Re: [squid-users] 00:00:00:00:00:00 %>eui and squid 3.4x

2014-04-03 Thread David Touzeau
-Message d'origine- From: Eliezer Croitoru Sent: Friday, April 04, 2014 12:04 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] 00:00:00:00:00:00 %>eui and squid 3.4x On 04/04/2014 12:33 AM, David Touzeau wrote: You suggest to report this behavior to bugtrack ?

Re: [squid-users] 00:00:00:00:00:00 %>eui and squid 3.4x

2014-04-03 Thread David Touzeau
On 03 Apr 2014, at 23:18, David Touzeau wrote: On 03 Apr 2014, at 22:59, David Touzeau wrote: Dear all I’m fighting with the squid 3.4x branch. Since this branch is born the %>eui did not work any more. I’m testing all Squid 3.4x builds and Squid is not able to detect MAC Addresses

Re: [squid-users] 00:00:00:00:00:00 %>eui and squid 3.4x

2014-04-03 Thread David Touzeau
On 03 Apr 2014, at 22:59, David Touzeau wrote: Dear all I’m fighting with the squid 3.4x branch. Since this branch is born the %>eui did not work any more. I’m testing all Squid 3.4x builds and Squid is not able to detect MAC Addresses and write in logs 00:00:00:00:00:00 The latest sq

[squid-users] 00:00:00:00:00:00 %>eui and squid 3.4x

2014-04-03 Thread David Touzeau
Dear all I’m fighting with the squid 3.4x branch. Since this branch is born the %>eui did not work any more. I’m testing all Squid 3.4x builds and Squid is not able to detect MAC Addresses and write in logs 00:00:00:00:00:00 The latest squid 3.3.1x works like a charme on MAC addresses and hav

[squid-users] Assertion failed: forward.cc:784: "peer->use_ssl" when using an Squid parent.

2014-04-03 Thread David Touzeau
Hi all i Have this kind of network: 1) A Squid "client" 3.3.12 with ssl-bump enabled transparent method. 2) A Squid Proxy 3.3.12 act has "parent" that listens 8080 but not in transparent mode. It is just designed to retreive content directly from Internet. Browser –> SSL –> Squid client +

Re: [squid-users] Pass the username to the cache parent

2014-03-14 Thread David Touzeau
On 14/03/2014 9:18 p.m., David Touzeau wrote: Dear Best list I'm using Squid connected to an Active Directory server in front of users. We have a central Squid server that act has Parent. This Squid parent server serves as caching and did not have any authentication method I would lik

[squid-users] Pass the username to the cache parent

2014-03-14 Thread David Touzeau
Dear Best list I'm using Squid connected to an Active Directory server in front of users. We have a central Squid server that act has Parent. This Squid parent server serves as caching and did not have any authentication method I would like the child Squid sends usernames to the Squid Parent

Re: [squid-users] Tproxy mode on Debian 7 Table does not exist

2014-02-27 Thread David Touzeau
hould use "-t mangle" instead of "tproxy" Good luck, Eliezer On 26/02/2014 13:57, David Touzeau wrote: uname –a report #1 SMP Debian 3.2.51-1 x86_64 GNU/Linux iptables -t tproxy -A PREROUTING -i eth0 -p tcp -m tcp --dport 80 -j TPROXY --on-port 80 iptables v1.4.14: can&#x

[squid-users] Tproxy mode on Debian 7 Table does not exist

2014-02-26 Thread David Touzeau
Hi all I’m trying to implement the Tproxy mode on Debian 7 without successs. Is there anybody have successfully implement it on Debian 7 I have setup this : modprobe -a nf_tproxy_core xt_TPROXY xt_socket xt_mark ip_gre gre lsmod |grep proxy nf_tproxy_core 12404 1 xt_TPROXY uname –a re

[squid-users] Amos: Procedure to get a quote from Squid Team.

2014-02-08 Thread David Touzeau
Dear Amos. I would like to know what is the procedure in order to contact you to get a quote/prices for specifics devs and support from Squid dev team. Could you please reply to me a message in order to discuss ? Best regards.

[squid-users] Squid 3.4.0.1-20130909-r12987 %>eui not working.

2013-09-09 Thread David Touzeau
Dear i have tested the squid 3.4 ( 3.4.0.1-20130909-r12987 ) There is some issue in regex_pattern (but i see that it will be fixed it in squid 3.4.0.2) I'm using %>eui in access.log in order to track MAC address. It seems that this version is not able to detect MAC and write 00:00:00:00:00:

[squid-users] squid 3.3.3 : deny_info with NTLM - remove popup auth -

2013-07-03 Thread David Touzeau
Dear, i would like squid to not display authentication popup if the client is not authenticated trough NTLM For this i have understood that if deny_info is set then Squid redirect the error to the specified url. I have set this: auth_param ntlm program /usr/bin/ntlm_auth --domain=ABC.LAB -

[squid-users] cache_peer: Squid did not use certificate defined in the the cache_peer

