ACL dstdomain, strange behaviour, HELP

From: Grabmann Martin <martin.grabmann@dont-contact.us>
Date: Fri, 11 Feb 2000 12:13:31 +0100

hello squid-users,

my configuration:
squid 2.2STABLE5 on HP-UX 10.20 compiled with gcc-2.8.1 and binutils-2.9.1

i use squid as a proxy for our company-intranet, the internet-requests are
forwarded to a parent-cache with a cache_peer entry

cache_peer xxx.xxx.xxx.xxx parent 81 7 no-query default

all users should have access to the company-intranet, but only some users
are allowed to access the internet. i have done this with acl

acl myIpRange src xxx.xxx.xxx.xxx/xxx.xxx.xxx.xxx
acl myTraNet dstdomain siemens.de siemens.be siemens.com fujitsu-siemens.de
fujitsu-siemens.be fujitsu-siemens.com
acl myTerUsers name1 name2 name3

http_access deny !myIpRange
http_access allow myTraNet
http_access allow !myTraNet myTerUsers
http_access deny all

no the problem:
it works well for internet-users, but it dosen't work well for the users who
have only access to the company-intranet (myTraNet).
this users cannot reach www.siemens.be, but all the others. if i remove all
the fujitsu-siemens entries it works fine, but i need them. i tried to use
dots in front of the entries - no success.
if i reorder the entries in some cases www.siemens.de doesn't work. if i
remove only fujitsu-siemens.de it works. i cann't say when it will work or
when it will not work. it's very strange.

please
HEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEELP!!!!!!!!!!!!!!!!!!!!!!!!!!!
thanks
martin
reply to: martin.grabmann@rbg5.siemens.de
Received on Fri Feb 11 2000 - 04:41:33 MST

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 16:51:11 MST