LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 11-15-2004, 08:10 AM   #1
Recirqie
Member
 
Registered: Jun 2003
Distribution: RH 8.2, SuSE 9.0
Posts: 135

Rep: Reputation: 15
squidGuard redirection gives TCP miss


I run a small network with a squid proxy, router and clients. All is well as long as allowed addresses are requested. But when a dis-allowed one is requested squidGuard shall redirect to another website. What happens is that lots of kdeinit processes are started until the machine freezes. Usually it reports that there is a timeout and that it cannot access the proxy. When I look at the squid access log I see the following (as many instances as there are processes in the client) e.g.:
1100508619.507 121321 192.168.x.x TCP_CLIENT_REFRESH_MISS/503 1414 GET <IP-address of dis-allowed site> - NONE/ - text/html

192.168.x.x is the address of the router on the proxy side.

What I should get is this:
1100508619.507 121321 192.168.x.x TCP_DENIED/503 1414 GET <IP-address of redirect site> - NONE/ - text/html

Where have I gone wrong?
 
Old 11-15-2004, 12:32 PM   #2
maxut
Senior Member
 
Registered: May 2003
Location: istanbul
Distribution: debian - redhat - others
Posts: 1,188

Rep: Reputation: 50
just an idea:
if u have firewall, try to allow loopback
iptables -I INPUT -i lo -j ACCEPT
 
Old 11-15-2004, 01:49 PM   #3
phatboyz
Member
 
Registered: Feb 2004
Location: Mooresville NC
Distribution: CentOS 4,Free BSD,
Posts: 358

Rep: Reputation: 30
not to get off subject but how do you like squidguard? I also run squid, but thinking on adding squidguard to keep down the no no webpages
 
Old 11-16-2004, 12:49 PM   #4
Recirqie
Member
 
Registered: Jun 2003
Distribution: RH 8.2, SuSE 9.0
Posts: 135

Original Poster
Rep: Reputation: 15
Unless something connected with iptables must be reloaded it doesn't help. And it looked to me as if it was allowed already????

The squid cache log gives umpteen messages as well, as follows:
2004/11/16 16:46:17 | comm_udp_sendto: FD 7, 213.142.64.170, port 53: (101) Network is unreachable
2004/11/16 16:46:17 | idnsSendQuery: FD 7: sendto: (101) Network is unreachable

As far as the usability of squidGuard goes I don't know yet. But it looks promising.
 
Old 11-20-2004, 04:48 PM   #5
Recirqie
Member
 
Registered: Jun 2003
Distribution: RH 8.2, SuSE 9.0
Posts: 135

Original Poster
Rep: Reputation: 15
Hah! It works, the problem seems to be a timout connected with a very slow response from the redirect page. (The proxy is an old machine, so I didn't want to set up apache on it.)
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
error: mail command failed for /var/log/squidguard/squidGuard.log.6 Niceman2005 Linux - Networking 1 01-22-2009 01:24 PM
I miss gv tantotea Fedora 6 06-21-2005 03:31 AM
Woody 3.0 Open Ports 1470/tcp/uaiact 1518/tcp/vpvd What for?How can I remove them? alexxxis Debian 5 07-05-2004 05:18 PM
close port 6000/tcp 515/tcp SchwipSchwap Linux - Newbie 1 09-12-2002 08:24 AM
Do you miss the spellchecker? jeremy LQ Suggestions & Feedback 9 01-24-2002 08:20 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 09:23 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration