Re: [squid-users] Squid 2.7 Transparent Between Router & Firewall Checkpoint UTM270 - Microsoft Page Issues

From: Kinkie <gkinkie_at_gmail.com>
Date: Tue, 12 Jan 2010 23:34:57 +0100

On Fri, Jan 8, 2010 at 3:35 AM, Alexandros Engelen <aengelen_at_toptech.gr> wrote:
> Hello,
>
> I have a squid box between the router (connectec to Internet) and the
> "final" firewall which is a Checkpoint UTM270 model. The Squid proxy is
> successfully running as a transparent proxy-router (using IPTables)  for the
> internal clients of the company.
> We have 2 major problems.
>
> No client is able to access the www.microsoft.com website or any other
> website of the microsoft.com domain. They request the page from their
> browser and the see the page after 2 or 3 minutes. BUT, if they type
> i3.microsoft.com (instead of www.microsoft.com) they successfully get the
> page in 1sec.

Have you checked the suggestions in
http://wiki.squid-cache.org/SquidFaq/TroubleShooting and
http://wiki.squid-cache.org/SquidFaq/SystemWeirdnesses out?

>
> The other problem is that the Checkpoint firewall has SPAMProtection but its
> spamResolver is down because of squid. It can't reach the mother database or
> even establish a connection for the firewall updates.

You setup looks uncommon. Usually squid is deployed inside the
perimeter firewall, not outside.
Is there anything related in the squid access.log and cache.log?

>
> Thank you in advance,
>
> Alexandros
>

-- 
    /kinkie
Received on Tue Jan 12 2010 - 22:35:01 MST

This archive was generated by hypermail 2.2.0 : Wed Jan 13 2010 - 12:00:03 MST