Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    C-ICAP - Access Logs e SQUID log [RESOLVIDO]

    Portuguese
    3
    9
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      diegovaz
      last edited by

      Pessoal,

      bom dia!

      2 coisas que queria duvida com vocês  ::)

      Observando meu PF hoje e notei 2 coisas meio que estranhas e gostaria de saber se é normal, a primeira e o log do C-ICAP ele fica enviando essa mensagem todo segundo…

      C-ICAP - Access Logs
      Date-Time	Message
      25.05.2017 07:54:44	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:44	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:43	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:43	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:43	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:43	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:42	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:42	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:42	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:42	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:41	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
      25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
      

      o outro é o log no meu squid que só apresenta essas mensagens

       Squid - Cache Logs
      Date-Time	Message
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00	
      31.12.1969 21:00:00
      

      Nao sei por que mas tenho um persentimento que não é normal.

      Agradeço pelo comentário de vocês!

      abraço

      squid.jpg
      squid.jpg_thumb
      ICAP.jpg
      ICAP.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • danilosv.03D
        danilosv.03
        last edited by

        Me explica primeiro como sua rede trabalha hoje. No teu squid o loopback tá selecionado?


        :)
        |E-mail: danilosv.03@gmail.com
        |Skype: danilosv.03


        1 Reply Last reply Reply Quote 0
        • D
          diegovaz
          last edited by

          danilosv.03

          Essa rede é uma rede simples, squid, squidguard, modo transparente, sem interceptaçao de ssl.

          nao a loopback nao esta selecionada.

          me chamou a atençao foram as datas do arquivo do squid, o pfsense esta com a hora e data setada correto.

          1 Reply Last reply Reply Quote 0
          • danilosv.03D
            danilosv.03
            last edited by

            Tu usa o forwarder na sua rede? Vai em System - General Setup e marque a opção: Disable DNS Forwarder


            :)
            |E-mail: danilosv.03@gmail.com
            |Skype: danilosv.03


            1 Reply Last reply Reply Quote 0
            • D
              diegovaz
              last edited by

              Danilo,

              desabilitei mas mesmo assim ficou na mesma.

              1 Reply Last reply Reply Quote 0
              • marcellocM
                marcelloc
                last edited by

                De acordo com a RFC, você está vendo os logs da comunicação ICAP entre o squid e o antivirus

                https://tools.ietf.org/html/rfc3507
                In "request modification" (reqmod) mode, an ICAP client sends an HTTP
                  request to an ICAP server.  The ICAP server may then:

                Treinamentos de Elite: http://sys-squad.com

                Help a community developer! ;D

                1 Reply Last reply Reply Quote 0
                • D
                  diegovaz
                  last edited by

                  entao isso é normal Marcelo?

                  1 Reply Last reply Reply Quote 0
                  • marcellocM
                    marcelloc
                    last edited by

                    @diegovaz:

                    entao isso é normal Marcelo?

                    Não são mensagens de erro. Se quiser ver se tem alguma informação a mais, veja os arquivos de log via console. Mas se o serviço está ok, acredito que seja normal.

                    Treinamentos de Elite: http://sys-squad.com

                    Help a community developer! ;D

                    1 Reply Last reply Reply Quote 0
                    • D
                      diegovaz
                      last edited by

                      Obrigado pelo feeds galera!

                      abraço

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.