Re: [squid-users] Using Squid as a Transparent Proxy

2015-04-23 Thread Eliezer Croitoru
I have been reading and have seen two things that needs consideration. 1 - An illustration for a WCCP example at: http://wiki.squid-cache.org/ConfigExamples/UbuntuTproxy4Wccp2#Toplogy 2 - The kernel connection tracking is needed for basic firewall functions which TPROXY is not really one of them

Re: [squid-users] bandwidth limiting

2015-04-23 Thread Alex Samad
Thanks, I had presumed that was from squid -> client not source -> squid. On 24 April 2015 at 14:06, Amos Jeffries wrote: > On 24/04/2015 2:43 p.m., Alex Samad wrote: >> Hi >> >> is there any way to limit the bandwidth squid uses to pull stuff from >> the internet ? >> >> Can it slow down reque

Re: [squid-users] bandwidth limiting

2015-04-23 Thread Amos Jeffries
On 24/04/2015 2:43 p.m., Alex Samad wrote: > Hi > > is there any way to limit the bandwidth squid uses to pull stuff from > the internet ? > > Can it slow down request, delay acks or ?? http://wiki.squid-cache.org/Features/DelayPools Amos ___ squid-u

Re: [squid-users] Bring refresh_pattern down to ~10sec?

2015-04-23 Thread Amos Jeffries
On 24/04/2015 2:46 p.m., Kristopher Linquist wrote: > Hi, > > > I’m using squid to throttle outgoing API calls to various services. > > > I’ve got Squid working with ssl_bump and currently caching any request more > often than 15 minutes with this line: > > > refresh_pattern . 15

Re: [squid-users] Using Squid as a Transparent Proxy

2015-04-23 Thread Amos Jeffries
On 24/04/2015 2:29 p.m., Srinath Krishna wrote: > Hello all, > > I'm trying my hands with openvswitch and squid. This is what I want to > achieve. > > The client tries to connect to the server. This packet is handled through > an openvswitch and it's sent to a machine running squid for proxying.

Re: [squid-users] Squid Upgrade from 3.4.12 to 3.5.3 on FreeBSD 10.1 broke Exchange RPC reverse proxy

2015-04-23 Thread Daniel K. Lima
At jun, Firefox will drop entirely it support for sslv3. On Thu, Apr 23, 2015 at 11:11 PM Amos Jeffries wrote: > On 24/04/2015 7:11 a.m., dweimer wrote: > > On 04/23/2015 9:24 am, dweimer wrote: > >> I upgraded our Reverse proxy from 3.4.12 to 3.5.3 via the FreeBSD > >> ports last night. It has b

[squid-users] Bring refresh_pattern down to ~10sec?

2015-04-23 Thread Kristopher Linquist
Hi, I’m using squid to throttle outgoing API calls to various services. I’ve got Squid working with ssl_bump and currently caching any request more often than 15 minutes with this line: refresh_pattern . 15 20% 4320 override-expire ignore-reload I’m interested in

[squid-users] bandwidth limiting

2015-04-23 Thread Alex Samad
Hi is there any way to limit the bandwidth squid uses to pull stuff from the internet ? Can it slow down request, delay acks or ?? A ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] Using Squid as a Transparent Proxy

2015-04-23 Thread Srinath Krishna
Hello all, I'm trying my hands with openvswitch and squid. This is what I want to achieve. The client tries to connect to the server. This packet is handled through an openvswitch and it's sent to a machine running squid for proxying. The machine running squid sees the packet with client to serve

Re: [squid-users] WARNING: Tos value ... adjusted

2015-04-23 Thread Amos Jeffries
On 24/04/2015 6:26 a.m., Nick Rogers wrote: > On Wed, Apr 22, 2015 at 10:35 PM, Amos Jeffries > wrote: > >> On 23/04/2015 9:14 a.m., Nick Rogers wrote: >>> After upgrading from 3.4.x to 3.5.x, I've noticed a new error message >> with >>> my squid configuration. Apparently squid 3.5 no longer allo

Re: [squid-users] Squid Upgrade from 3.4.12 to 3.5.3 on FreeBSD 10.1 broke Exchange RPC reverse proxy

2015-04-23 Thread Amos Jeffries
On 24/04/2015 7:11 a.m., dweimer wrote: > On 04/23/2015 9:24 am, dweimer wrote: >> I upgraded our Reverse proxy from 3.4.12 to 3.5.3 via the FreeBSD >> ports last night. It has broken our Outlook RPC over HTTPS. OWA and >> Phones are still connecting with Active Sync, its just the RPC for >> Outloo

Re: [squid-users] access_log none acl

2015-04-23 Thread Amos Jeffries
On 24/04/2015 6:10 a.m., Yuri Voinov wrote: > > http://www.squid-cache.org/Doc/config/access_log/ > > 23.04.15 23:25, smaku пишет: >> Hi all, > >> I dont want to log my traffic to squid in access_log. >> That's why I add two lines to default config. >> but when I vi or tail access.log I can see

