Re: [squid-users] How to setup squid as reverse proxy to intercept Office365 traffic

2017-09-05 Thread Antony Stone
On Tuesday 05 September 2017 at 22:19:03, SShukla wrote: > Hi, > > I am trying to setup squid as reverse proxy to intercept office365 > traffic. Why do you want to set up a *reverse* proxy for Office 365 traffic? Are you running Office 365 servers and want some sort of front-end for them? I t

[squid-users] How to setup squid as reverse proxy to intercept Office365 traffic

2017-09-05 Thread SShukla
Hi, I am trying to setup squid as reverse proxy to intercept office365 traffic. The configuration we need to do in squid.conf file, I need help with that. Could anyone provide me sample config file that would help me set this up? or any directions will be much appreciated. Thanks -- Sent

Re: [squid-users] gateway failure

2017-09-05 Thread Eliezer Croitoru
Hey Vieri, You can run a crontab job(s) that will run periodic tests against public dns and http(s) servers. Also try to enable path mtu discovery which might help in some cases. You can also try to use iptables clamp-mss \ set-mss to either set a static or by the path mtu. Take a peek at: http

Re: [squid-users] SSL3_GET_SERVER_CERTIFICATE:certificate verify failed

2017-09-05 Thread Amos Jeffries
On 05/09/17 04:20, erdosain9 wrote: Hi. Im having a lot of this in cache.log... is this normal?? The https is access is working fine... but i have those error. > 2017/09/04 13:10:58 kid1| Error negotiating SSL on FD 467: > error:14090086:SSL routines:SSL3_GET_SERVER_CERTIFICATE:certificate ver

Re: [squid-users] squid cache peer not rotating over round robin !

2017-09-05 Thread Amos Jeffries
On 05/09/17 07:17, --Ahmad-- wrote: hello folks I’m trying to rotate squid request over several peers my config are below but they are only stuck with 1 peer . acl custNet dstdomain .trustly.com .ing.nl .adyen.com .rabobank.nl .abn.nl .iplocation.net .abnamro.com .abnamro.nl .abnamro.nl cac

Re: [squid-users] gateway failure

2017-09-05 Thread Amos Jeffries
On 05/09/17 21:31, Vieri wrote: Hi, I'm sometimes getting hit by ERR_GATEWAY_FAILURE. I'd like to know what could be causing this issue. When this happens on a production server, I don't have much time to investigate. I usually only have enough time to ssh into the squid server, test internet

Re: [squid-users] RC4-MD5 cipher is always enabled?

2017-09-05 Thread Amos Jeffries
On 05/09/17 20:55, chiasa.men wrote> Thanks, that was easy... but: That does not work: https_port 3128 accel defaultsite=www.example.com cert=/example/cert.pem key=/ example/key.pem cipher=ECDHE-ECDSA-AES256-GCM-SHA384:!RC4:!MD5 openssl s_client -connect localhost:3128 140048907216536:error:14

Re: [squid-users] external ACL queue overload

2017-09-05 Thread Vieri
Thanks for clearing that up. I haven't seen queue overloads since. Hope this keeps up. Vieri ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] gateway failure

2017-09-05 Thread Vieri
Hi, I'm sometimes getting hit by ERR_GATEWAY_FAILURE. I'd like to know what could be causing this issue. When this happens on a production server, I don't have much time to investigate. I usually only have enough time to ssh into the squid server, test internet access via command line, and befor

Re: [squid-users] RC4-MD5 cipher is always enabled?

2017-09-05 Thread chiasa.men
Am Montag, 4. September 2017, 14:07:54 CEST schrieb Amos Jeffries: > On 04/09/17 20:36, chiasa.men wrote: > > "RC4-MD5" seems to be always enabled. Is there a way to prohibit RC4-MD5? > > > > > > > > squid.conf: > > https_port 3128 accel defaultsite=www.example.com cert=/example/cert.pem > > key