Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-11 Thread dweimer
On 2015-12-10 10:29 pm, Alex Samad wrote: Hi I did the change over today. Tested with Window 7 + exchange 2010 and it wouldn't connect whilst there was no tls1 ! interesting IE worked against the web site so .. Did you come across this issues ? On 11 December 2015 at 11:09, dweimer wro

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Alex Samad
Hi I did the change over today. Tested with Window 7 + exchange 2010 and it wouldn't connect whilst there was no tls1 ! interesting IE worked against the web site so .. Did you come across this issues ? On 11 December 2015 at 11:09, dweimer wrote: > On 2015-12-10 4:24 pm, Alex Samad wrot

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread dweimer
On 2015-12-10 4:24 pm, Alex Samad wrote: Hi Answer my own question http://www.squid-cache.org/Versions/v3/3.5/cfgman/http_port.html seems like there is a no-vhost, I presume vhost turns it on On 11 December 2015 at 09:23, Alex Samad wrote: Hi On 10 December 2015 at 23:44, dweimer wrote:

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Alex Samad
Hi So I have taken this config done some slight customization for my site and it appears to be working Thanks for this .. On 10 December 2015 at 23:44, dweimer wrote: > On 2015-12-09 11:29 pm, Alex Samad wrote: >> >> Hi >> >> config >> https_port 22.4.2.5:443 accel >> cert=/etc/httpd/conf.d/off

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Alex Samad
Hi Answer my own question http://www.squid-cache.org/Versions/v3/3.5/cfgman/http_port.html seems like there is a no-vhost, I presume vhost turns it on On 11 December 2015 at 09:23, Alex Samad wrote: > Hi > > > On 10 December 2015 at 23:44, dweimer wrote: >> https_port 10.50.20.12:443 accel de

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Alex Samad
Hi On 10 December 2015 at 23:44, dweimer wrote: > https_port 10.50.20.12:443 accel defaultsite=mail.mydomain.com \ > cert=/certs/wildcard.certificate.crt \ > key=/certs/wildcard.certificate.key \ > options=NO_SSLv2:NO_SSLv3:NO_TLSv1:SINGLE_DH_USE:CIPHER_SERVER_PREFERENCE \ > dhparams=/usr/lo

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Alex Samad
Thanxs everyone i will try the changes and try with the debug options Tls1 might be an issue. Might have to look at the ssl offloading config so squid to exchange can be http instead of ssl Eliezer hopefuly you'll do a centos 6. Any chance you can let me have a non released .12 save me try

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Eliezer Croitoru
On 09/12/2015 12:49, Alex Samad wrote: Hi Can't seem to find 3.5.12 for centos pre compiled at http://www1.ngtech.co.il/repo/centos/6/x86_64/ Since it's in testing I have built and tested for CentOS 7 but yet to publish them. It will take a week or more. Eliezer __

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread dweimer
On 2015-12-09 11:29 pm, Alex Samad wrote: Hi config https_port 22.4.2.5:443 accel cert=/etc/httpd/conf.d/office.abc.com.crt key=/etc/httpd/conf.d/office.abc.com.key defaultsite=office.abc.com options=NO_SSLv2,NO_SSLv3 dhparams=/etc/squid/squid-office-dhparams.pem cipher=ECDHE-RSA-AES128-GCM-SHA2

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-10 Thread Amos Jeffries
On 10/12/2015 6:29 p.m., Alex Samad wrote: > Hi > > config > https_port 22.4.2.5:443 accel > cert=/etc/httpd/conf.d/office.abc.com.crt > key=/etc/httpd/conf.d/office.abc.com.key defaultsite=office.abc.com > options=NO_SSLv2,NO_SSLv3 > dhparams=/etc/squid/squid-office-dhparams.pem > cipher=ECDHE-RS

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-09 Thread Alex Samad
Hi config https_port 22.4.2.5:443 accel cert=/etc/httpd/conf.d/office.abc.com.crt key=/etc/httpd/conf.d/office.abc.com.key defaultsite=office.abc.com options=NO_SSLv2,NO_SSLv3 dhparams=/etc/squid/squid-office-dhparams.pem cipher=ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-A

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-09 Thread Alex Samad
Hi Can't seem to find 3.5.12 for centos pre compiled at http://www1.ngtech.co.il/repo/centos/6/x86_64/ On 8 December 2015 at 19:34, Amos Jeffries wrote: > * try an upgrade to 3.5.12. There were some regressions in the .10/.11 > releases that can lead to really weird behaviour.

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-08 Thread Amos Jeffries
On 8/12/2015 7:35 p.m., Alex Samad wrote: > Hi > > Any suggestions on how to debug this... I wouldn't mind rolling > forward to 3.5 again > Some ideas inline. The main ones are: * re-enable cache.log. It is not optional. * try an upgrade to 3.5.12. There were some regressions in the .10/.11 re

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-07 Thread Alex Samad
Hi Any suggestions on how to debug this... I wouldn't mind rolling forward to 3.5 again On 2 December 2015 at 20:39, Alex Samad wrote: > Just to add to this I have a lot of these in the log file > > TCP_MISS_ABORTED/000 0 RPC_IN_DATA > TCP_MISS_ABORTED/200 4322 RPC_OUT_DATA > TCP_MISS_ABORTED/00

Re: [squid-users] squid reverse proxy infront of exchange 2010

2015-12-02 Thread Alex Samad
Just to add to this I have a lot of these in the log file TCP_MISS_ABORTED/000 0 RPC_IN_DATA TCP_MISS_ABORTED/200 4322 RPC_OUT_DATA TCP_MISS_ABORTED/000 0 RPC_IN_DATA https: On 2 December 2015 at 17:24, Alex Samad wrote: > Hi > > recently upgraded to squid-3.5.11-1.el6.x86_64 from the cento

[squid-users] squid reverse proxy infront of exchange 2010

2015-12-01 Thread Alex Samad
Hi recently upgraded to squid-3.5.11-1.el6.x86_64 from the centos 6.7 squid 3.1 I am now having problems with people who use active sync via this connection . seems like emails with attachments aren't making it through . cache_peer 10.32.69.11 parent 443 0 proxy-only no-query no-digest origins