Re: [squid-users] a bit off topic. New user question

2017-05-22 Thread Amos Jeffries
On 23/05/17 11:39, George Diaz wrote: Hi sorry this off-topic question ... I want pre-cache some object from some interest host with wget. My question is : I want: the wget download the object to the /dev/null but I'm not found this switches (GNU Wget 1.5.3) I'm probe this : export htt

Re: [squid-users] External ACL

2017-05-22 Thread Amos Jeffries
On 23/05/17 13:25, avi_h wrote: Hi, I'm currently using the DB authentication (squid_db_auth). This works flawlessly, however I have a need to enable authentication by a list of IPs. What do you mean by that exactly? I tried using a simple ACL, but it's not dynamic so that doesn't answer my

Re: [squid-users] clientside_mark

2017-05-22 Thread Amos Jeffries
On 23/05/17 12:03, Ikari C wrote: On 22/05/17 02:51, Ikari C wrote: Hi, i'm new in maillist and in Squid configuration, I use Squid 3.5 version and i read about clientside_mark configuration, but i have a doubt, wich type of ACL is compatible with this option. I want to create

[squid-users] External ACL

2017-05-22 Thread avi_h
Hi, I'm currently using the DB authentication (squid_db_auth). This works flawlessly, however I have a need to enable authentication by a list of IPs. I tried using a simple ACL, but it's not dynamic so that doesn't answer my need. So I'm trying to create an external ACL. For some reason the exter

Re: [squid-users] clientside_mark

2017-05-22 Thread Ikari C
On 22/05/17 02:51, Ikari C wrote: > Hi, i'm new in maillist and in Squid configuration, I use Squid 3.5 > version and i read about clientside_mark configuration, but i have a doubt, > wich type of ACL is compatible with this option. I want to create a MARK > by dstdomain ACL, and use TC configura

[squid-users] a bit off topic. New user question

2017-05-22 Thread George Diaz
Hi sorry this off-topic question ... I want pre-cache some object from some interest host with wget. My question is : I want: the wget download the object to the /dev/null but I'm not found this switches (GNU Wget 1.5.3) I'm probe this : export http_proxy=http://mycache.com:8080/ wget -r ht

Re: [squid-users] clientside_mark

2017-05-22 Thread Amos Jeffries
On 22/05/17 02:51, Ikari C wrote: Hi, i'm new in maillist and in Squid configuration, I use Squid 3.5 version and i read about clientside_mark configuration, but i have a doubt, wich type of ACL is compatible with this option. I want to create a MARK by dstdomain ACL, and use TC configuration

Re: [squid-users] Problem with Squid3 Authentication

2017-05-22 Thread Amos Jeffries
On 23/05/17 02:15, Marcio Demetrio Bacci wrote: I have migrated of Samba 4.2.1 to Samba 4.6.3 as DC, but now my Squid authentication doesn't work. In samba 4.2.1 is working properly. This is my authentication block: auth_param basic program /usr/lib/squid3/basic_ldap_auth -R -b DC=empresa,D

Re: [squid-users] It is possible to use SSL_bump on my squid server 3.5.23, if my parent cache (cache_peer) does not use ssl_bump (not configured).

2017-05-22 Thread Alex Rousskov
On 05/22/2017 08:14 AM, yuriang wrote: > It is possible to use SSL_bump on my squid server 3.5.23, if my parent > cache (cache_peer) does not use ssl_bump (not configured). I do not think it is possible to use SslBump steps 2+ with cache_peers that expect plain HTTP requests. AFAICT, for SslBump

Re: [squid-users] Documentation for squidclient?

2017-05-22 Thread Amos Jeffries
On 23/05/17 07:11, erdosain9 wrote: Ok, Thanks. We are using a windows server 2012... Can you explain to me how the negotiate authenticator works?? how works? when a user want browser to a pa

Re: [squid-users] Documentation for squidclient?

2017-05-22 Thread erdosain9
Ok, Thanks. We are using a windows server 2012... Can you explain to me how the negotiate authenticator works?? how works? when a user want browser to a page, the squid, use the authenticator for know if can browse?? every time? for every single web pages? Thanks -- View this message in contex

Re: [squid-users] 503 service unavailable on connection refused

2017-05-22 Thread Alex Rousskov
On 05/22/2017 03:02 AM, Dominic Kim wrote: > I have tested with squid 3.3, 3.5, 4. > And the behavior were same. When using Squid v3.5 or v4, please reproduce the problem using a single HTTP transaction while collecting level-7 or higher debugging and then post the corresponding (compressed) cache

Re: [squid-users] Tagged ACLs?

2017-05-22 Thread Alex Rousskov
On 05/22/2017 05:56 AM, Ralf Hildebrandt wrote: > * Alex Rousskov : >> On 05/20/2017 10:07 AM, Ralf Hildebrandt wrote: >>> we want to create statistics on how many >>> clients were "caught" trying to access blocked sites. >>> >>> Currently, we're grepping the log for TCP_DENIED in conjunction with

[squid-users] Problem with Squid3 Authentication

2017-05-22 Thread Marcio Demetrio Bacci
I have migrated of Samba 4.2.1 to Samba 4.6.3 as DC, but now my Squid authentication doesn't work. In samba 4.2.1 is working properly. This is my authentication block: auth_param basic program /usr/lib/squid3/basic_ldap_auth -R -b DC=empresa,DC=com,DC=br -D CN=proxy,CN=Users,DC=empresa,DC=com,D

[squid-users] It is possible to use SSL_bump on my squid server 3.5.23, if my parent cache (cache_peer) does not use ssl_bump (not configured).

2017-05-22 Thread yuriang
It is possible to use SSL_bump on my squid server 3.5.23, if my parent cache (cache_peer) does not use ssl_bump (not configured). # When I try to access an https: // # With this setting: http_port 127.0.0.1:3129 ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/s

Re: [squid-users] 503 service unavailable on connection refused

2017-05-22 Thread Dominic Kim
I have tested with squid 3.3, 3.5, 4. And the behavior were same. Thanks Regards Dongkyoung 2017-05-22 18:01 GMT+09:00 Dominic Kim : > When I connect to a target server via squid, if server does not exist, I > get "No route to host" error. > And if server exist, but port is not opened yet, I get

[squid-users] 503 service unavailable on connection refused

2017-05-22 Thread Dominic Kim
When I connect to a target server via squid, if server does not exist, I get "No route to host" error. And if server exist, but port is not opened yet, I get "Connection refused" error. As per the definition of "connect_retries" option, it should retry when connection attempt failed. (reference: h