2013-05-27 Thread David Touzeau
Dear i have setup a local apache that listens on 82 port Squid is on reverse proxy mode and listen both 443, 80 The Apache is set in virtualhost mode. When connecting to the virtual host called upadm.domain.com:443, the certificate sended by SQUID is the default certificate and not the certifi

[squid-users] Bypass bumping all websites in SSL transparent mode

2013-03-12 Thread David Touzeau
Dear I would like to use Squid 3.3x in transparent SSL mode (in order to build a kind of HotSpot systems.) My issue is : "squid force to bump all websites and change the certificate even an ACL is created to deny bump websites." I would like to know if it is possible to do that ? I have se

[squid-users] ext_time_quota_acl default rule

2013-02-26 Thread David Touzeau
Dear I would like to create a default rule in ext_time_quota_acl helper. According the config file in man.8 , you must match identity with a quota eg : john 8h / 1d In our case, we need to specifiy a "all" token as a default rule... eg * 24h/4d Is it possible to do that ?

[squid-users] ACLs: simple question about http_access and AND operator

2013-02-18 Thread David Touzeau
Dear i need some clarifications about the "AND" operator in http_access (or any other tokens using ACLs) I cannot found where i'm missed... I need to bann some websites except for some specified users. i create 2 acls: acl MyAllowedU proxy_auth david jhon mirna acl bannedw dstdomain .msn.co

Re: [squid-users] cache_dir on /dev/shm?

2013-02-13 Thread David Touzeau
-Original Message- From: Alex Rousskov Sent: Wednesday, February 06, 2013 11:01 PM To: Scott Baker Cc: squid-users@squid-cache.org Subject: Re: [squid-users] cache_dir on /dev/shm? On 02/06/2013 02:48 PM, Scott Baker wrote: I want to store all my cache dir on a ram disk. I have this

Re: [squid-users] Squid 3.3x: UNLNK id(232) Error: no filename in shm buffer

2013-02-13 Thread David Touzeau
-Original Message- From: Amos Jeffries Sent: Wednesday, February 13, 2013 2:17 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Squid 3.3x: UNLNK id(232) Error: no filename in shm buffer On 13/02/2013 1:29 a.m., David Touzeau wrote: Dear I have these errors on Squid

[squid-users] Squid 3.3x: UNLNK id(232) Error: no filename in shm buffer

2013-02-12 Thread David Touzeau
Dear I have these errors on Squid 3.3 What does it means ? 26988 UNLNK id(232) Error: no filename in shm buffer 26989 UNLNK id(547) Error: no filename in shm buffer 26988 UNLNK id(233) Error: no filename in shm buffer 26989 UNLNK id(548) Error: no filename in shm buffer 26988 UNLNK id(234) Erro

Re: [squid-users] Back to Youtube Caching or any stream cache feature request/discuss

2013-01-19 Thread David Touzeau
On 18/01/2013 9:32 p.m., David Touzeau wrote: On 1/16/2013 3:31 PM, David Touzeau wrote: Dear I would like to know if there is currently tips on Squid 3.2.x in order to cache Youtube or other stream flows. Probably not... google is your friend just add the "site:squid-cache.org&qu

[squid-users] Bad opcode: 112 from [6661:6c73:6522:2061:7420:6c69:6e65:2036]

2013-01-19 Thread David Touzeau
Dear I’m using squid 3.2.6 with 4 workers on i386 After restarting squid all kids write the Bad opcode: 112 from [6661:6c73:6522:2061:7420:6c69:6e65:2036] event I’m unable to surf trough squid. processes still in memory, cache mgr:info give to me a good status What does it means ?

Re: [squid-users] Back to Youtube Caching or any stream cache feature request/discuss

2013-01-18 Thread David Touzeau
On 1/16/2013 3:31 PM, David Touzeau wrote: Dear I would like to know if there is currently tips on Squid 3.2.x in order to cache Youtube or other stream flows. Probably not... google is your friend just add the "site:squid-cache.org" to the search to filter some garbage. If ther

[squid-users] Back to Youtube Caching or any stream cache feature request/discuss

2013-01-16 Thread David Touzeau
Dear I would like to know if there is currently tips on Squid 3.2.x in order to cache Youtube or other stream flows. Probably not... If there any plan on Squid 3.3 to supports the Store URL Rewriting 2.7 feature ( http://wiki.squid-cache.org/Features/StoreUrlRewrite ) Best regards

Re: [squid-users] ACL: remove Authentication popup

2013-01-07 Thread David Touzeau
Fixed using a 303 deny_info remote address Thanks !! -Original Message- From: David Touzeau Sent: Monday, January 07, 2013 6:10 PM To: squid-users@squid-cache.org Subject: [squid-users] ACL: remove Authentication popup Dear, i’m using external helper in order to ban members according

[squid-users] ACL: remove Authentication popup

2013-01-07 Thread David Touzeau
Dear, i’m using external helper in order to ban members according groups against an Active Directory server. Rule works as expected but banned users are asked indefenitively with an authentication popup. I have tested many ways but always a popup authentication is displayed to the banned users

Re: [squid-users] Re: Fighting with kerberos: WARNING: received type 1 NTLM token

