Re: [squid-users] destination ip to splice

2017-05-15 Thread Alex Rousskov
corresponding debugging log snippet. Alex. > -Original Message- > From: Alex Rousskov [mailto:rouss...@measurement-factory.com] > Sent: Tuesday, May 16, 2017 3:31 AM > To: Eliezer Croitoru ; squid-users@lists.squid-cache.org > Subject: Re: [squid-users] destination ip to

Re: [squid-users] destination ip to splice

2017-05-15 Thread Eliezer Croitoru
quid-users@lists.squid-cache.org Subject: Re: [squid-users] destination ip to splice On 05/15/2017 06:11 PM, Eliezer Croitoru wrote: > I want to [match] all localnet(10.0.0.0/8, 192.168.0.0/16...) How about something like this, adapted from the existing localnet ACL definition in squid.conf.documen

Re: [squid-users] destination ip to splice

2017-05-15 Thread Alex Rousskov
On 05/15/2017 06:11 PM, Eliezer Croitoru wrote: > I want to [match] all localnet(10.0.0.0/8, 192.168.0.0/16...) How about something like this, adapted from the existing localnet ACL definition in squid.conf.documented? > acl to_localnet dst 0.0.0.1-0.255.255.255 # RFC 1122 "this" network (LAN

[squid-users] destination ip to splice

2017-05-15 Thread Eliezer Croitoru
I have a scenario which I want to disable ssl-bump for specific hosts ip network masks. In this scenario I want to allow all localnet(10.0.0.0/8, 192.168.0.0/16...) https traffic to be spliced. I tried to understand from the acl docs if there is such acl out there but couldn't understand if it exis