• Firewall

    Mar 9, 2015, 9:59 AM
    0 Votes
    3 Posts
    1k Views

    But while we bypass proxy for some particular IP's the same site is opening for bypassed IP's but remaining IP's are blocked as above Mod-Security.

  • 0 Votes
    1 Posts
    1k Views
    No one has replied
  • [HAProxy-1_5] SNI ACL don't work

    Mar 9, 2015, 3:20 PM
    0 Votes
    12 Posts
    4k Views

    Should be fixed in pkg v0.22, pullrequest send. https://github.com/pfsense/pfsense-packages/pull/834 will probably be committed and be on the package repository in a day or so.

  • Squid: Critical bug

    Mar 13, 2015, 5:14 PM
    0 Votes
    5 Posts
    1k Views

    I think you have misunderstood me. I did not just stop filter that hostname. It simply stopped filtering anything.

  • Squid Crashing On Log Rotation

    Feb 15, 2015, 2:54 PM
    0 Votes
    3 Posts
    2k Views

    2.2-RELEASE (i386)
    built on Thu Jan 22 14:04:25 CST 2015
    FreeBSD 10.1-RELEASE-p4

    Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
    2 CPUs: 1 package(s) x 2 core(s)

    Install pkgs: squid3 (Transparent HTTP proxy enable, c-icap&clamd disable), corn, sarg

    log:
    Mar 16 00:00:13 squid[88317]: Squid Parent: (squid-1) process 92076 started
    Mar 16 00:00:12 php: swapstate_check.php: Squid cache and/or swap.state exceeded size limits. Removing and rotating. File was 3891776 bytes, 0% of total disk space.
    Mar 16 00:00:12 squid[86533]: Squid Parent: (squid-1) process 86945 exited with status 0
    Mar 16 00:00:10 squid[88317]: Squid Parent: (squid-1) process 87786 exited with status 1
    Mar 16 00:00:10 (squid-1): Failed to verify one of the swap directories, Check cache.log for details. Run 'squid -z' to create swap directories if needed, or if running Squid for the first time.
    Mar 16 00:00:10 squid[88317]: Squid Parent: (squid-1) process 87786 started
    Mar 16 00:00:07 squid[88317]: Squid Parent: (squid-1) process 87478 exited with status 1
    Mar 16 00:00:07 (squid-1): Failed to verify one of the swap directories, Check cache.log for details. Run 'squid -z' to create swap directories if needed, or if running Squid for the first time.
    Mar 16 00:00:06 squid[88317]: Squid Parent: (squid-1) process 87478 started
    Mar 16 00:00:05 squid[86533]: Squid Parent: (squid-1) process 86945 started
    Mar 16 00:00:05 squid[86533]: Squid Parent: will start 1 kids
    Mar 16 00:00:05 php: swapstate_check.php: The command '/usr/pbi/squid-i386/sbin/squid -k kill -f /usr/pbi/squid-i386/local/etc/squid/squid.conf' returned exit code '1', the output was 'squid: ERROR: Could not send signal 9 to process 13758: (3) No such process'
    Mar 16 00:00:03 squid[88317]: Squid Parent: (squid-1) process 80899 exited with status 1
    Mar 16 00:00:03 (squid-1): Failed to verify one of the swap directories, Check cache.log for details. Run 'squid -z' to create swap directories if needed, or if running Squid for the first time.
    Mar 16 00:00:03 squid[88317]: Squid Parent: (squid-1) process 80899 started
    Mar 16 00:00:00 kernel: pid 13758 (squid), uid 62: exited on signal 6
    Mar 16 00:00:00 php: swapstate_check.php: Creating squid cache subdirs in /var/squid/cache
    Mar 16 00:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 16 00:00:00 php: swapstate_check.php: Creating Squid cache dir /var/squid/cache
    Mar 16 00:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 23:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 22:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 21:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 20:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 19:29:41 kernel: arp: xxx.xx.xx.1 moved from 00:17:10:89:12:60 to 00:17:10:89:10:20 on em2
    Mar 15 19:29:38 kernel: arp: xxx.xx.xx.1 moved from 00:17:10:89:10:20 to 00:17:10:89:12:60 on em2
    Mar 15 19:29:34 kernel: arp: xxx.xx.xx.1 moved from 00:17:10:89:12:60 to 00:17:10:89:10:20 on em2
    Mar 15 19:29:31 kernel: arp: xxx.xx.xx.1 moved from 00:17:10:89:12:60 to 00:17:10:89:10:20 on em2
    Mar 15 19:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.
    Mar 15 18:00:00 php: sarg.php: Sarg: force refresh now with -d date +%d/%m/%Y-date +%d/%m/%Y args, compress(on) and none action after sarg finish.

