Re: [squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-23 Thread Amos Jeffries
On 23/04/2016 10:08 p.m., Jason Haar wrote: > On Sun, Apr 17, 2016 at 9:11 PM, Amos Jeffries wrote: > >> Like Jok mentioned Chrome is probably using QUIC protocol or one of the >> other non-HTTPS is uses. >> > > > Other non-HTTPS? Can you expand on that? I'm aware of QUIC (udp/443) and > ensure

Re: [squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-23 Thread Jason Haar
On Sun, Apr 17, 2016 at 9:11 PM, Amos Jeffries wrote: > Like Jok mentioned Chrome is probably using QUIC protocol or one of the > other non-HTTPS is uses. > Other non-HTTPS? Can you expand on that? I'm aware of QUIC (udp/443) and ensure our firewalls block it so as to force it to tcp/443 - but

Re: [squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-17 Thread Amos Jeffries
On 17/04/2016 1:53 p.m., Jok Thuau wrote: > Blocking YouTube (appear to be on your list) is tricky, if the browser is > chrome: > > https://en.m.wikipedia.org/wiki/QUIC > > If you click on the 'green lock' and look at the connection you will see it's > not using https (funnily enough, the ads t

Re: [squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-16 Thread Jok Thuau
Blocking YouTube (appear to be on your list) is tricky, if the browser is chrome: https://en.m.wikipedia.org/wiki/QUIC If you click on the 'green lock' and look at the connection you will see it's not using https (funnily enough, the ads there do!). Look at the wiki for more info on how to blo

[squid-users] Browser circunvents acl's blocking https (intercept mode)

2016-04-16 Thread Sergio Belkin
Hi, I cannot block some sites using squid 3.4.8, this the configuration. On Firefox, blocking works, browser says: `Error code: SSL_ERROR_RX_RECORD_TOO_LONG` But on Chromium Versión 49.0.2623.108, browser is not affected by the blocking acl's, despite access_logs says: 192.168.80.250 - - [