Re: [squid-users] HTTPS Filtering and SSL-Bump

2015-04-23 Thread Marcus Kool
On 04/23/2015 05:52 PM, Jonathan Chretien wrote: Hi all. I'm trying to implement the filtering of https content for a particular url. The only thing that I'm trying to do it's to unlock corporate video on the Youtube website. I do not want to unlock everything on Youtube but only our corpor

[squid-users] HTTPS Filtering and SSL-Bump

2015-04-23 Thread Jonathan Chretien
Hi all. I'm trying to implement the filtering of https content for a particular url. The only thing that I'm trying to do it's to unlock corporate video on the Youtube website. I do not want to unlock everything on Youtube but only our corporate stuff. The url looks like this: https://www.yout

Re: [squid-users] Squid Upgrade from 3.4.12 to 3.5.3 on FreeBSD 10.1 broke Exchange RPC reverse proxy

2015-04-23 Thread dweimer
On 04/23/2015 9:24 am, dweimer wrote: I upgraded our Reverse proxy from 3.4.12 to 3.5.3 via the FreeBSD ports last night. It has broken our Outlook RPC over HTTPS. OWA and Phones are still connecting with Active Sync, its just the RPC for Outlook anywhere that is broken. Did anyone else have any

Re: [squid-users] WARNING: Tos value ... adjusted

2015-04-23 Thread Nick Rogers
On Wed, Apr 22, 2015 at 10:35 PM, Amos Jeffries wrote: > On 23/04/2015 9:14 a.m., Nick Rogers wrote: > > After upgrading from 3.4.x to 3.5.x, I've noticed a new error message > with > > my squid configuration. Apparently squid 3.5 no longer allows setting the > > two lower-most ECN bits of the To

Re: [squid-users] access_log none acl

2015-04-23 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 http://www.squid-cache.org/Doc/config/access_log/ 23.04.15 23:25, smaku пишет: > Hi all, > > I dont want to log my traffic to squid in access_log. > That's why I add two lines to default config. > but when I vi or tail access.log I can see my requ

[squid-users] access_log none acl

2015-04-23 Thread smaku
Hi all, I dont want to log my traffic to squid in access_log. That's why I add two lines to default config. but when I vi or tail access.log I can see my requests: 1429810062.286142 10.31.6.5 TCP_MISS/302 807 GET http://www.google.pl/ - HIER_DIRECT/173.194.32.207 text/html squid.conf: #

[squid-users] Squid Upgrade from 3.4.12 to 3.5.3 on FreeBSD 10.1 broke Exchange RPC reverse proxy

2015-04-23 Thread dweimer
I upgraded our Reverse proxy from 3.4.12 to 3.5.3 via the FreeBSD ports last night. It has broken our Outlook RPC over HTTPS. OWA and Phones are still connecting with Active Sync, its just the RPC for Outlook anywhere that is broken. Did anyone else have any issues when upgrading from 3.4 bran

Re: [squid-users] ssl_bump peek in squid-3.5.3

2015-04-23 Thread James Lay
On Thu, 2015-04-23 at 17:18 +0930, Michael Hendrie wrote: > > > > On 23 Apr 2015, at 4:28 pm, Michael Hendrie > > wrote: > > > > > > > > > > > > > On 23 Apr 2015, at 4:21 pm, Amos Jeffries > > > wrote: > > > > > > On 23/04/2015 6:29 p.m., Michael Hendrie wrote: > > > > > > > Hi All > >

Re: [squid-users] [squid ] externalAclLookup: 'wbinfo_group_helper' queue overload.

2015-04-23 Thread Jagannath Naidu
Hi Amos, regrets, I am late. On 21 April 2015 at 09:15, Amos Jeffries wrote: > On 20/04/2015 7:31 p.m., Jagannath Naidu wrote: > > Hi, > > > > I am having this issue very frequently. Please help on this. > > > > I get these errors randomly, mostly when usage is at very peak. (800 > users) > > >

[squid-users] GSSAPI problem when try create keytab using msktutil

2015-04-23 Thread kukuh amukti
Dear All, i've building squid in W2K12 and there is no problem but when i try running in W2K3, i get problem when try create keytab with msktutil command to win server 2003. and when i run msktutil : msktutil -c -b "OU=WSUS - Server,OU=Astragraphia-ITS" -s HTTP/proxyagit01.ag-it.com -k /etc/squid3

Re: [squid-users] ERR_ONLY_IF_CACHED_MISS and cache digests problem

2015-04-23 Thread Victor Sudakov
Amos Jeffries wrote: [dd] > > I dont think anything is wrong wth either. Its more a collision in how > the features work vs the protocols. > > Cache Digests (CD) are exchanged periodically and updated approx hourly. > Also they are based on just the URL. So there is always a gap where they > ma

Re: [squid-users] ssl_bump peek in squid-3.5.3

2015-04-23 Thread Michael Hendrie
> On 23 Apr 2015, at 4:28 pm, Michael Hendrie wrote: > > >> On 23 Apr 2015, at 4:21 pm, Amos Jeffries wrote: >> >> On 23/04/2015 6:29 p.m., Michael Hendrie wrote: >>> Hi All >>> >>> I’ve been running squid-3.4.x in tproxy mode with ssl_bump >>> server-first for some time and has been working