Re: [squid-users] [EXTERNAL] Re: Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread Amos Jeffries
On 30/04/20 9:11 am, Anthony Mead wrote: > Hmm, if there were more logs I'd share them! Any reason why I'd only see a > access.log line? > > I promise if I curl https://google.com this is the only line I see: > 1588193897.852 20 10.0.1.180 TCP_TUNNEL_ABORTED/200 5103 CONNECT > 172.217.15.

Re: [squid-users] [EXTERNAL] Re: Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread Anthony Mead
Hmm, if there were more logs I'd share them! Any reason why I'd only see a access.log line? I promise if I curl https://google.com this is the only line I see: 1588193897.852 20 10.0.1.180 TCP_TUNNEL_ABORTED/200 5103 CONNECT 172.217.15.78:443 - ORIGINAL_DST/172.217.15.78 - Or curl https:

Re: [squid-users] Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread Amos Jeffries
On 30/04/20 8:15 am, Anthony Mead wrote: > Thanks! I've re-compiled without the unnecessary flag, and restarted the > service with a new whitelist, unfortunately i'm getting such a varying of > /var/log/squid/access.log messages that I'm not sure what to google anymore. > > I want to deny all a

Re: [squid-users] [EXTERNAL] Re: Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread Anthony Mead
Thanks! I've re-compiled without the unnecessary flag, and restarted the service with a new whitelist, unfortunately i'm getting such a varying of /var/log/squid/access.log messages that I'm not sure what to google anymore. I want to deny all access to external sites except http/https github.co

[squid-users] Help with FTP native proxy squid 3.5

2020-04-29 Thread Dawood Aijaz
Hi, I am able to configure an FTP proxy through HTTP however I need a native FTP. I was told squid supports as of Cv3.5.But I am unable to find any help regarding configuration and any tutorial to help me do this task Can anyone share configuration for setting up native FTP proxy, Regards, Dawood

Re: [squid-users] Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread Amos Jeffries
On 30/04/20 4:10 am, AMead wrote: > 1. Compiled Squid 4.11 on Ubuntu 18 T3 EC2 instance: > > ./configure \ ... > --with-openssl \ > --enable-ssl \ "--enable-ssl" is not a Squid build option. > --enable-ssl-crtd > > > 2. Initialized the ssl database: > > sudo /usr/libexec/squid/se

Re: [squid-users] Gateway Proxy failure - but only with one browser ...

2020-04-29 Thread Alex Rousskov
On 4/29/20 2:16 PM, Walter H. wrote: > It is very probable that the following has the same reason - but I don't > know what's causing it ... While your symptoms are a bit different, you might be suffering from the problem fixed by https://github.com/squid-cache/squid/pull/588 > Handshake with SS

Re: [squid-users] Gateway Proxy failure - but only with one browser ...

2020-04-29 Thread Amos Jeffries
On 30/04/20 6:16 am, Walter H. wrote: > It is very probable that the following has the same reason - but I don't > know what's causing it ... > > the old browser on old OS gives this > > > While trying to retrieve the URL: https://mein.elba.hypo.at/* > > The following error was encountered: >

Re: [squid-users] Gateway Proxy failure - but only with one browser ...

2020-04-29 Thread Walter H.
It is very probable that the following has the same reason - but I don't know what's causing it ... the old browser on old OS gives this While trying to retrieve the URL: https://mein.elba.hypo.at/* The following error was encountered:     * Failed to establish a secure connection to 217.13.

[squid-users] Gateway Proxy failure - but only with one browser ...

2020-04-29 Thread Walter H.
I have two squids, one does SSL bump (3.5latest CentOS 6) the other doesn't SSL bump (3.4latest CentOS 6) everything works, I have a site that uses SSL/TLS, and two different browsers (one in a VM with old windows), when I use the squid without SSL bump, the site works with both browsers, b

[squid-users] Ubuntu 18 with Squid 4.11 SSL_BUMP

2020-04-29 Thread AMead
1. Compiled Squid 4.11 on Ubuntu 18 T3 EC2 instance: ./configure \ --prefix=/usr \ --exec-prefix=/usr \ --bindir=/usr/bin \ --sbindir=/usr/sbin \ --libdir=/usr/lib \ --libexecdir=/usr/libexec/squid \ --includedir=/usr/include \ --mandir=/usr/share/man \ --infodi

Re: [squid-users] Squid - Can't visit (government site and Banking Site) - Please help

2020-04-29 Thread russel0901
Hi again, as per checking using wireshark on my client-pc This are my error messages Client PC - Proxy ServerTCP 54 [TCP Retransmission] 49804 -> [FIN, ACK] Seq=1 Ack=2 Win=1020 Len=0 Client PC - Proxy ServerTCP 55 [TCP Keep-Alive] 49847 -> [ACK] Seq=0 Ack