Re: [squid-users] can't get to certain sites through proxy

From: <trainier@dont-contact.us>
Date: Wed, 26 Oct 2005 14:13:09 -0400

The error message, or a copy of cache.log would be a good start.
Second, you appear to be trying to accel an http server. Are you doing
this on purpose?
This is NOT proxying as you see it. This is used to speed up web servers
and should not be used.
This applies to all your http_accel entries.

Also, what happend to your 'http_access deny all' line? You don't really
want anyone from anywhere to be
able to use your proxy do you? If so, can you save me the trouble of
hunting you down and give your IP
address so I can toss it into the blacklist? :-)

Please get a better understanding of how ACLs work before you drop a proxy
device out there. That "http_access deny all" line
is VERY important.

Tim Rainier
Information Services, Kalsec, INC
trainier@kalsec.com

Mark Drago <mdrago@bascom.com> wrote on 10/26/2005 11:00:47 AM:

> Hello,
>
> Is there a page or an FAQ somewhere that may help me troubleshoot a
> problem where a site works fine when not going through squid but has
> errors when accessed through squid? I'm having trouble logging in to a
> site when the connection is going through the proxy and I'm not really
> sure where to start.
>
> I'm running squid version 2.5.STABLE9 and my configuration file is
> included below.
>
> Any hints, tips, or links are greatly appreciated.
>
> Thank You,
> Mark Drago
>
> /etc/squid.conf
> ---------------
>
> http_port 3128
> hierarchy_stoplist cgi-bin ?
>
> acl QUERY urlpath_regex cgi-bin \?
> no_cache deny QUERY
>
> cache_dir ufs /var/squid/cache 7727 16 256
>
> cache_access_log /dev/null
> cache_log /dev/null
> cache_store_log none
>
> refresh_pattern ^ftp: 1440 20% 10080
> refresh_pattern . 0 20% 4320
>
> acl all src 0.0.0.0/0.0.0.0
>
> http_access allow all
> icp_access allow all
> miss_access allow all
>
> half_closed_clients off
> server_persistent_connections off
> client_persistent_connections off
>
> visible_hostname serial_number.bascom.net
> unique_hostname serial_number.bascom.net
>
> httpd_accel_host virtual
> httpd_accel_port 80
> httpd_accel_with_proxy on
> httpd_accel_uses_host_header on
>
> maximum_object_size 120000 KB
>
> redirect_program /usr/local/bin/jesred
> redirect_children 40
>
> uri_whitespace deny
> [attachment "signature.asc" deleted by Tim Rainier/KAL/Kalsec]
Received on Wed Oct 26 2005 - 12:17:45 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Nov 01 2005 - 12:00:05 MST