paul Cocker
Just squid, it's running on a Windows box and I don't have the time currently to figure out how to run cygwin and squidguard together, so I'm looking simply to hook the most useful lists direct into squid and see how much it harms performance. Paul Cocker IT Systems Administrator

RE: [squid-users] Domain & URL blacklists

2007-11-02 Thread Paul Cocker
Is there any existing information on the number of entries squid can handle before you start running into problems. Am I right in assuming this is mainly processor dependent? Paul Cocker IT Systems Administrator -Original Message- From: Chris Robertson [mailto:[EMAIL PROTECTED] Sent

[squid-users] Full domain block

2007-11-05 Thread Paul Cocker
Alas, it was all so perfectly planned. Grab some blacklists from Shalla - http://www.shallalist.de/ - and hook the domain lists into squid using dstdomain. Unfortunately, it seems squid's interpretation of domain names is incredibly literal, so rather than youtube.com blocking *.youtube.com, we in

[squid-users] Optimal maximum cache size

2007-11-05 Thread Paul Cocker
Is there such a thing as too much disk cache? Presumably squid has to have some way of checking this cache, and at some point it takes longer to look for a cached page than to serve it direct. At what point do you hit that sort of problem, or is it so large no human mind should worry? :) Paul IT

RE: [squid-users] squidGuard 1.3.0 released

2007-11-06 Thread Paul Cocker
Someone care to explain the difference, or history, behind squidGuard and squidGuard? :) Paul Cocker -Original Message- From: Guido Serassio [mailto:[EMAIL PROTECTED] Sent: 05 November 2007 22:07 To: squid-users@squid-cache.org Subject: [squid-users] squidGuard 1.3.0 released We are

RE: [squid-users] Optimal maximum cache size

2007-11-06 Thread Paul Cocker
I assume the in-memory index is in addition to the memory_cache? So if you have a 100GB disk cache you would need 1GB RAM... but that would only cover the index and so you would need more memory for squid itself and the memory_cache? Paul Cocker -Original Message- From: Amos Jeffries

RE: [squid-users] Full domain block

2007-11-05 Thread Paul Cocker
Thanks, chaps. Should be easy enough as there's a line break prior to each name so a simple search & replace should nail them all. Paul Cocker IT Systems Administrator TNT Post -Original Message- From: Thomas Raef [mailto:[EMAIL PROTECTED] Sent: 05 November 2007 19:12 To: sq

RE: [squid-users] Domain & URL blacklists

2007-11-06 Thread Paul Cocker
Apologies for my ignorance, but what then does squidGuard add as I was under the impression that filtering was its big job. Would I be right at assuming then that squidGuard is faster at processing block lists? Paul Cocker -Original Message- From: Amos Jeffries [mailto:[EMAIL PROTECTED

[squid-users] Exceptions to blocks

2007-11-07 Thread Paul Cocker
hey automatically get the relevant exceptions. Paul Cocker IT Systems Administrator IT Security Officer 01628 81(6647) TNT Post 1 Globeside Business Park Fieldhouse Lane Marlow Bucks SL7 1HY TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop M

[squid-users] RE: [SPAM?] Re: [squid-users] Optimal maximum cache size

2007-11-07 Thread Paul Cocker
to the disk caching...? Paul Cocker -Original Message- From: Colin Campbell [mailto:[EMAIL PROTECTED] Sent: 07 November 2007 01:06 To: Matus UHLAR - fantomas Cc: squid-users@squid-cache.org Subject: [SPAM?] Re: [squid-users] Optimal maximum cache size Importance: Low Hi, On Tue, 2007-11

[squid-users] squid log analysis

2007-11-26 Thread Paul Cocker
ysis tools available to me? Paul Cocker IT Systems Administrator TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd (05695897),TNT Post North Ltd (05701709) and TNT Post South West Ltd (05983401). Emma&#x

[squid-users] Intermittent group failure

2007-12-05 Thread Paul Cocker
ng) d:/squid2616/libexec/mswin_check_lm_group.exe -D cd -G I believe the domain shorthand is the correct format, yes? Does the authenticator respect site boundaries, or is it possible it's trying to travel the WAN? Paul Cocker IT Systems Administrator TNT Post is the trading name for TNT Post UK

[squid-users] File cache & squid

2007-12-13 Thread Paul Cocker
Is the OS file cache of any importance to squid? And by that I mean quite simply, HOW important is the OS file cache to squid? Paul Cocker IT Systems Administrator TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post

[squid-users] Reverse proxy non-performance benefits

2008-02-06 Thread Paul Cocker
ration for a website on the internal network. I see Apache can also do reverse proxy, which was surprising to me, or is it not quite the same thing? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Sc

[squid-users] mswin_check_lm_group - Time to check?

