[squid-users] squid reverse proxy infront of exchange 2010

2015-12-01 Thread Alex Samad
Hi recently upgraded to squid-3.5.11-1.el6.x86_64 from the centos 6.7 squid 3.1 I am now having problems with people who use active sync via this connection . seems like emails with attachments aren't making it through . cache_peer 10.32.69.11 parent 443 0 proxy-only no-query no-digest origins

[squid-users] mail upload problem

2015-12-01 Thread vivek singh
we are facing problem while users trying to upload some attachments it fails using linux proxy, while at the same time if they switch to windows proxy attachment uploaded succesfully. I am using squid 3.5 version onboth linux and windows proxy servers, any help would be appreciation.

[squid-users] setting up cache peering

2015-12-01 Thread Alex Samad
/business/markets-live/markets-live-investors-take-stock-20151201-gld1lu.html -O /dev/null and setting http_proxy to either alc or gsdmz1 I would get a 504 error. wget -d http://www.smh.com.au/business/markets-live/markets-live-investors-take-stock-20151201-gld1lu.html -O /dev/null Setting --output

[squid-users] TCP_SWAPFAIL_MISS

2015-12-01 Thread joe
TCP_MEM_HIT/200 469 GET http://engine.adzerk.net/i.gif?e=eyJhdiI6NDE0LCJhdCI6NCwiYnQiOjAsImNtIjoxODc5NTQsImNoIjoxMTc4LCJjayI6e30sImNyIjo2NjQ0MjQsImRpIjoiZTc4OWZlNmQ4ZjUwNGZhOGI0ZWM4NDMxY2MyZWViOTkiLCJkbSI6MSwiZmMiOjY4NjI4MywiZmwiOjQxNTQ4NSwiaXAiOiJ1bmtub3duIiwibnciOjIyLCJwYyI6MCwiZWMiOjAsInBy

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 :) May be, may be not. 01.12.15 22:51, Eliezer Croitoru пишет: > Hey Yuri, > > Even if mikrotik is SOHO-class in some places of the world it is still a nice product which in many cases is being used as a edge on non SOHO networks. > For amazon it

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Eliezer Croitoru
Hey Yuri, Even if mikrotik is SOHO-class in some places of the world it is still a nice product which in many cases is being used as a edge on non SOHO networks. For amazon it won't do the trick but we are talking about 1Gbps+ WAN connections which are not SOHO. Eliezer On 01/12/2015 18:41,

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Eliezer Croitoru
On 01/12/2015 18:23, joe wrote: put your server behind mikrotik mikrotik has advance firewall and use tarpit instead of drop tarpit it freeze the attacker then drop his connection so making his attack slow dig in mikrotik forum you find lots of working sample depend on Ddos attack I will look

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Yuri Voinov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 mikrotik is SOHO-class network equipment. AFAIK we are not talking about SOHO. 01.12.15 22:23, joe пишет: > put your server behind mikrotik > mikrotik has advance firewall and use tarpit instead of drop > tarpit it freeze the attacker then drop hi

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread joe
put your server behind mikrotik mikrotik has advance firewall and use tarpit instead of drop tarpit it freeze the attacker then drop his connection so making his attack slow dig in mikrotik forum you find lots of working sample depend on Ddos attack -- View this message in context: http://sq

Re: [squid-users] Question about c-icap and setting X-Next-Services header to empty string

2015-12-01 Thread Alex Rousskov
On 12/01/2015 08:58 AM, Giray Simsek wrote: > I am trying to update the adaptation plan dynamically in the first > service (service_a_resp) Basically, if a certain condition is met, > then I don't want the second service (service_b_resp) to be called by > Squid. > icap_enable on > icap_send_clie

Re: [squid-users] 2 way SSL on a non standard SSL Port

2015-12-01 Thread Bart Spedden
Thank you so much Amos! You figured it out! I was able to telnet to those ports from my localhost, but not from the server where squid is installed. I'm working to get those ports opened now. Thanks again! On Mon, Nov 30, 2015 at 7:08 PM, Amos Jeffries wrote: > On 1/12/2015 1:01 p.m., Bart Spe

[squid-users] Question about c-icap and setting X-Next-Services header to empty string

2015-12-01 Thread Giray Simsek
Hi, [Sorry for the dupe mail but I forgot to format the previous one as "Plain Text" and it looks bad.] I have 2 icap response modification services. I have integrated them to squid as in the below config.  I am trying to update the adaptation plan dynamically in the first service (service_a_

[squid-users] Question about c-icap and setting X-Next-Services header to empty string

2015-12-01 Thread Giray Simsek
Hi, I have 2 icap response modification services. I have integrated them to squid as in the below config. I am trying to update the adaptation plan dynamically in the first service (service_a_resp)Basically, if a certain condition is met, then I don't want the second service (service_b_resp) to

Re: [squid-users] missing icap respmod request when the web object is found in the cache?

