On 24.02 16:15, David Landgren wrote:
> I've just spent the better part of three hours up to my ears in packet
> traces, squid debugging, reconfiguring, upgrading from -STABLE5 to
> -STABLE8 and and firewall tweaking.
>
> I was getting "Zero Sized Reply" on a specific page of a website (within
> an authenticated realm). All the usual recipes got me nowhere. And the
> firewall was showing odd behaviour: I was getting connection rejects on
> a high port of the natted address of the Squid box, coming from source
> port 80 of the remote host I was making the connections too. And no
> amount of nat tweaks or changes to the ruleset would make the page work.
That is a specific behaviour of that page, or better scripts on that
address. For example new versions of IRC servers check if you are not
conecting from open proxy by connecthing back to your IP and scanning for
SOCKS/HTTP proxies on some standard ports.
Scripts on page you are trying to get probably do the same. May I know
what is exact address of that page, to see what's happening?
> Then, after staring at the FAQ (section 11.51) for the seventeenth, the
> I finally began to comprehend the words I was reading ;o)
>
> "Disable any advanced TCP features on the Squid system"
I don't think this is related to squid. This is imho problem of the page
you are requesting and scripts on it. This imho does NOT belong to SQUID
FAQ, but probably to remote server's or page FAQ.
I see that it was already added to the SQUID FAQ. I'd like to investigate
this problem a bit more...
-- Matus UHLAR - fantomas, [email protected] ; http://www.fantomas.sk/ Warning: I wish NOT to receive e-mail advertising to this address. Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu. I drive way too fast to worry about cholesterol.Received on Fri Feb 25 2005 - 01:41:34 MST
This archive was generated by hypermail pre-2.1.9 : Tue Mar 01 2005 - 12:00:02 MST