Re: [squid-users] 4.0.21 Ssl bump access denied

2017-11-07 Thread Amos Jeffries
On 08/11/17 04:52, snable snable wrote: Hello i forward from.my openwrt router the traffic for 443 and 80 to my squid box to port 3129 and 3128 What do you mean by "forward" ? Any dst-IP:port NAT operation *MUST* only happen on the Squid device itself or _later_ down the traffic path. Tra

Re: [squid-users] ALPN, HTTP/2 and sslbump

2017-11-07 Thread Amos Jeffries
On 08/11/17 17:15, senor wrote: I am surprised that I didn't find this question asked and answered recently. Maybe this issue is newer than I realize. I understand that support of HTTPS/2 is in development but I'd like to better understand what is and is not currently supported. I discovered the

Re: [squid-users] Non intrusive sslbump for whitelisting (asked many times but..)

2017-11-07 Thread Amos Jeffries
On 08/11/17 12:18, A. Benz wrote: Hi all, ## Intro I read many blogs and emails on this list related to what I'm trying to do, but most go into bumping or do things that are not as simple as I'm trying to achieve. I have an extremely slow line, with very high latency in a remote location.

[squid-users] ALPN, HTTP/2 and sslbump

2017-11-07 Thread senor
I am surprised that I didn't find this question asked and answered recently. Maybe this issue is newer than I realize. I understand that support of HTTPS/2 is in development but I'd like to better understand what is and is not currently supported. I discovered the other day that an intercepted

Re: [squid-users] Non intrusive sslbump for whitelisting (asked many times but..)

2017-11-07 Thread reinerotto
>I tried doing filters with firewall or dns level, but those are not effective.< (dnsmasq + ipset) + iptables should do it. You most likely need (dnsmasq+ipset) to allow traffic to multi-IP sites like google, facebook etc. Will work on openwrt/LEDE, too. As I am using it. -- Sent from: http://

[squid-users] Non intrusive sslbump for whitelisting (asked many times but..)

2017-11-07 Thread A. Benz
Hi all, ## Intro I read many blogs and emails on this list related to what I'm trying to do, but most go into bumping or do things that are not as simple as I'm trying to achieve. I have an extremely slow line, with very high latency in a remote location. About 14 people are sharing this l

Re: [squid-users] Google Chrome reports "Too many redirects" on ssl-dumped connections with LA Times News Website

2017-11-07 Thread Jeffrey Merkey
I have done extensive testing and have been able to recreate this error reliably on both Chrome and Firefox with or without squid loaded or installed.I have determined that it is not a bug in Squid, and it also does not appear to be a bug in the browser but some sort of problem with websites in

Re: [squid-users] squid-users Digest, Vol 39, Issue 10

2017-11-07 Thread Nilesh Gavali
Hi Antony, I found where was the issue, Actually access given to the site was based on LDAP group membership when user try to launch recording from site, the .wax file will be played from local machine IP , which is getting blocked. created ACL to allow specific ip to access the Site and it worke

Re: [squid-users] problem squid squidguard with outlook 2016

2017-11-07 Thread Antony Stone
On Tuesday 07 November 2017 at 14:34:36, rmohammed wrote: > I have a problem with outlook 2016 in my office, > > When i activate squid and squidguard, Is the behaviour the same if you use Squid without Squidguard? > outlook stop to receive and send emails, > > can anyone help me plz? Tell us

Re: [squid-users] Squid and CPU 100%

2017-11-07 Thread Alex Rousskov
On 11/07/2017 10:16 AM, Vieri wrote: > A quick grep at access.log before the issue I reported shows that > there were 1350 lines during a full minute. So I understand that > would mean there were 1350 requests during that minute even though > some of them were denied by squid.conf's policies. So I

Re: [squid-users] Squid and CPU 100%

2017-11-07 Thread Vieri
A quick grep at access.log before the issue I reported shows that there were 1350 lines during a full minute. So I understand that would mean there were 1350 requests during that minute even though some of them were denied by squid.conf's policies. So I should estimate less than 2 * 1350. I woul

Re: [squid-users] ERR_ICAP_FAILURE unless squid reconfigure

2017-11-07 Thread Alex Rousskov
On 11/07/2017 09:28 AM, Vieri wrote: > whenever I restart c-icap, the Squid cache HTTP clients display the > ERR_ICAP_FAILURE page. Yes, when an essential ICAP service is unavailable, Squid will try icap_service_failure_limit times and then will declare the service as down, displaying the corres

Re: [squid-users] ERR_ICAP_FAILURE unless squid reconfigure

2017-11-07 Thread Enrico Heine
Set bypass to 1 Am 7. November 2017 17:28:56 MEZ schrieb Vieri : >Hi, > >I noticed that whenever I restart c-icap >(http://c-icap.sourceforge.net/), the Squid cache HTTP clients display >the ERR_ICAP_FAILURE page. >If I send the reconfigure action to the squid process then this "error" >goes away.

[squid-users] ERR_ICAP_FAILURE unless squid reconfigure

2017-11-07 Thread Vieri
Hi, I noticed that whenever I restart c-icap (http://c-icap.sourceforge.net/), the Squid cache HTTP clients display the ERR_ICAP_FAILURE page. If I send the reconfigure action to the squid process then this "error" goes away. How can I avoid having to "recofnigure" squid when c-icap is restarte

[squid-users] 4.0.21 Ssl bump access denied

2017-11-07 Thread snable snable
Hello i forward from.my openwrt router the traffic for 443 and 80 to my squid box to port 3129 and 3128 certificates gets created from squid but i always get on every single page an access denied error from the proxy. ssl_bump bump all is configured any idea? thanka _

Re: [squid-users] Squid and CPU 100%

2017-11-07 Thread Alex Rousskov
On 11/07/2017 04:42 AM, Vieri wrote: > So I'm worried that 32768 may not be enough. > Is this weird, or should I really increase this value? Think about the underlying physics of what you are observing. It may help reduce guessing and guide you towards a solution: You can estimate the reasonable

[squid-users] problem squid squidguard with outlook 2016

2017-11-07 Thread rmohammed
I have a problem with outlook 2016 in my office, When i activate squid and squidguard, outlook stop to receive and send emails, can anyone help me plz? thanks -- Sent from: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-Users-f1019091.html _

[squid-users] Squid and CPU 100%

2017-11-07 Thread Vieri
Sorry to bring this back up, but every now and then (few days) I need to restart squid because its CPU usage goes up to 100% for a long time (irresponsive). Right before restarting Squid: # free [11/07/17 11:18:52] total used free shared buff/cache available Mem: 32865056 14811320 1374212 15702