2013-01-03 Thread David Touzeau
Hi David, Can you get a ticket for HTTP/ ? Do you use IE or Firefox or ? Markus "David Touzeau" wrote in message news:21acfb9be8e34c7dba0fa2f2d0b32...@fr.kaspersky.com... Dear I have connected the server to the Active Directory, get tickets and so on. Clients are Windows 8 co

[squid-users] Fighting with kerberos: WARNING: received type 1 NTLM token

2013-01-02 Thread David Touzeau
Dear I have connected the server to the Active Directory, get tickets and so on. Clients are Windows 8 connected to the domain. in squid.conf: auth_param negotiate program /lib/squid3/negotiate_kerberos_auth -d auth_param negotiate children 10 auth_param negotiate keep_alive on auth_param basic

Re: [squid-users] Re: Squid did not use the next set cache

2013-01-02 Thread David Touzeau
-Original Message- From: RW Sent: Saturday, December 29, 2012 11:24 PM To: squid-users@squid-cache.org Subject: [squid-users] Re: Squid did not use the next set cache On Thu, 27 Dec 2012 10:54:09 +0100 David Touzeau wrote: Dear, I have set 2 caches on my squid 3.2.5

[squid-users] Squid did not use the next set cache

2012-12-27 Thread David Touzeau
Dear, I have set 2 caches on my squid 3.2.5 #- Multiple cpus -- (disabled) workers 1 cache_dir aufs /var/squid/cache1 1105 16 256 max-size=716800 cache_dirufs /var/cache/squid 2000 16 256 in caches infos we ca see that the first cache is full at 94% and second cache is 0% Why squ

Re: [squid-users] Squid 3.1.19 and NTLM ?

2012-12-27 Thread David Touzeau
-Original Message- From: Noc Phibee Telecom Sent: Wednesday, December 26, 2012 10:08 AM To: squid-users@squid-cache.org Subject: Re: [squid-users] Squid 3.1.19 and NTLM ? Anyone have a answer ? Le 23/12/2012 09:43, Noc Phibee Telecom a écrit : Hi we have updated our Squid Prox

[squid-users] Reverse Proxy not re-encrypt SSL

2012-12-13 Thread David Touzeau
Dear I'm using Squid 3.2.4 in reverse mode with multiple SSL web servers I need to force squid to not use the default certificate for specific target Web servers and i did not know how to do... I'm turning around this issue... Example: http_port 80 accel vhost https_port 443 accel cert=/etc

Fw: [squid-users] access_log, squid and NTLM : HaProxy

2012-12-13 Thread David Touzeau
Dear I’m using HaProxy in order to balance with 2 squids 3.2x connected to Active Directory with NTLM The NTLM is correctly forwarded to the Squid. But in access_log, squid did not write the NTLM session username. in debug mode, i correctly see NTLM forwarded by HaProxy eg: Host: www.google-

[squid-users] access_log, squid and NTLM : HaProxy

2012-12-11 Thread David Touzeau
Dear I’m using HaProxy in order to balance with 2 squids 3.2x connected to Active Directory with NTLM The NTLM is correctly forwarded to the Squid. But in access_log, squid did not write the NTLM session username. in debug mode, i correctly see NTLM forwarded by HaProxy eg: Host: www.google-an

[squid-users] cache_peer, squid parents and NTLM : NT_STATUS_INVALID_PARAMETER

2012-12-07 Thread David Touzeau
Dear I would like to use several parent proxy backend with a squid proxy that in charge to balacne requests to backends parents proxy are connected to the Active Directory and perform authentication. This in order to log accounts in access_log BROWSER 10.32.0.21 => Squid client 10.32.0.25 =>

Re: [squid-users] A way to redirect google/Youtube SSL

2012-11-28 Thread David Touzeau
-Original Message- From: Steve Hill Sent: Wednesday, November 28, 2012 5:13 PM To: David Touzeau Cc: squid-users@squid-cache.org Subject: Re: [squid-users] A way to redirect google/Youtube SSL On 28.11.12 13:52, David Touzeau wrote: Since Google and Youtube "force"

Re: [squid-users] A way to redirect google/Youtube SSL

2012-11-28 Thread David Touzeau
Thanks !!! But what about Youtube ? -Original Message- From: Steve Hill Sent: Wednesday, November 28, 2012 5:13 PM To: David Touzeau Cc: squid-users@squid-cache.org Subject: Re: [squid-users] A way to redirect google/Youtube SSL On 28.11.12 13:52, David Touzeau wrote: Since

[squid-users] A way to redirect google/Youtube SSL

2012-11-28 Thread David Touzeau
Dear all Since Google and Youtube "force" browser to use SSL we have lake of statistics and web filtering with Squid. I would like if there is a good way in order to redirect SSL requests to google/Youtube to non-encrypted requests ? Best regards

[squid-users] squid 3.2.2: external_acl_type why ttl is not working

2012-10-13 Thread David Touzeau
Dear As i understand, TTL in external_acl_type force Squid to cache a positive answer from the external process. In my case it seems that the TTL is not used and squid query the helper on each request. Did i miss something ? external_acl_type SplashScreenAuthDef ttl=120 negative_ttl=0 chil

