Re: [squid-users] https sessions timeout

From: Matus UHLAR - fantomas <uhlar@dont-contact.us>
Date: Fri, 23 Jun 2006 15:18:12 +0200

On 23.06.06 11:56, Owens, Ron wrote:
> I am running squid Version 2.5.STABLE12, running on 4 servers. The
> clients uses a .pac file to load balance between these 4 servers.
>
> When I log into a https site, (usually a bank), then the session expires
> after a few minutes, telling me I have been inactive for over 5 minutes.
> However, if I point the client directly at any of the servers (bypassing
> the .pac file) the problem goes away.

This is probably caused by your .pac script (or dns) directing difefrent
requests to different caches. Server sees different hosts to request
documents within the same session and many applications do not like it.

The pac script should probably direct the same destination site to the same
proxy. We have L3 switches (Nortel Alteon, similar functionality should be
provided by linux IPVS) that balance proxies using source IP hashing, which
results in using still the same proxy by each client

-- 
Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
Warning: I wish NOT to receive e-mail advertising to this address.
Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
Honk if you love peace and quiet. 
Received on Fri Jun 23 2006 - 07:18:17 MDT

This archive was generated by hypermail pre-2.1.9 : Sat Jul 01 2006 - 12:00:02 MDT