Re: [squid-users] Squid Proxy - Block Access Why ?

2023-07-24 Thread Morad, Marc
Hello Alex, thanks for your answer ! We did some more testing and apparently did some things wrong while testing. We now have our solution we need. Kind regards, Marc -Ursprüngliche Nachricht- Von: squid-users Im Auftrag von Alex Rousskov Gesendet: Freitag, 21. Juli 2023 16:21 An

[squid-users] Squid Proxy - Block Access Why ?

2023-07-21 Thread Morad, Marc
ernal Subnet (192.10.16.0/22). This request is getting blocked, which is a behaviour we want to have. Why is it like that ? I read through all my configuration settings and looked what they do but cannot find a definite answer to that. Kind regards,

Re: [squid-users] ephemeral port selection

2019-05-08 Thread Marc
> Yes, it is a valid feature request, and I have seen similar requests in > the past. The default ephemeral port management on Linux (and probably > other OSes) does not satisfy the needs of some busy proxies. Moreover, > we have implemented an explicit source port manager algorithm in Web > Polygr

[squid-users] ephemeral port selection

2019-05-07 Thread Marc
Dear all, We're considering running squid for thousands of users. Squid will use a single parent proxy IP address. A lot of connections will go from the Child squid to the Parent proxy. Often, the Parent proxy initiates closing the TCP connecting by sending the first FIN. This results the connecti

[squid-users] squid hanging in 100% steal

2019-01-24 Thread Marc
Hi, For some reason my squid sometimes hangs (after weeks of running smoothly) in 100% steal, until I kill the proces and restart it, after which the proces will again run stable for weeks. It's running on a AWS EC2 instance, squid version: squid-3.5.20-10.34.amzn1.x86_64 , see below for some deb

[squid-users] sending proxy protocol

2017-06-29 Thread Marc Boschma
in of the request. I’ve been able to find that SQUID can accept the proxy protocol from the ELB… I’m curious as to whether or not the proxy protocol and TLV (NETNS or another) can be set? Regards, Marc [1] https://www.haproxy.org/download/1.8/doc/proxy-pro

[squid-users] Automatic redirect to https

2017-05-08 Thread Marc Werner
x27;t deny the request at port 80 but I had access to my webserver via http! Can someone please tell me what's wrong with my ACL? I don't get it. Thank you very much! King regards Marc Werner ___ squid-users mailing list squid-users@lists.squi

Re: [squid-users] squid.conf for soekirs net6501-70

2016-11-18 Thread Marc Sontowski
for your understanding — Marc Sontowski > Am 17.11.2016 um 22:37 schrieb Eliezer Croitoru : > > Hey Marc, > > It depends on how much of each you have on the machine. > Also what other software would run on it. > I would start with cache_mem only to see how the machine handl

[squid-users] squid.conf for soekirs net6501-70

2016-11-17 Thread Marc Sontowski
Hi, What is your suggestion regarding the squid config for a soekris net6501-70? Specially cache_men & cache_dir ? Thanks in advance! -- Marc Sontowski ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache

Re: [squid-users] FW: squid tproxy ssl-bump and Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-10-10 Thread Marc
On Mon, Oct 10, 2016 at 11:41 AM, Eliezer Croitoru wrote: > Thanks for updating! > > May I ask what version of Linux are you using squid ontop? > I have released couple RPMs and am working on releasing a drop-in tar.xz for > debian based systems. Yeah sure, I'm using Fedora Core 24. - Installed

Re: [squid-users] FW: squid tproxy ssl-bump and Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-10-09 Thread Marc
Hi Vieri, Squid 4 fixes it, in my case. Same config, same system. Regards, Marc On Thu, Oct 6, 2016 at 11:00 PM, Marc wrote: > Hi Viery, > > Sorry, copy/paste error, my bad. Please try: > > openssl s_client -quiet -connect www.google.com:443 -tls1 -cipher > RC4-MD5:RC4-SH

Re: [squid-users] FW: squid tproxy ssl-bump and Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-10-06 Thread Marc
#x27;t have to be 12345, some regular ones do the trick as well. But openssl doesn't always include the existing ones correctly, so I used the dummy. Please let me know. If adding a random extension fixes the error with you too, well.. It could be a step in the right direction toward

Re: [squid-users] FW: squid tproxy ssl-bump and Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

2016-10-05 Thread Marc
XP1024-DHE-DSS-DES-CBC-SHA -serverinfo 12345 < <(echo -e "GET / HTTP/1.1\nHost: https://www.google.com\n\n";) Succes! Don't want to pull the bug card too quick, but well.. Marc ___ squid-users mailing list squid-users@lists.squid-cache.

Re: [squid-users] handshake problems with stare and bump

2016-10-05 Thread Marc
=gnu --enable-plugin --enable-initfini-array --disable-libgcj --with-isl --enable-libmpx --enable-gnu-indirect-function --with-tune=generic --with-arch_32=i686 --build=x86_64-redhat-linux Thread model: posix gcc version 6.2.1 20160916 (Red Hat 6.2.1-2) (GCC) ### Regards, Marc ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

[squid-users] handshake problems with stare and bump

2016-10-03 Thread Marc
orts http_accessallow localnet http_accessallow localhost http_accessdeny all forwarded_for delete cache deny all always_direct allow all ssl_bump stare all ssl_bump bump all # Thanks, Marc ___ squid-users mailing list squid-users@lists.squid-cache.org http://lists.squid-cache.org/listinfo/squid-users

Re: [squid-users] Squid Log

2016-03-29 Thread Marc Mapplebeck
I'll give that regex a try, funny though, that's just built on the code from lightparser.pl, must be a problem with the stock code as well, the original 4 entries that were shipped with it are exactly like the one I posted. Thanks, - Marc -_-_-_-_-_-_-_-_-_-_-_- Marc A. Mapplebeck,

[squid-users] Squid Log

2016-03-28 Thread Marc Mapplebeck
? - Marc -_-_-_-_-_-_-_-_-_-_-_- Marc A. Mapplebeck, MCP/MCDST/MCTS/MCSE/MCDBA/MOS/A+/N+/CNA/CCNA/VCP6-DCV ProCom Data T: 800-408-3313 x242 F: 709-256-3031 E: marc.mappleb...@townsuite.com ___ squid-users mailing list squid-users@lists.squid-cache.org http

Re: [squid-users] assertion failed: client_side.h:364: "sslServerBump == srvBump"

2015-04-20 Thread Marc Micalizzi
I'm encountering this same issue in Squid-3.5.3 > Changed to: > > inline void setServerBump(Ssl::ServerBump *srvBump) { > if (!sslServerBump) > sslServerBump = srvBump; > else > assert(sslServerBump = srvBump); Just FYI, from a glance this would lea