Re: [squid-users] external_acl_type script crash always after 1mn

2012-09-29 Thread David Touzeau
riginal Message- From: David Touzeau Sent: Saturday, September 29, 2012 4:46 PM To: squid-users@squid-cache.org Subject: [squid-users] external_acl_type script crash always after 1mn Dear i'm trying to build my own external_helper using php. I have some troubles and i did not see why... It s

[squid-users] external_acl_type script crash always after 1mn

2012-09-29 Thread David Touzeau
Dear i'm trying to build my own external_helper using php. I have some troubles and i did not see why... It seems that after 1mn squid claim that helper are crashed. I did not know why in my code. i did not see where and how it crash... You will see that the php code is very simple and do nothing

[squid-users] Replicate caches between 2 squid servers

2012-09-29 Thread David Touzeau
Dear I have setup 2 squid servers in load-balancing mode. I would like to replicate the cache content between these 2 servers. If the load-balancer switch to the second server, the second server already store the first server content cache Is it possible to do that ? best regards

[squid-users] SQUID -> Active Directory lsass.exe to 100% CPU

2012-09-27 Thread David Touzeau
Dear i would like to know if somebody have encounter this issue with Samba+squid I'm using NTLM with Squid and connected Samba to my Active Directory 2008 R2 I mention that squid works perfectly but it seems this is a winbindd issue or misconfiguration. It seems that winbindd ask every millis

[squid-users] Redirect https to http

2012-09-13 Thread David Touzeau
Dear I would like to create acl in order to redirect requests to https://www.youtube.com to http://www.youtube.com some firefox browsers go directly to youtube using ssl mode has the http mode is not a problem on youtube. Can anybody helps me about creating this kind of acls best regards

Re: [squid-users] Questions about SSL logging

2012-09-11 Thread David Touzeau
t;%{X-Forwarded-For}>h" cache_store_log stdio:/var/log/squid/store.log access_log syslog:authpriv.info common !squidclient access_log stdio:/var/log/squid/sarg.log squid !squidclient #- Multiple cpus -- (disabled) workers 1 cache_dir aufs /var/cache/squid 10000 16 256 # - OTHER

[squid-users] Questions about SSL logging

2012-09-10 Thread David Touzeau
Dear, i’m using squid 3.2 Sometimes the Squid-cache log correctly the SSL connections to web sites Sep 11 00:30:37 kav4proxy squid[8504]: MAC:64:27:37:02:53:3d 192.168.1.158 - dtouzeau [11/Sep/2012:00:30:37 +0200] "CONNECT www.artica.fr:443 HTTP/1.1" 200 26051 TCP_MISS:HIER_DIRECT UserAgent:"Moz

[squid-users] Debug only for a destination domain

2012-08-02 Thread David Touzeau
Dear We encounter issues while accessing to a website trough squid 3.2.18 while accessing to it without using squid is not an issue. We would like to know how to create a debug rule only when accessing to this web site. Is there a way do this ? Best regards.

Re: [squid-users] Squid 3.1x: No login name is sent to the redirector (NTLM+Active Directory)

2012-06-13 Thread David Touzeau
Thanks Amos for the answer. According this discuss with you it seems that the only workaround is to reverse back to 2.7 ? http://www.squid-cache.org/mail-archive/squid-users/201001/0228.html Le 14/06/2012 02:15, Amos Jeffries a écrit : On 14.06.2012 04:21, David Touzeau wrote: Dear I&#

[squid-users] Squid 3.1x: No login name is sent to the redirector (NTLM+Active Directory)

2012-06-13 Thread David Touzeau
Dear I'm using 3.1.20 connected to Active Directory with Ufdbguard as the redirector URL Web filter engine. It seems that Squid did not send the username to the redirector (only ip addresses). In this case, we cannot create rules according login name in the redirector configuration. Is it a

Re: [squid-users] 3.2.0.17-20120527-r11561: FATAL: Ipc::Mem::Segment::open failed to shm_open(/squid-squid-page-pool.shm)

2012-06-11 Thread David Touzeau
Did i'm alone on this issue ? Le 08/06/2012 16:34, David Touzeau a écrit : Dear I think i have this bug back http://bugs.squid-cache.org/show_bug.cgi?id=3411 I'm using I've recompiled squid with squid3.2 version 3.2.0.17-20120527-r11561 on 64 bits computer Ubuntu 12.04 So

[squid-users] 3.2.0.17-20120527-r11561: FATAL: Ipc::Mem::Segment::open failed to shm_open(/squid-squid-page-pool.shm)

2012-06-08 Thread David Touzeau
Dear I think i have this bug back http://bugs.squid-cache.org/show_bug.cgi?id=3411 I'm using I've recompiled squid with squid3.2 version 3.2.0.17-20120527-r11561 on 64 bits computer Ubuntu 12.04 So i've a problem because when i open a google maps FATAL: Ipc::Mem::Segment::open failed to shm_

