Re: [squid-users] Problem with squid and dansguardian viewing streaming videos

From: David Touzeau <david_at_touzeau.eu>
Date: Mon, 30 Aug 2010 23:15:14 +0200

Depends of your squid version

It seems that Dansguardian is not really compliance squid 3.x
Stay on squid 2.6 for Dansguardian or switch to C-ICAP+SquidGuard has a
good alternative.

On 30/08/2010 18:58, Darren wrote:
> I've been made aware of an issue with viewing streaming media files
> off of sites like cbc.ca where the video files simply will not load
> and play.
>
> I am using squid and dansguardian. If I proxy directly through squid
> and skip dansguardian, the videos stream fine. If I go through
> dansguardian, the videos will not stream.
>
> I can, however, stream video from youtube just fine through dans and squid.
>
> I think that my issue is with dansguardian not dealing with the java
> script files on the loading pages properly, so I've allowed certain
> mime types through dans. Unfortunately this has not met with success.
>
> Has anyone else had this experience or able to recommend an avenue to explore?
>
> Thanks,
>
> D
>
>
>
>
>
> Squid.conf
>
> acl manager proto cache_object
> acl localhost src 127.0.0.1/32
> acl to_localhost dst 127.0.0.0/8
> acl SSL_ports port 443
> acl Safe_ports port 80 # http
> acl Safe_ports port 21 # ftp
> acl Safe_ports port 443 # https
> acl Safe_ports port 70 # gopher
> acl Safe_ports port 210 # wais
> acl Safe_ports port 1025-65535 # unregistered ports
> acl Safe_ports port 280 # http-mgmt
> acl Safe_ports port 488 # gss-http
> acl Safe_ports port 591 # filemaker
> acl Safe_ports port 777 # multiling http
> acl CONNECT method CONNECT
>
> maximum_object_size 4 GB
> store_avg_object_size 50 KB
> half_closed_clients off
> quick_abort_min -1 KB
>
> http_access allow manager localhost
> #http_access deny manager
> http_access deny !Safe_ports
> http_access deny CONNECT !SSL_ports
> http_access allow localhost
> icp_access deny all
> htcp_access deny all
> http_port 207.102.59.150:3128 transparent
> hierarchy_stoplist cgi-bin ?
> access_log /var/log/squid/access.log squid
> logfile_rotate 10
> cache_store_log none
>
> refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
> refresh_pattern . 0 20% 4320
>
> #efresh_pattern ^ftp: 1440 20% 10080
> #refresh_pattern ^gopher: 1440 0% 1440
> #refresh_pattern . 0 40% 40320
> #refresh_pattern (/cgi-bin/|\?) 0 0% 0
>
>
>
> icp_port 3130
> coredump_dir /var/spool/squid
>
> dns_nameservers 208.67.222.222 208.67.220.220
>
> redirect_rewrites_host_header off
> cache_replacement_policy heap GDSF
> cache_effective_user squid
> cache_effective_group squid
> cache_mem 300 MB
> cache_dir ufs /var/spool/squid 2000 16 256
>
> emulate_httpd_log on
>
> visible_hostname Proxy
>
> always_direct allow all
> acl our_networks src xxx.xxx.xx.xxx
> http_access allow our_networks
>
Received on Mon Aug 30 2010 - 21:15:22 MDT

This archive was generated by hypermail 2.2.0 : Tue Aug 31 2010 - 12:00:03 MDT