[squid-users] What happens when duplicate external_acl_type are mentioned

2018-11-30 Thread Amish
Hello, PREFACE: - I have a squid.conf file which includes 2 files. include pre.conf include main.conf main.conf will never be changed and contains most of the config and an external acl helper with roughly following directives: external_acl_type ipuser queue-size=40 ttl=120 children

[squid-users] Squid SSL-bump error Change Cipher Spec

2018-11-30 Thread John Refwe
Hi,   I have an error when going to a site that is set to be ssl-bumped in squid.   I have modified my squid config so that I have not specified any ciphers (I read in another forum post this would be the way to make it closest to the standard openssl).   The error that I see in squid cache l

Re: [squid-users] Question on Many Clients to Many Proxy Lists

2018-11-30 Thread Wire Cutter
Yes both were before the cache, but I wasn't calling the correct group in the ACL, which caused the issue. Thanks for you help. Now to figure out why it's slow On Fri, Nov 30, 2018 at 2:17 PM Alex Rousskov < rouss...@measurement-factory.com> wrote: > On 11/30/18 11:51 AM, Wire Cutter wrote: >

Re: [squid-users] Question on Many Clients to Many Proxy Lists

2018-11-30 Thread Alex Rousskov
On 11/30/18 11:51 AM, Wire Cutter wrote: > cache_peer_access peerA1 allow port_8080 > > cache_peer 192.168.1.2 parent 8800 0 round-robin no-query name=peerA1 > Then this is the error I get when I start the service  > > Bungled /etc/squid/squid.conf line 3148: cache_peer_access peerA1 allow >

Re: [squid-users] Question on Many Clients to Many Proxy Lists

2018-11-30 Thread Wire Cutter
So thats exactly what I did. #Rules for Peer group - list 1 cache_peer_access peerA1 allow port_8080 cache_peer_access peerA2 allow port_8080 cache_peer_access peerA3 allow port_8080 cache_peer_access peerA4 allow port_8080 #cache_peer cache_peer 192.168.1.2 pa

Re: [squid-users] how to go from connect/tunnel in squid4 ->GET

2018-11-30 Thread Alex Rousskov
On 11/30/18 10:39 AM, L A Walsh wrote: > On 11/29/2018 12:41 PM, Alex Rousskov wrote: >> You have not configured any ssl_bump rules. Thus, you are effectively >> not using any SslBump features. All HTTPS traffic is simply tunneled >> through without decryption/analysis. > Where were the ssl_bump o

Re: [squid-users] Fwd: ERROR: http_port or ACL larger than 65536 (short type)

2018-11-30 Thread Antony Stone
On Friday 30 November 2018 at 19:07:58, kalice caprice wrote: > Hello, > > Inside my squid.conf I'm setting up ACL like this: > > http_port 0.0.0.0:20740 name=20740 So, you're using the name to represent the port number... > acl ip10740 myportname 20740 > > and then > > tcp_outgoing_address

[squid-users] Fwd: ERROR: http_port or ACL larger than 65536 (short type)

2018-11-30 Thread kalice caprice
Hello, Inside my squid.conf I'm setting up ACL like this: http_port 0.0.0.0:20740 name=20740 acl ip10740 myportname 20740 and then tcp_outgoing_address x.x.x.x ip10740 I've got over 65536 (about 80k) ACL inside my squid.conf and squid throws this error: ERROR: The value '65536' is larger than

Re: [squid-users] how to go from connect/tunnel in squid4 ->GET

2018-11-30 Thread L A Walsh
On 11/29/2018 12:41 PM, Alex Rousskov wrote: You have not configured any ssl_bump rules. Thus, you are effectively not using any SslBump features. All HTTPS traffic is simply tunneled through without decryption/analysis. --- OkI didn't do any of that in squid 3.x when I had something

[squid-users] Why does Squid4 do socket(AF_NETLINK, SOCK_RAW, NETLINK_NETFILTER) = -1 EACCES (Permission denied) ?

2018-11-30 Thread Ahmad, Sarfaraz
I think almost every time squid opens a TCP connection, It also tried to open a raw socket of type AF_NETLINK. Syscall pasted below. All that I can make sense of this is that Squid is trying to engage with iptables subsystem somehow ? I have SELinux enforcing and would like to know what Squid is

Re: [squid-users] Caching Vimeo Videos

2018-11-30 Thread eliezer
Hey, There are two types of streams on Vimeo: * Simple mp4 files * HLS Dash streams Example of links to mp4 files: https://03-lvl3-pdl.vimeocdn.com/01/2370/1/36854018/84618512.mp4?expires=1543576693&token=x https://03-lvl3-pdl.vimeocdn.com/01/2370/1/36854018/84618512.mp4?expi

Re: [squid-users] office365 - brand new endpoint management question!!

2018-11-30 Thread Amos Jeffries
On 30/11/18 6:46 am, Jennifer Canterbury wrote: > Did anyone see the changes to office365 IP and URLs management effective > as of 11/27/18?  Microsoft appears to be be going to 3 different CDN > networks (Akamai, MarkMonitor, and ExactTarget) for office365 connectivity. > > I have a few questions

Re: [squid-users] Caching Vimeo Videos

2018-11-30 Thread Antony Stone
On Friday 30 November 2018 at 10:05:49, Raju M K wrote: > Need help on how to cache Vimeo videos under squid proxy. Need info on what you tried already and how you identified it didn't work. Antony. -- Ramdisk is not an installation procedure.

[squid-users] Caching Vimeo Videos

2018-11-30 Thread Raju M K
Need help on how to cache Vimeo videos under squid proxy. -- Regards, M K Raju. ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] fi.se ssl bump error

2018-11-30 Thread Amos Jeffries
On 30/11/18 12:16 pm, John Refwe wrote: > Hi, >   > I'm encountering a ssl bump error when going > to https://www.finansinspektionen.se/ >   > The error is similar in nature > to  > http://squid-web-proxy-cache.1019090.n4.nabble.com/Message-with-SSL-bump-with-a-specific-site-td4686867.html TLS is