2015-12-01 Thread Giray Simsek
Thanks Alex, this was helpful. > Subject: Re: [squid-users] missing icap respmod request when the web object > is found in the cache? > To: squid-users@lists.squid-cache.org > From: rouss...@measurement-factory.com > CC: giray_sim...@hotmail.com > Date: Mo

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Eliezer Croitoru
On 01/12/2015 12:57, Amos Jeffries wrote: On 1/12/2015 8:19 a.m., Eliezer Croitoru wrote: I was wondering if someone have a nice idea on how to use squid to protect against DOS\DDOS http\https attacks. The basic way I was thinking is rate limiting by counting the client IP page HITs but I am un

Re: [squid-users] squid 3.4.8 ssl-bump resolve ip in access.log

2015-12-01 Thread LANGLOIS Nicolas
Thanks Amos for the quick reply, I 'm making lot of mistake around ssl with squid, i 'm following your advice and try to setup with with last squid 3.5 version using tproxy will let you know . Have a good day Nicolas -Message d'origine- De : squid-users [mailto:squid-users-boun..

Re: [squid-users] deny_info / url_rewrite_program

2015-12-01 Thread Jens Kallup
Hello, bellow, a Perl script that works for me - it redirect the URL in browser; when i type in "web.de" the result is "www.freenet.de". But the browser don't connect to www.freenet.de, he shows me a Error: redirect-error - this problem can be, when Cookies deactivated or denied. (iceweasel - fir

Re: [squid-users] squid 3.4.8 ssl-bump resolve ip in access.log

2015-12-01 Thread Amos Jeffries
On 2/12/2015 12:40 a.m., LANGLOIS Nicolas wrote: > Hi, i'm trying to set up squid 3.4.8 on debian , i want a full transparent > proxy, no conf on client side . That is not what "fully transparent" means. The best form of transparent proxy is when clients are auto-configured with explicit-proxy

[squid-users] squid 3.4.8 ssl-bump resolve ip in access.log

2015-12-01 Thread LANGLOIS Nicolas
Hi, i'm trying to set up squid 3.4.8 on debian , i want a full transparent proxy, no conf on client side . it's working actually but i 'm ask to report websites access but for https actually i just get this kind of line in my access.log : < TCP_MISS/200 288 CONNECT 64.233.184.106:443 - ORIGINAL

Re: [squid-users] Looking for ideas on how to use squid in order to protect against a DOS\DDOS.

2015-12-01 Thread Amos Jeffries
On 1/12/2015 8:19 a.m., Eliezer Croitoru wrote: > I was wondering if someone have a nice idea on how to use squid to > protect against DOS\DDOS http\https attacks. > > The basic way I was thinking is rate limiting by counting the client IP > page HITs but I am unsure about it since it can actually

Re: [squid-users] 32bit (i386) squid 3.5 cache dir size

2015-12-01 Thread Amos Jeffries
On 1/12/2015 8:48 a.m., TarotApprentice wrote: > From the Debian repo. Stretch has 3.5.10 at the moment. Jessie has 3.4.8. > Then it should have large-file support IIRC. Amos ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.

Re: [squid-users] How to use the different Store ID with same url and different proxy port ?

2015-12-01 Thread Amos Jeffries
On 1/12/2015 5:44 p.m., 风声 wrote: > Hi, > > We want to Squid-3 to listen serveral ports (like 3128/3129/3120/...), but > we want reply different cached objects for different ports with same > request (same url), Don't. URL do not work that way. RFC 3986 section 1.1.3: " The term "Uniform Resourc

Re: [squid-users] Time-Based Download Restrictions

2015-12-01 Thread Amos Jeffries
On 1/12/2015 3:56 a.m., Edmonds Namasenda wrote: > Greetings. > > I want to deny access to certain downloads (in str-med.txt) during "WorkHrs" > This is failing miserably as this is not achieved. > > Please look through my files (squid.conf and str-med.txt) below for > pointers to rectify this. T