[squid-users] Squid 3.1: access.log did not log authenticated members

2012-04-20 Thread David Touzeau
Dear I have tested all log formats on my squid 3.1.19 and member information still "IP - - " eg: 192.168.1.212 - - [ Is it normal ? I notice that using squid 3.2 log correctly members uid in access.log Best regards

Re: [squid-users] Need help for ACL: Authentication web Form + Cookies

2012-04-14 Thread David Touzeau
Thanks Amos That should be very cool ! especially MySQL Le 14/04/2012 09:11, Amos Jeffries a écrit : On 14/04/2012 6:08 a.m., David Touzeau wrote: Dear all I would like to use 2 external helpers in order to use a web authentication form The deal is to use combination of ext_session_acl

[squid-users] Need help for ACL: Authentication web Form + Cookies

2012-04-13 Thread David Touzeau
Dear all I would like to use 2 external helpers in order to use a web authentication form The deal is to use combination of ext_session_acl and my own external helper But i did not know how to create the ACLs I have done 50% --- external_acl_type checkau

Re: [squid-users] squid 3.2: TCP_MISS:HIER_DIRECT

2012-04-13 Thread David Touzeau
p.m., David Touzeau wrote: Dear With this configuration i have a lot of TCP_MISS:HIER_DIRECT I understand that TCP_MISS means that the object is not stored on cache What's means HIER_DIRECT ? http://wiki.squid-cache.org/SquidFaq/SquidLogs under hierarchy codes. Second, why the proxy

[squid-users] squid 3.2: transparent mode freeze with google queries/long urls.

2012-04-12 Thread David Touzeau
Dear I'm using the Squid Cache: Version 3.2.0.16-20120401-r11543 It seems when trying (in transparent mode) to access to websites with long queries like google does when trying to search items, access to websites is frozen. retrying the query on google after several seconds allows to access

[squid-users] squid 3.2: TCP_MISS:HIER_DIRECT

2012-04-12 Thread David Touzeau
Dear With this configuration i have a lot of TCP_MISS:HIER_DIRECT I understand that TCP_MISS means that the object is not stored on cache What's means HIER_DIRECT ? Second, why the proxy did not cache anything ? cache_dir diskd /var/squid/cache_booster 500 16 256 max-size=322560 #- M

[squid-users] 3.2.0.16-20120327-r11543: shm_open(/squid-squid-page-pool.shm): (2) No such file or directory

2012-03-30 Thread David Touzeau
Dear I have this error FATAL: Ipc::Mem::Segment::open failed to shm_open(/squid-squid-page-pool.shm): (2) No such file or directory Here it is the worker configuration : cache_dir ufs /var/spool/squid3 676 16 256 cache_dir ufs /var/spool/squid3-0 5 16 256 workers 2 if ${process_number}

Re: [squid-users] squid 3.2.0.16: heavy load, huge store.log and WARNING: Disk space over limit: 246385708.00 KB > 5120000 KB

2012-03-09 Thread David Touzeau
fix you mention the latest version was squid-3.2.0.15-20120302-r11519 Do you recommend cleaning a rebuilding caches ? Le 09/03/2012 13:35, Amos Jeffries a écrit : On 10/03/2012 12:28 a.m., David Touzeau wrote: Dear I have upgraded my squid 3.2.0.15 to the squid 3.2.0.16 My server have a load be

[squid-users] squid 3.2.0.16: heavy load, huge store.log and WARNING: Disk space over limit: 246385708.00 KB > 5120000 KB

2012-03-09 Thread David Touzeau
Dear I have upgraded my squid 3.2.0.15 to the squid 3.2.0.16 My server have a load between 4 to 10 ps aux squid10495 69.2 0.8 878308 34624 ?Dl 14:41 21:26 (squid-3) -sYC -f /etc/squid3/squid.conf squid10496 19.5 0.8 877012 36300 ?Sl 14:41 6:02 (squid-1) -sYC -f

[squid-users] Squid 3.2: segfault at 0 ip (null) sp bfa8e03c using iptables + transparent mode

2012-03-07 Thread David Touzeau
Dear, I'm using Squid Cache: Version 3.2.0.15-20120306-r11529 in i386 on Ubuntu 10.04 iptables v1.4.4 and kernel 2.6.32-38-generic-pae #83-Ubuntu SMP In transparent mode with iptables. Each 10 Minutes we are unable to access to Internet and there is a squid crash. Restart squid service sol

Re: [squid-users] blacklist

2012-03-04 Thread David Touzeau
Have you tried ufdbguard (www.urlfilterdb.com) ? More fastest than squidguard Le 04/03/2012 13:37, Esteban Torres Rodríguez a écrit : Hi all. Currently I have 3 servers running with squid and haproxy balancing ahead of them. It works perfectly. Now I want to block porn sites, viruses, externa

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
Your are right Amos. If need iptables 1.4.10 and kernel 2.6.37 and Debian backports provide iptables 1.4.8 and kernel 3.0 It is not possible with debian squeeze to use correctly TProxy mode. I think this should be the reason that in my previous post, i had many issues implementing TProxy mode.

