[squid-users] p2p and squid

2008-01-23 Thread Frank Bonnet
Hello Is there a way to use squid proxying with P2P clients ? if yes is it possible to avoid it or do I have to filter with my firewall ? infos links tricks welcome Thanks Frank

Re: [squid-users] p2p and squid

2008-01-23 Thread Adrian Chadd
Squid doesn't support p2p protocols that aren't HTTP. :) On Wed, Jan 23, 2008, Frank Bonnet wrote: > Hello > > Is there a way to use squid proxying with P2P clients ? > if yes is it possible to avoid it or do I have to filter > with my firewall ? > > infos links tricks welcome > > Thanks > Fran

Re: [squid-users] p2p and squid

2008-01-23 Thread Leonardo Rodrigues Magalhães
Yeah squid supports only HTTP but also support connection tunneling with CONNECT method. My experiences showed that almost all 'P2P-through-squid' uses CONNECT and connects to IP addresses instead of hostnames. My experiences showed that CONNECT to ip addresses almost do NOT happe

Re: [squid-users] p2p and squid

2008-01-23 Thread Marcus Kool
Yes, indeed Squid *does* support P2P using HTTPS tunneling. You may use the free ufdbGuard Squid redirector to block HTTPS tunneling. ufdbGuard can also block HTTPS sites which have no valid certificate and sites which have no FQDN in the URL. Marcus Leonardo Rodrigues Magalhães wrote: Yeah

Re: [squid-users] p2p and squid

2008-01-23 Thread Leonardo Rodrigues Magalhães
Marcus Kool escreveu: Yes, indeed Squid *does* support P2P using HTTPS tunneling. just to make things clear . squid supports connection tunneling and not only HTTPS tunneling. A misconfigured squid can be used, for example, by worms to send spam emails !!! worms can connect to squid p

Re: [squid-users] p2p and squid

2008-01-23 Thread Frank Bonnet
Leonardo Rodrigues Magalhães wrote: Marcus Kool escreveu: Yes, indeed Squid *does* support P2P using HTTPS tunneling. just to make things clear . squid supports connection tunneling and not only HTTPS tunneling. A misconfigured squid can be used, for example, by worms to send spam ema

Re: [squid-users] p2p and squid

2008-01-23 Thread Marcus Kool
Leonardo Rodrigues Magalhães wrote: Marcus Kool escreveu: Yes, indeed Squid *does* support P2P using HTTPS tunneling. just to make things clear . squid supports connection tunneling and not only HTTPS tunneling. A misconfigured squid can be used, for example, by worms to send spam em

Re: [squid-users] p2p and squid

2008-01-23 Thread Mar Matthias Darin
Hello, Frank Bonnet writes: OK thanks a lot for your "lights" , I think the easyiest way for me would be protocol filtering done by the firewall ... This is also the most secure. I personally do not let squid handle the CONNECT. IMHO, this is too easy to be abused. I use a pac file that

Re: [squid-users] p2p and squid

2008-01-23 Thread Marcus Kool
Mar Matthias Darin wrote: Hello, Frank Bonnet writes: OK thanks a lot for your "lights" , I think the easyiest way for me would be protocol filtering done by the firewall ... This is also the most secure. I personally do not let squid handle the CONNECT. IMHO, this is too easy to be abused

Re: [squid-users] p2p and squid

2008-01-24 Thread Leonardo Rodrigues Magalhães
Marcus Kool escreveu: Mar Matthias Darin wrote: Hello, Frank Bonnet writes: OK thanks a lot for your "lights" , I think the easyiest way for me would be protocol filtering done by the firewall ... This is also the most secure. I personally do not let squid handle the CONNECT. IMHO, this

Re: [squid-users] p2p and squid

2008-01-24 Thread Mar Matthias Darin
Hello, Leonardo Rodrigues Magalhães writes: Yeah i have to agree with Marcus and disagree completly with Mar Matthias. But ... there are cases and cases. At least for me, letting squid deal with CONNECTs showed completly efficient and pretty enough for my needs. My needs are usually

Re: [squid-users] p2p and squid

2008-02-06 Thread Gary
On Jan 23, Marcus Kool wrote: > ufdbGuard can also block HTTPS sites which have no valid certificate > and sites which have no FQDN in the URL. Is this the only option? Does it require an account on urlfilterdb.com? Here's what I've tried but it doesn't appear to work perhaps due to misconfigura

Re: [squid-users] p2p and squid

2008-02-07 Thread Marcus Kool
Gary, ufdbGuard is free. You can can download it from http://sourceforge.net/projects/ufdbguard and you can use it with free URL databases. You only need a database license if you use it with the commercial URL database from URLfilterDB. -Marcus Gary wrote: On Jan 23, Marcus Kool wrote: > u