Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-24 Thread Ming-Ching Tiew
- Original Message - From: Amos Jeffries squ...@treenet.co.nz To: squid-users@squid-cache.org The HTTP Host: header contains a domain name which does not match the IP address the TCP connection is being made to. http://wiki.squid-cache.org/KnowledgeBase/HostHeaderForgery covers

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-23 Thread Ming-Ching Tiew
- Original Message - From: Ming-Ching Tiew mct...@yahoo.com To: squid-users@squid-cache.org squid-users@squid-cache.org The test is very repeated, ie when I 'make install' from squid-3.2.0.12 it works but not squid-3.2.018. I meant the tests were very repeatable, squid-3.2.0.12

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-23 Thread Ming-Ching Tiew
- Original Message - From: Ming-Ching Tiew mct...@yahoo.com To: squid-users@squid-cache.org squid-users@squid-cache.org The test is very repeated, ie when I 'make install' from squid-3.2.0.12 it works but not squid-3.2.018. I meant the tests were very repeatable, squid-3.2.0.12

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-23 Thread Amos Jeffries
On 24.07.2012 14:20, Ming-Ching Tiew wrote: - Original Message - From: Ming-Ching Tiew The test is very repeated, ie when I 'make install' from squid-3.2.0.12 it works but not squid-3.2.018. I meant the tests were very repeatable, squid-3.2.0.12 works, squid-3.2.0.13 works.

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-23 Thread Ming-Ching Tiew
- Original Message - From: Amos Jeffries squ...@treenet.co.nz To: squid-users@squid-cache.org One big change in 3.2.0.14 related to TPROXY traffic handling. A bug in host_strict_verify was fixed, making the validation bypass properly when the (default) non-strict was configured.

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-23 Thread Amos Jeffries
On 24/07/2012 4:53 p.m., Ming-Ching Tiew wrote: - Original Message - From: Amos Jeffries squ...@treenet.co.nz To: squid-users@squid-cache.org One big change in 3.2.0.14 related to TPROXY traffic handling. A bug in host_strict_verify was fixed, making the validation bypass properly

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-22 Thread Ming-Ching Tiew
- Original Message - From: Eliezer Croitoru elie...@ngtech.co.il i would say that the result can show some really nasty issue you are having in the network level and ebtables+switch is the basic thing to check. i will try to dump the tcp sessions on the interfaces using: tcpdump -i

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Ming-Ching Tiew
OK I could see the same problem with just fedora 15. The client side I use a Window XP machine loaded with Firefox and Internet Explorer. What I experience with this set up is that, it is impossible to logon on to Yahoo mail using Firefox. But in other occasions, from home internet, I have

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Ming-Ching Tiew
- Original Message - From: Ming-Ching Tiew mct...@yahoo.com rc.local attached. Attachment rejected so re-post inline below :- #!/bin/sh # # This script will be executed *after* all the other init scripts. # You can put your own initialization stuff in here if you don't # want to do

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Eliezer Croitoru
On 7/21/2012 3:15 AM, Ming-Ching Tiew wrote: - Original Message - From: Ming-Ching Tiew mct...@yahoo.com rc.local attached. Attachment rejected so re-post inline below :- i got it all in the private mail. #!/bin/sh # # This script will be executed *after* all the other init

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Ming-Ching Tiew
- Original Message - From: Eliezer Croitoru elie...@ngtech.co.il so what you just need for ebtables is two rules: all packets the are destined to the web om port 80.. route them into the machine... later will be intercepted by tproxy so: ebtables -t broute -A BROUTING -i eth0 -p

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Eliezer Croitoru
On 7/21/2012 6:01 AM, Ming-Ching Tiew wrote: - Original Message - From: Eliezer Croitoru elie...@ngtech.co.il so what you just need for ebtables is two rules: all packets the are destined to the web om port 80.. route them into the machine... later will be intercepted by tproxy so:

