[squid-users] change packet flow to have transparent squid proxy

2018-09-14 Thread morteza omidian
Hi I am in a dire need about using squid in my Linux iptables firewall as a transparent proxy. In my linux iptables firewall i want to do iptables rules and controls in forward chain and after that do http filtering with squid, because of that i need to change netfilter packet flow and send pack

Re: [squid-users] Squid Cache Server

2018-09-14 Thread Mujtaba Hassan Madani
Hi Amos, you did not get back to me about my below concern Regards Mujtaba H, From: Mujtaba Hassan Madani Sent: Thursday, September 13, 2018 5:36:48 PM To: Amos Jeffries; squid-users@lists.squid-cache.org Subject: Re: [squid-users] Squid Cache Server Hi

Re: [squid-users] Squid https_port

2018-09-14 Thread Amos Jeffries
On 15/09/18 5:49 AM, John Refwe wrote: > Hi, >   > I have a couple of questions about the squid https_port. >   > 1) Does it only exist for transparent connections? I know if I want to > have a transparent proxy that can accept requests TLS requests, I need > to have the port be a https_port rather

Re: [squid-users] Squid https_port

2018-09-14 Thread Alex Rousskov
On 09/14/2018 12:11 PM, John Refwe wrote:   > I have a couple of questions about the squid https_port. >   > 1) Does it only exist for transparent connections? No, it does not. It also supports encrypted connections between the client and Squid. In that scenario, Squid can be called an HTTPS prox

[squid-users] Problem with kerb/ntlm authentication

2018-09-14 Thread Yanier Salazar Sanchez
Sorry for my bad english. This is the scenario I have ubuntu 18.04.01 (with las update) with squid 4.2-2, samba and winbind 4.7.6, AD on Windows Server 2012 R2/2016 with the las update, Client with windows 10 1709 with the las update, firefox 60.2.0esr, google chrome 61.0.3163.79, firefox

[squid-users] Squid https_port

2018-09-14 Thread John Refwe
Hi (sorry resending this because the original sent as an html email),   I have a couple of questions about the squid https_port.   1) Does it only exist for transparent connections? I know if I want to have a transparent proxy that can accept requests TLS requests, I need to have the port be a ht

[squid-users] Problem with kerb/ntlm authentication

2018-09-14 Thread Yanier Salazar Sanchez
Sorry for my bad english. This is the scenario I have ubuntu 18.04.01 (with las update) with squid 4.2-2, samba and winbind 4.7.6, AD on Windows Server 2012 R2/2016 with the las update, Client with windows 10 1709 with the las update, firefox 60.2.0esr, google chrome 61.0.3163.79, firefox

[squid-users] Squid https_port

2018-09-14 Thread John Refwe
Hi,   I have a couple of questions about the squid https_port.   1) Does it only exist for transparent connections? I know if I want to have a transparent proxy that can accept requests TLS requests, I need to have the port be a https_port rather than a http_port, but is that what it was create

[squid-users] R: R: R: SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Troiano Alessio
I opened a bug. Anyway I think that anyone in this list can check the problem in his squid in very simple way going to https://sqm.telemetry.microsoft.com and looking the logs (if you have %mailto:squid-users-boun...@lists.squid-cache.org] Per conto di Antony Stone Inviato: venerdì 14 settembre

Re: [squid-users] R: R: SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Antony Stone
On Friday 14 September 2018 at 18:52:46, Troiano Alessio wrote: > I don't understand what I need to do... I already did my tests and see the > problem. Yes, but to file a bug we need to know whether it's still in the current code (it may already have been fixed). > But I see that last 3.5 squid

[squid-users] R: R: SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Troiano Alessio
I don't understand what I need to do... I already did my tests and see the problem. But I see that last 3.5 squid version is 3.5.28 so I can't reproduce the issue in that version without upgrade squid. Anyway can you provide to a me a guide to report a bugzilla? Il presente messaggio e-mail e o

Re: [squid-users] R: SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Alex Rousskov
On 09/14/2018 10:06 AM, Troiano Alessio wrote: > Ok, so reverting the question: can you reproduce with the latest version the > same error? Unfortunately, I do not have the free time required to do this testing right now. Please note that you do not need to upgrade your existing Squid installatio

[squid-users] R: SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Troiano Alessio
Ok, so reverting the question: can you reproduce with the latest version the same error? I cannot update squid, but you can test the link provided https://sqm.telemetry.microsoft.com to check if your squid fill the server IP field or not. Il presente messaggio e-mail e ogni suo allegato devon

Re: [squid-users] SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Alex Rousskov
On 09/14/2018 04:33 AM, Troiano Alessio wrote: > In HTTPS connections when the destination server does not answer > (maybe blocked by our firewall because it is malicious) the > destination ip is not logged. If Squid tried to contact the server, then you are right -- there is a Squid bug here. If

Re: [squid-users] About SSL peek-n-splice/bump configurations

2018-09-14 Thread Alex Rousskov
On 09/13/2018 06:13 PM, Julian Perconti wrote: >ssl_bump stare noBumpSites # This is the first line of SslBumps ruleset. > So, when squid reaches this first rule and line (there is no explicit > step) ...does Squid make a "bucle of steps" only along the first > line and go to next line only

[squid-users] SQUID does not insert server ip and port in logs for CONNECT method when the connection fails (error 503)

2018-09-14 Thread Troiano Alessio
Hello, I'm seeing the problem as from subject. I'm interested in log fields %http://sqm.telemetry.microsoft.com and https://sqm.telemetry.microsoft.com . The site is not reachable. Squid.conf: logformat custom_squid %%SQUID-4: %>a %>p [%tl] "%rm %ru HTTP/%rv" %h" "%{User-Agent}>h" %Ss:%Sh %http:/