• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

C-ICAP - Access Logs e SQUID log [RESOLVIDO]

Scheduled Pinned Locked Moved Portuguese
9 Posts 3 Posters 1.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    diegovaz
    last edited by May 26, 2017, 11:41 AM May 25, 2017, 11:29 AM

    Pessoal,

    bom dia!

    2 coisas que queria duvida com vocês  ::)

    Observando meu PF hoje e notei 2 coisas meio que estranhas e gostaria de saber se é normal, a primeira e o log do C-ICAP ele fica enviando essa mensagem todo segundo…

    C-ICAP - Access Logs
    Date-Time	Message
    25.05.2017 07:54:44	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:44	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:43	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:43	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:43	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:43	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:42	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:42	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:42	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:42	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:41	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:40	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 200
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 REQMOD squid_clamav 204
    25.05.2017 07:54:39	127.0.0.1 127.0.0.1 RESPMOD squid_clamav 204
    

    o outro é o log no meu squid que só apresenta essas mensagens

     Squid - Cache Logs
    Date-Time	Message
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00	
    31.12.1969 21:00:00
    

    Nao sei por que mas tenho um persentimento que não é normal.

    Agradeço pelo comentário de vocês!

    abraço

    squid.jpg
    squid.jpg_thumb
    ICAP.jpg
    ICAP.jpg_thumb

    1 Reply Last reply Reply Quote 0
    • D
      danilosv.03
      last edited by May 25, 2017, 12:47 PM

      Me explica primeiro como sua rede trabalha hoje. No teu squid o loopback tá selecionado?


      :)
      |E-mail: danilosv.03@gmail.com
      |Skype: danilosv.03


      1 Reply Last reply Reply Quote 0
      • D
        diegovaz
        last edited by May 25, 2017, 1:23 PM

        danilosv.03

        Essa rede é uma rede simples, squid, squidguard, modo transparente, sem interceptaçao de ssl.

        nao a loopback nao esta selecionada.

        me chamou a atençao foram as datas do arquivo do squid, o pfsense esta com a hora e data setada correto.

        1 Reply Last reply Reply Quote 0
        • D
          danilosv.03
          last edited by May 25, 2017, 1:26 PM

          Tu usa o forwarder na sua rede? Vai em System - General Setup e marque a opção: Disable DNS Forwarder


          :)
          |E-mail: danilosv.03@gmail.com
          |Skype: danilosv.03


          1 Reply Last reply Reply Quote 0
          • D
            diegovaz
            last edited by May 25, 2017, 4:20 PM

            Danilo,

            desabilitei mas mesmo assim ficou na mesma.

            1 Reply Last reply Reply Quote 0
            • M
              marcelloc
              last edited by May 25, 2017, 4:38 PM

              De acordo com a RFC, você está vendo os logs da comunicação ICAP entre o squid e o antivirus

              https://tools.ietf.org/html/rfc3507
              In "request modification" (reqmod) mode, an ICAP client sends an HTTP
                request to an ICAP server.  The ICAP server may then:

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • D
                diegovaz
                last edited by May 25, 2017, 4:45 PM

                entao isso é normal Marcelo?

                1 Reply Last reply Reply Quote 0
                • M
                  marcelloc
                  last edited by May 25, 2017, 4:51 PM

                  @diegovaz:

                  entao isso é normal Marcelo?

                  Não são mensagens de erro. Se quiser ver se tem alguma informação a mais, veja os arquivos de log via console. Mas se o serviço está ok, acredito que seja normal.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • D
                    diegovaz
                    last edited by May 25, 2017, 4:54 PM

                    Obrigado pelo feeds galera!

                    abraço

                    1 Reply Last reply Reply Quote 0
                    9 out of 9
                    • First post
                      9/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                      This community forum collects and processes your personal information.
                      consent.not_received