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-20 Thread Ming-Ching Tiew
Thank you for the input. I will do that sometime later and report back when I have new info. - Original Message - From: Eliezer Croitoru elie...@ngtech.co.il they indeed are not suppose to fail your setup but it's not suppose to be symmetric with tproxy. the idea of the bridge is

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-19 Thread Ming-Ching Tiew
, 2012 8:08 PM Subject: Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21) On 7/18/2012 11:35 AM, Felix Leimbach wrote: Hi, On 07/18/2012 04:28 AM, Ming-Ching Tiew wrote: When logging out from yahoo mail, it's very slow and eventually there is any error. I'm

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-19 Thread Eliezer Croitoru
you dont need to recompile the kernel. the basic kernel of fedora 15 is ok. i have some issues with fedora but most of them are due to SELINUX or basic misconfiguration. you dont need the DVD for that. just use the netinst iso and install minimal server. there is a nice RPM for fedora 15 of

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-18 Thread Felix Leimbach
Hi, On 07/18/2012 04:28 AM, Ming-Ching Tiew wrote: When logging out from yahoo mail, it's very slow and eventually there is any error. I'm not sure whether this is your problem - but I too had similar problems with 3.1.19. Upgrading to 3.1.20 solved the problem - turned out bug 3466

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-18 Thread Eliezer Croitoru
On 7/18/2012 11:35 AM, Felix Leimbach wrote: Hi, On 07/18/2012 04:28 AM, Ming-Ching Tiew wrote: When logging out from yahoo mail, it's very slow and eventually there is any error. I'm not sure whether this is your problem - but I too had similar problems with 3.1.19. Upgrading to 3.1.20

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-17 Thread Ming-Ching Tiew
When logging out from yahoo mail, it's very slow and eventually there is any error. Don't get that when configured to use nat mode. attachment: zero_size_reply.jpg

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-04 Thread Ming-Ching Tiew
--- On Mon, 7/2/12, Ming-Ching Tiew mct...@yahoo.com wrote: No your symptom and mine are totally different. With the limited testing, I don't see any problem with any OSes, any sites. I only see problem when visiting yahoo mail. Meaning when I use Windows XP, firefox, IE, Linux with

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-02 Thread Eliezer Croitoru
On 6/28/2012 11:18 AM, Ming-Ching Tiew wrote: I have set up a bridge according to instruction here :- http://wiki.squid-cache.org/Features/Tproxy4 with squid 3.1.19 and kernel 3.2.21. The configuration is working with other with most of the sites, except for yahoo mail. It's is extremely

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-02 Thread Ming-Ching Tiew
--- On Mon, 7/2/12, Eliezer Croitoru elie...@ngtech.co.il wrote: it works slowly for all clients or just windows 7 ? other clients? i have seen a problem when applying tproxy on a router with win7 client. from unknown reason using standard routing and intercept everything works fine

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-01 Thread Ming-Ching Tiew
mail problem with tproxy (squid 3.1.19, kernel 3.2.21) To: squid-users@squid-cache.org Date: Thursday, June 28, 2012, 8:18 AM I have set up a bridge according to instruction here :- http://wiki.squid-cache.org/Features/Tproxy4 with squid 3.1.19 and kernel 3.2.21. The configuration

Re: [squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-07-01 Thread Ming-Ching Tiew
--- On Mon, 7/2/12, Ming-Ching Tiew mct...@yahoo.com wrote: Attached please find the 'squid -X -N -d2 21' ouput log when connecting to yahoo mail. When connecting to http://mail.yahoo.com, I get a 'No object data received'. When connecting to https, the bridge is not setup to intercept

[squid-users] yahoo mail problem with tproxy (squid 3.1.19, kernel 3.2.21)

2012-06-28 Thread Ming-Ching Tiew
I have set up a bridge according to instruction here :- http://wiki.squid-cache.org/Features/Tproxy4 with squid 3.1.19 and kernel 3.2.21. The configuration is working with other with most of the sites, except for yahoo mail. It's is extremely slow with yahoo mail, can hardly able to login