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
d in the first place? Thanks. On Fri, Mar 2, 2012 at 9:33 AM, David Touzeau wrote: There is bad news, backports did not change something according Tproxy Only kernel 3.2x is available on backports repository. apt-get install -t squeeze-backports linux-image-3.2.0-0.bpo.1-686-pae apt-get inst

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
SNIF Le 02/03/2012 17:03, David Touzeau a écrit : iptables -t tproxy -A PREROUTING -i eth0 -p tcp -m tcp --dport 80 -j TPROXY --on-port 80

Re: [squid-users] Squid 3.2x: Question about performances in tmpfs

2012-03-02 Thread David Touzeau
Thanks Amos You are talking about rock but it seems that rock is not really ready in the 3.2 branch... There is some bugs still need to be fixed. Do you confirm it ? Le 02/03/2012 17:03, Amos Jeffries a écrit : On 3/03/2012 4:47 a.m., David Touzeau wrote: Dear / / I have a server with

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
OK thanks Amos I will try it and send to the list my results... Le 02/03/2012 16:55, Amos Jeffries a écrit : On 3/03/2012 4:37 a.m., David Touzeau wrote: Thanks Amos So to be clear for me I need to enable backports in my sources.list and upgrade the kernel version to 2.6.37 or above

Re: [squid-users] Squid 3.2x: Question about performances in tmpfs

2012-03-02 Thread David Touzeau
Thanks Matus So for you... It make more sense to increase the "cache_mem" to the maximal possible value instead playing with "cache_dir" ? Le 02/03/2012 16:55, Matus UHLAR - fantomas a écrit : On 02.03.12 16:47, David Touzeau wrote: I have a server with 8Go me

[squid-users] Squid 3.2x: Question about performances in tmpfs

2012-03-02 Thread David Touzeau
Dear / / I have a server with 8Go memory on 4 processors. Currently my squid proxy 3.2 and my Debian using around 2Go memory in the full production mode. I would like to try to add a kind of "temporary" cache in tmpfs using around 3.5go of Squid Cache./ /Did it make sense to perform this inf

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
Thanks Amos So to be clear for me I need to enable backports in my sources.list and upgrade the kernel version to 2.6.37 or above in order to make TPROXY already compiled in the kernel ? Le 02/03/2012 16:01, Amos Jeffries a écrit : On 2/03/2012 11:03 p.m., David Touzeau wrote: Thanks

Re: [squid-users] Implement Tproxy on Debian squeeze

2012-03-02 Thread David Touzeau
it : On 2/03/2012 2:46 p.m., David Touzeau wrote: Dear I would like to implement TProxy with Debian squeeze for Squid 3.2x Is there a freshed howto somewhere that explain how to correctly build the debian kernel in order to enable Tproxy ? Best regards The Squeeze kernel should work out of th

[squid-users] Implement Tproxy on Debian squeeze

2012-03-01 Thread David Touzeau
Dear I would like to implement TProxy with Debian squeeze for Squid 3.2x Is there a freshed howto somewhere that explain how to correctly build the debian kernel in order to enable Tproxy ? Best regards

[squid-users] 3.2.0.15-20120219-r11508: Frequently Timed out connections

2012-02-23 Thread David Touzeau
Dear I'm testing this version 3.2.0.15-20120219-r11508 Regulary, there is a freeze with timed out connections. When squid display a timed out connection a refresh page with F5 key display the web page without any problem. Is it a known issue on this version ? Bets regards

[squid-users] Make Dansguardian working with squid 3.2 + NTLM: Cannot initialise conversion from UTF-16LE to UTF-8

2011-12-20 Thread David Touzeau
Dear all I'm writing this topic here because it seems that the dansguardian mailing list is very silent. I have set squid 3.2 with nlm has this #- NTLM AUTH settings auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp auth_param basic program /usr/bin/ntlm_au

[squid-users] 3.2 version: What is the best way to connect to Active Directory ?

2011-12-14 Thread David Touzeau
since Active Directory 2008 growth fast in computing, what is the best way to link Squid 3.2x with Active Directory 2008/2003 ? Any tips ? Best regards

Re: [squid-users] Squid 3.2 help using kerberos Error returned 'BH received type 1 NTLM token'

2011-12-13 Thread david touzeau
Le mercredi 14 décembre 2011 à 10:41 +1300, Amos Jeffries a écrit : > On Tue, 13 Dec 2011 18:27:00 +0100, David Touzeau wrote: > > Dear > > > > I would like to connect my squid 3.2 to the Active Directory 2003 > > > > All Kerberos settings should working >

[squid-users] Squid 3.2 help using kerberos Error returned 'BH received type 1 NTLM token'

2011-12-13 Thread David Touzeau
Dear I would like to connect my squid 3.2 to the Active Directory 2003 All Kerberos settings should working # /usr/bin/kinit administrat...@maison.touzeau.biz -V 2>&1 Password for administrat...@maison.touzeau.biz: Authenticated to Kerberos v5 # klist Ticket cache: FILE:/tmp/krb5cc_0 Defa

