[squid-users] Squid's IDENT doesn't work through firewall

From: STEPHEN <ssha@dont-contact.us>
Date: Mon, 13 Aug 2001 12:49:58 +0100

Hi Everyone,

This may or may not be more of a firewall issue, but I'm hoping that
some of you may have come across this and may be able to help:

I am using ident_aware_hosts to retrieve the ident of clients for simply
access control. All has worked well until a firewall (Cisco PIX 515) was
installed between the internal squid proxy and our clients.
Unfortunately I know very little about the firewall but can simply
monitor its log on a terminal.

The IDENT no longer works and Squid does not receive an IDENT reply.
Port 113 is supposedly open on the firewall and it does not report any
deny/113 errors, but closes comms going on 113 with TCP-RST with 0
bytes. In other words, the firewall seems to think that the IDENT
between the squid and client is either 0 bytes or invalid, and
immediately closes the connection.

Any ideas? Thanks.

Steve Sharrad
Network Manager - The HENLEY College
High Performance Networking Specialist,
Systems & Automation Software Programmer
& Dell Certified Server and RAID Engineer
Mobile +44 7909 528724
Telephone +44 1491 579988
Fax +44 1491 410099
E-mail steve_sharrad@bigfoot.com or ssha@henleycol.ac.uk
IT Services - Making IT a success at The HENLEY College
Received on Tue Aug 14 2001 - 01:44:07 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:01:37 MST