[squid-users] delay pools and ntlm errors

From: Leonardo Bacha Abrantes <leonardo_at_lbasolutions.com>
Date: Fri, 5 Oct 2012 16:13:17 -0300

Hi guys,

I'm facing many problems with my squid.

This message appears a lot on the log:

[2012/10/05 15:57:28.523249, 1] libsmb/ntlmssp.c:342(ntlmssp_update)
  got NTLMSSP command 3, expected 1

===

Surf on internet is slow when delay pools is enabled.

====
I also had:

FATAL: Too many queued ntlmauthenticator requests

and I increased the value of auth_param ntlm|basic children.

=====

my squid.conf:

http_port 3128
append_domain .contoso.local
cache_effective_user squid
cache_mem 2 GB
cache_effective_group squid
forwarded_for off
httpd_suppress_version_string on
visible_hostname proxy.contoso.local
retry_on_error on
pipeline_prefetch on

auth_param ntlm program /usr/bin/ntlm_auth
--helper-protocol=squid-2.5-ntlmssp --domain=contoso
auth_param ntlm children 45
auth_param basic program /usr/bin/ntlm_auth
--helper-protocol=squid-2.5-basic --domain=contoso
auth_param basic children 25
auth_param basic realm Para prosseguir e necessario digitar seu login de rede.
auth_param basic credentialsttl 2 hours

acl localnetwork src xxx.xxx.xxx.xxx/25
acl AuthorizedUsers proxy_auth -i "/etc/squid/default_access.acl"
#acl unlimitedBandwidth src "/etc/squid/unlimited_bandwidth"
acl localhost src 127.0.0.1
acl java browser Java/1.4 Java/1.5 Java/1.6

cache_dir ufs /var/spool/squid 6144 16 256
coredump_dir /var/spool/squid
maximum_object_size_in_memory 512 KB
maximum_object_size 64 MB
minimum_object_size 0 KB

acl manager proto cache_object
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 8080 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 1025-65535 # unregistered ports
acl purge method PURGE
acl CONNECT method CONNECT

#delay_pools 1

#delay_class 1 2
#delay_parameters 1 -1/-1 65536/65536
#delay_access 1 deny unlimitedBandwidth localhost
#delay_access 1 allow localnetwork
#delay_access 1 deny all

logformat combined [%tl] %un %>a %rm %Ss %Hs %ru
access_log /var/log/squid/access.log squid
access_log /var/log/squid/gerencia.log combined
cache_store_log /var/log/squid/store.log

redirect_program /etc/squidGuard/bin/squidGuard -c
/usr/local/squidGuard/squidGuard.conf
redirect_children 30

http_access deny CONNECT !SSL_ports
http_access allow java
http_access allow AuthorizedUsers
http_access allow unlimitedBandwidth
#http_access allow AuthorizedUsers
http_access deny all

cache_swap_low 90
cache_swap_high 95
dns_nameservers xxx.xxx.xxx.xxx
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (zip|rar|tar\.gz|exe)$ 0 50% 259200
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
request_header_access All allow all

many thanks!
Received on Fri Oct 05 2012 - 19:14:04 MDT

This archive was generated by hypermail 2.2.0 : Mon Oct 08 2012 - 12:00:02 MDT