  • 0 Votes
    5 Posts
    1k Views

    sorry for not being clear, I solved it creating a group acl at the last order and assignin my network as source like you said thanks

  • Proxy reports (light squid)

    Mar 13, 2015, 6:56 AM
    0 Votes
    2 Posts
    912 Views

    Probably chrome probing for DNS/etc.

    http://serverfault.com/questions/235307/unusual-head-requests-to-nonsense-urls-from-chrome

  • HAProxy 1.5 and HSTS

    Mar 10, 2015, 4:45 PM
    0 Votes
    6 Posts
    5k Views

    Yes I totally agree with you.

    I'll try to reproduce the issue again and get back to you.

    Nicolas

  • 0 Votes
    4 Posts
    3k Views

    Doese failover work?

  • Squid3 missing ident support

    Mar 11, 2015, 5:49 PM
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    10 Posts
    7k Views

    Hi there,

    any news concerning that issue? Same problem over here…just spend nearly the whole day trying to fix it. Could one of you guys solve it?

    Cheers

  • Squid 3 and caching

    Mar 10, 2015, 9:39 PM
    0 Votes
    2 Posts
    1k Views

    You could do a tail -f /var/squid/logs/access.log and see if you get hits or misses when manually running Windows Update, or you could update a client and watch the bandwidth monitor to see if there is WAN activity that matches the LAN activity.  No WAN activity + large LAN activity means it's using the cache.  Just be warned though.  I have played with Dynamic Content caching in the past and it was not reliable for me.    Every request for a segment of the download would cause the entire file to be downloaded, so a 100MB update ended up making Squid download many gigabytes.  My WAN was saturated for an hour while LAN was flat.  I disabled Dynamic Content after that.

  • 0 Votes
    4 Posts
    2k Views

    did you solved the problem?

  • 0 Votes
    5 Posts
    2k Views

    I realized on my installation that the new squid package does NOT start squidguard immediately, but on the first access to a website!

    This is supposedly how the new SquidGuard works.  I'm not sure how it's a problem unless you must see the little green/white triangle.  As long as it works, that is what's important.

  • Squid + kerberos

    Mar 9, 2015, 8:11 PM
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    2 Posts
    2k Views

    Hi!

    I have this problem too.

  • Lightsquid on 2.2 should be OK now

    Feb 13, 2015, 7:27 PM
    0 Votes
    25 Posts
    7k Views

    There should be no need for that with the current package. The gd library is there and the package should be invoking ldconfig to nudge the system to find it without such hacks.

    Check to see if it's there at all:

    find / -name "*GD*.so"
  • 0 Votes
    3 Posts
    2k Views

    All righty, thank you for the explanation :)

    Nicolas

  • 0 Votes
    11 Posts
    7k Views

    I had this same issue with squid 2.7.9.  This worked for me:

    Set squid proxy to listen on port 3129 (or any port you choose, the GUI wouldn't allow me to leave it blank)
    Add custom option: http_port 3128 transparent

    Port forward on LAN:
    Traffic TCP Src * Srcport * Dest * Destport HTTP(80) TargetIP pfsensebox IP Targetport 3128

    My guess is that on the GUI without the transparent box checked, squid was not operating transparently on port 3128 until specifically defined to do so.

    Unfortunately my ultimate goal was to use this rule to apply limiters to the traffic but apparently there is a bug with limiters and squid in transparent mode that I can't seem to get around!

  • Squid Reverse Proxy

    Mar 5, 2015, 1:25 PM
    0 Votes
    1 Posts
    1k Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.