Re: [squid-users] IP addresses in log with log_FQDN on

From: DaveP <davep@dont-contact.us>
Date: Mon, 01 Nov 2004 14:58:03 +0000

Henrik Nordstrom wrote:
> On Thu, 28 Oct 2004, DaveP wrote:
>
>> I set up access control using srcdomain in the hope of 'forcing' a reverse
>> lookup but there are still a few rogue log entries getting through.
>
> Should work... but there is a very small race window if the cached lookup
> expires before the request completes..

The internal DNS is a zone transfer from Win2k and there are some very
short TTL values in there (20 minutes...). Maybe the MS domain admins
can extend their TTL, but that would only reduce not eliminate the
problem. Is this likely to be fixed in Squid? The code is too complex
and insufficiently commented to try hacking it myself.

-- 
Dave
The information contained in this message (and any attachments) may 
be confidential and is intended for the sole use of the named addressee. 
Access, copying, alteration or re-use of the e-mail by anyone other 
than the intended recipient is unauthorised. If you are not the intended 
recipient please advise the sender immediately by returning the e-mail 
and deleting it from your system.
______________________________________________________________________
This email has been scanned by the MessageLabs Email Security System.
For more information please visit http://www.messagelabs.com/email 
______________________________________________________________________
Received on Mon Nov 01 2004 - 07:58:10 MST

This archive was generated by hypermail pre-2.1.9 : Wed Dec 01 2004 - 12:00:01 MST