2008-02-14 Thread Paul Cocker
in cache.log? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd (05695897),TNT Post North Ltd (05701709) and TNT Post South West Ltd (05983401). Emma's Diary and Lifecycle are trading

[squid-users] Sarg report of log - Connect?

2008-05-20 Thread Paul Cocker
ections to the cache, or the number of browser connections (with multiple connections being possible during a single 'visit') etc.? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd

[squid-users] Anti-Virus Exclusions

2008-06-13 Thread Paul Cocker
The proxy server running squid will soon be getting a real-time anti-virus scanner on it. Are there any exclusions which need to be configured in regards to squid? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278

[squid-users] Blocking non-safe ports

2008-07-22 Thread Paul Cocker
ter I should be expecting to see, assuming 16825 is not listed in the Safe_ports ACL? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd (05695897),TNT Post North Ltd (05701709) and TNT

[squid-users] Understanding Expect 100 default setting

2008-12-04 Thread Paul Cocker
they were, especially as the behaviour described with the Expect 100 wasn't in violation of spec, just unusual. We had a problem which was solved by this setting, and I want to be in a position to explain why things were setup in a way which caused this issues to occur. Thanks, Paul Cocker TNT Post

[squid-users] squid & Windows Firewall

2008-12-18 Thread Paul Cocker
ee timeouts for slow response web servers for example? I feel silly for asking, but better safe than sorry I guess. Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd (05695897), TNT Post Nort

RE: [squid-users] squid & Windows Firewall

2008-12-18 Thread Paul Cocker
requests are being silently forwarded to the squid on > the router, this should not be a problem, as Windows Firewall > will not see anything different than HTTP traffic without a proxy. We explicity specify the proxy in the browser. Paul > > Regards > HASSAN > > &g

[squid-users] TCP_MISS followed by multiple TCP_DENIED

2008-12-18 Thread Paul Cocker
hecking then ntlmauthenticator shows there have been three periods over the course of the day where we had an authentication backlog, but that's it. Is that the likely cause? Performance wise everything is fine with squid. This is under squid 2.7 STABLE5 Paul Cocker TNT Post is t

[squid-users] Group and NTLM service times

2008-12-19 Thread Paul Cocker
Are there any guidelines for good and bad average service times for external_acl and ntlmauthenticator? Currently we average 120ms for the former and about 10ms for the latter and I don't know whether I should be interpreting that as good or bad. Paul Cocker TNT Post is the trading name fo

[squid-users] Native WIN32 NTLM and Basic Helpers must be used without the -A & -D switches.

2008-12-19 Thread Paul Cocker
check_lm_group line used -D as I recall there were lookup problems without it, however I want to check what this line means. What is considered a native WIN32 helper? -A isn't documented as a switch either. Certainly we're a 100% Windows domain. Can anyone clarify this line for me? Thank

[squid-users] cache_mem

2009-01-21 Thread Paul Cocker
at a smaller value like 64MB? Paul Cocker TNT Post is the trading name for TNT Post UK Ltd (company number: 04417047), TNT Post (Doordrop Media) Ltd (00613278), TNT Post Scotland Ltd (05695897), TNT Post North Ltd (05701709), TNT Post South West Ltd (05983401), TNT Post Midlands Limited (645816

RE: [squid-users] cache_mem

2009-01-22 Thread Paul Cocker
> -Original Message- > From: Amos Jeffries [mailto:squ...@treenet.co.nz] > Sent: 21 January 2009 23:42 > To: Chris Robertson > Cc: squid-users@squid-cache.org > Subject: Re: [squid-users] cache_mem > > > Paul Cocker wrote: > >> Simple one I hope