[squid-users] FATAL: commonUfsDirCloseTmpSwapLog: rename failed

2011-12-03 Thread David Touzeau
Dear I have this is my cache.log FATAL: commonUfsDirCloseTmpSwapLog: rename failed Squid Cache (Version 3.2.0.13-2030-r11447): Terminated abnormally. What does it means ? Best regards

Re: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-12-02 Thread David Touzeau
Le vendredi 02 décembre 2011 à 15:05 +1300, Amos Jeffries a écrit : > Hooray progress :) > > > On 2/12/2011 5:49 a.m., David Touzeau wrote: > > > > Here it is the log in debug mode : > > > > -- > > 2011/12/01 17:49:14.106 kid1| HTTP Client loca

Re: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-12-01 Thread David Touzeau
Le jeudi 01 décembre 2011 à 09:58 +0100, David Touzeau a écrit : > Le mercredi 30 novembre 2011 à 11:14 +1300, Amos Jeffries a écrit : > > On Tue, 29 Nov 2011 22:48:39 +0100, David Touzeau wrote: > > > Dear > > > > > > I'm trying to make Squid Cac

Re: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-12-01 Thread David Touzeau
Cache: Version 3.2.0.13 > Date: > Fri, 02 Dec 2011 01:12:40 +1300 > (01/12/2011 13:12:40) > > > On 1/12/2011 9:58 p.m., David Touzeau wrote: > > Le mercredi 30 novembre 2011 à 11:14 +1300, Amos Jeffries a écrit : > >> On Tue, 29

Re: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-12-01 Thread David Touzeau
Le mercredi 30 novembre 2011 à 11:14 +1300, Amos Jeffries a écrit : > On Tue, 29 Nov 2011 22:48:39 +0100, David Touzeau wrote: > > Dear > > > > I'm trying to make Squid Cache: Version 3.2.0.13-2027-r11436 on > > transparent mode > > > > But squ

Re: [squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-11-29 Thread David Touzeau
Le mercredi 30 novembre 2011 à 11:14 +1300, Amos Jeffries a écrit : > On Tue, 29 Nov 2011 22:48:39 +0100, David Touzeau wrote: > > Dear > > > > I'm trying to make Squid Cache: Version 3.2.0.13-2027-r11436 on > > transparent mode > > > > But squ

[squid-users] SECURITY ALERT: Squid Cache: Version 3.2.0.13

2011-11-29 Thread David Touzeau
Dear I'm trying to make Squid Cache: Version 3.2.0.13-2027-r11436 on transparent mode But squid refuse to access to some websites for example google.* is ok but microsoft is impossible. How to fix this issue ? On event : Nov 29 22:18:57 squid2 squid[11257]: SECURITY ALERT: By user age

Re: [squid-users] SECURITY ALERT generated by squid in events

2011-11-28 Thread David Touzeau
Le lundi 28 novembre 2011 à 12:05 +1300, Amos Jeffries a écrit : > On Sun, 27 Nov 2011 23:36:23 +0100, David Touzeau wrote: > > Dear > > > > I have this squid version : > > > > Squid Cache: Version 3.2.0.13-2025-r11436 > > configure options:

Re: [squid-users] Display Squid Errors on browsers in transparent mode

2011-11-28 Thread David Touzeau
Le lundi 28 novembre 2011 à 12:36 +1300, Amos Jeffries a écrit : > On Sun, 27 Nov 2011 23:59:15 +0100, David Touzeau wrote: > > Le lundi 28 novembre 2011 à 11:45 +1300, Amos Jeffries a écrit : > >> On Sun, 27 Nov 2011 20:54:13 +0100, David Touzeau wrote: > >> > Than

Re: [squid-users] Display Squid Errors on browsers in transparent mode

2011-11-27 Thread David Touzeau
Le lundi 28 novembre 2011 à 11:45 +1300, Amos Jeffries a écrit : > On Sun, 27 Nov 2011 20:54:13 +0100, David Touzeau wrote: > > Thanks AMos, > > > > here it is my settings > > And the particular wrong messages which you are seeing? > > > From this I would g

[squid-users] SECURITY ALERT generated by squid in events

2011-11-27 Thread David Touzeau
Dear I have this squid version : Squid Cache: Version 3.2.0.13-2025-r11436 configure options: '--prefix=/usr' '--includedir=/include' '--mandir=/share/man' '--infodir=/share/info' '--localstatedir=/var' '--libexecdir=/lib/squid3' '--disable-maintainer-mode' '--disable-dependency-tracking' '-

Re: [squid-users] Display Squid Errors on browsers in transparent mode

2011-11-27 Thread David Touzeau
off ftp_epsv_all off ftp_telnet_protocol off debug_options ALL,1 #Logs----- coredump_dir/var/squid/cache cache_log /var/log/squid/cache.log pid_filename/var/run/squid.pid error_directory /usr/share/squid-langpack/en cache_store_log /var/

[squid-users] Display Squid Errors on browsers in transparent mode

2011-11-26 Thread David Touzeau
I think is normal but is there any tips/tweaks in order to display SQUID pages error when using squid in transparent mode. When connecting directly to the port, the error is correctly generated by Squid When using the transparent mode only the browser display errors. Best regards.

