[squid-users] Strange problem with some sites (403 and no connection)

From: Antonio Gutiérrez Mayoral <agutierr_at_gmail.com>
Date: Tue, 25 Mar 2014 12:58:04 +0100

Hi there, I have a problem with my squid setup. I am running
Squid 3.2 in a SLES 11 box. Ok, everthing is working fine, with my
particular setup but I have discovered (by my users) that there is
at least two sites that are not working.

The strange thing is this sites are not forbidden, but, I am seeing
403 codes and after that, the home site for this sles server :? (for apache)
not my 403 customized page in case this site was forbiden (like facebook,
youtube, etc).

This sites are spanish sites: www.aemet.es and www.agenciatributaria.es
Its very strange. The access.log shows this:

1395744973.690 2 10.10.5.17 TCP_MISS/403 5821 GET http://www.aemet.es/
MyUser DIRECT/:: text/html

1395744973.707 6 10.10.5.17 TCP_REFRESH_UNMODIFIED/304 330 GET
http://www.aemet.es/welcome/inc/micro.js MyUser DIRECT/:: -

1395744973.708 5 10.10.5.17 TCP_REFRESH_UNMODIFIED/304 329 GET
http://www.aemet.es/welcome/inc/share.js MyUser DIRECT/:: -

The strange thing is I have runned tcpdump in the proxy server, and
the DNS queries for
aemet.es were ok, after that there isnt any kind of connection from
the proxy server
to the aemet site. I dont understand why. This site is not
blacklisted. And in case it was,
I guess that I must see my custom forbidden page, not the apache main site.

Could anybody give me any help about whats happening? I was about one month
with this problem and I didnt discover anything...

any help will be welcome. Could anybody test these sites in your squids ?

thank you!

-- 
--
Antonio Gutiérrez Mayoral <agutierr_at_gmail.com>
Received on Tue Mar 25 2014 - 11:58:11 MDT

This archive was generated by hypermail 2.2.0 : Tue Mar 25 2014 - 12:00:13 MDT