ACLs - a seriously weird thing

From: <rstagg@dont-contact.us>
Date: Wed, 17 Feb 1999 19:36:42 +0000

Greetings,

I've just seen something worryingly weird on one of my caches. It's a
Squid2.1PATCH2 install on a Solaris 2.6 Enterprise 450.

Yesterday I had a call from a colleague; he was trying to access a server
(call it 20.20.20.20) which is internal to our company. Squid thought it
was external, but this was not a problem. I added:

     acl int_ip_host dst 20.20.20.20
     always_direct allow int_ip_host

This fixed the problem. Then the performance started to suffer. The cache
became intermittent, and it took me _ages_ to figure out what was going on.

You'll love this: If I browsed sites ending in .com, .net, .se, .org... etc
etc, in fact most sites, they were fine. If I browsed a site ending in .uk,
the cache sat and thought about it for a full minute before giving me a
couple of objects and then going back into catatonia. I removed the above
two lines from squid.conf, and the problem vanished. I tested and retested
this, on the grounds that it's clearly nonsense, but the fact is apparent
that the lines above break the cache, _only_ on *.uk sites.

I'm totally confused by this. Is this a bug? Have I mucked up? Does anyone
have any ideas?

Regards

Richard Stagg
Received on Wed Feb 17 1999 - 12:35:41 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:44:35 MST