Re: [squid-users] [3.2.0.13]: DiskIO/IpcIo/IpcIoFile.cc for RockStore / No such file or directory

2011-11-23 Thread David Touzeau
Le mercredi 23 novembre 2011 à 22:40 +1300, Amos Jeffries a écrit : > On 23/11/2011 9:12 p.m., FredB wrote: > > Maybe a problem with /var/cache/RockStore-0 directory ? Permission ? > > > > > > - Mail original - > > De: "David Touzeau" > > À:

Re: [squid-users] ERROR: No forward-proxy ports configured

2011-11-23 Thread David Touzeau
d-proxy ports configured > Date: > Wed, 23 Nov 2011 23:37:00 +1300 > (23/11/2011 11:37:00) > > > On 23/11/2011 11:14 p.m., David Touzeau wrote: > > Dear i'm using squid 3.2.0.13-2021-r11422 > > for each request i receive an event >

[squid-users] ERROR: No forward-proxy ports configured

2011-11-23 Thread David Touzeau
Dear i'm using squid 3.2.0.13-2021-r11422 for each request i receive an event Nov 23 11:08:24 kav4proxy64Coatpont squid[16844]: ERROR: No forward-proxy ports configured. Nov 23 11:08:24 kav4proxy64Coatpont squid[16844]: ERROR: No forward-proxy ports configured. Nov 23 11:08:24 kav4proxy64Coatp

[squid-users] [3.2.0.13]: DiskIO/IpcIo/IpcIoFile.cc for RockStore / No such file or directory

2011-11-22 Thread David Touzeau
Dear I have enabled RockStore on my squid 3.2.0.13-20111027-r11388 has this workers 2 cache_dir rock /var/cache/RockStore-0 256 max-size=32768 cache_dir rock /var/cache/RockStore-1 256 max-size=32768 cache_dir ufs /var/cache/squid 2000 16 256 squid claim 2011/11/22 17:25:31 kid2| Disk

[squid-users] 3.2.0.13: send log to tcp behavior ?

2011-10-24 Thread David Touzeau
Dear I'm using access_log tcp:127.0.0.1:54424 common for testing purpose. I have developed a daemon that listen TCP on specified port. All logs are correctly sended but there is this behavior : If my daemon crash and close the current TCP connection with squid, squid stop sending logs to my

[squid-users] 3.2.0.13: Notice about access_log doc

2011-10-24 Thread David Touzeau
Dear in http://www.squid-cache.org/Doc/config/access_log/ there is mention about udp To send each log line as text data to a UDP receiver. Place: The destination host name or IP and port. Place Format: \\host:port tcp To send each log line as

Re: [squid-users] 3.2.0.13: Cannot bind socket FD 21 to [::]:22381: (98) Address already in use

2011-10-24 Thread David Touzeau
Le lundi 24 octobre 2011 à 11:48 +0200, Jean-Philippe Menil a écrit : > > > > I had removed icp_port but the problem still occur : > > > > notice that i have > > > > http_port 22381 > > > > perhaps it is an ipv6 issue ?? > > > > Oct 24 11:34:19 kprxy squid[19120]: Squid Parent: (squid-1) process >

Re: [squid-users] 3.2.0.13: Cannot bind socket FD 21 to [::]:22381: (98) Address already in use

2011-10-24 Thread David Touzeau
t; "Comm::IsConnOpen(icpOutgoingConn)" -> maybe ICP Bug with workers ? > > > - "David Touzeau" a écrit : > > > Dear > > > > I encounter many times this issue. > > > > "Cannot bind socket FD 21 to [::]:x: (98) Address a

Re: [squid-users] 3.2.0.13: FATAL: dying from an unhandled exception: theGroupBSize > 0

2011-10-24 Thread David Touzeau
Le lundi 24 octobre 2011 à 11:49 +1300, Amos Jeffries a écrit : > On 23/10/11 23:49, David Touzeau wrote: > > Dear > > > > I'm using the 3.2.0.13-20111022-r11381 > > > > When set > > > > worker 2 > > > > In squid.conf > > > >

[squid-users] 3.2.0.13: Cannot bind socket FD 21 to [::]:22381: (98) Address already in use

2011-10-24 Thread David Touzeau
Dear I encounter many times this issue. "Cannot bind socket FD 21 to [::]:x: (98) Address already in use" Perhaps it is a misunderstand of the SMP working process. I have 2 processors. Is each worker try to bind the same Port/IP ? Oct 24 09:35:31 prxysquid-squid squid[3586]: Starting Squ

Re: [squid-users] 3.2.0.13: commBind: Cannot bind socket FD 18 to [::]: (13) Permission denied

2011-10-24 Thread David Touzeau
Le lundi 24 octobre 2011 à 08:46 +0200, Jean-Philippe Menil a écrit : > Hi, > > on wich os? > > On debian, i have to create /var/run/squid and check the permission, to > get it working. > > Regards. > Debian 6 Your tips seems to fix the issue... THanks

  1   2   >