Diskusi tentang Ubuntu Server baik webserver, database server, samba server dan service lainnya serta jaringan menggunakan Sistem Operasi Ubuntu.
Post 24 May 2014, 18:52

mohon bantuannya nih mas
tiap login di pake proxy kok selalu tidak bisa ya..ini lognya
1400912075.727 287 TCP_MISS/000 0 POST - DIRECT/ -
1400912076.127 394 TCP_MISS/000 0 POST - DIRECT/ -
1400912076.407 274 TCP_MISS/000 0 POST - DIRECT/ -
1400912076.824 410 TCP_MISS/000 0 POST - DIRECT/ -
1400912077.087 252 TCP_MISS/000 0 POST - DIRECT/ -

Post 26 May 2014, 20:51

heemm, ane masih bingung sm pertanyaan ente?

btw sdh coba cari trit2 di FUI yg sdh mmbahas ttg squid proxy om...kali aj ada yg mirip2 masalahnya om :)

Post 27 May 2014, 03:45

kalo masuk di lancar tapi kalo login prosesnya lama trus keluar tampilan error di browser seperti ini

While trying to retrieve the URL:

The following error was encountered:

Read Error

The system returned:

(104) Connection reset by peer

An error condition occurred while reading data from the network. Please retry your request.

Post 27 May 2014, 19:16

sdh yakin klo di konfigurasi squidnya yg perlu diperbaiki

coba gelar dimari squid.conf nya om, nnti ane & temen2 lain bisa bantu..

eehm...sekilas sih ada gmbran ...rset by peer

coba baca ini om > connection reset by peer?
``Connection reset by peer'' is an error code that Unix operating systems sometimes return for read, write, connect, and other system calls.

Connection reset means that the other host, the peer, sent us a RESET packet on a TCP connection. A host sends a RESET when it receives an unexpected packet for a nonexistent connection. For example, if one side sends data at the same time that the other side closes a connection, when the other side receives the data it may send a reset back.

The fact that these messages appear in Squid's log might indicate a problem, such as a broken origin server or parent cache. On the other hand, they might be ``normal,'' especially since some applications are known to force connection resets rather than a proper close.

You probably don't need to worry about them, unless you receive a lot of user complaints relating to SSL sites.

Rick Jones notes that if the server is running a Microsoft TCP stack, clients receive RST segments whenever the listen queue overflows. In other words, if the server is really busy, new connections receive the reset message. This is contrary to rational behaviour, but is unlikely to change.

Post 31 May 2014, 07:07

maaf baru nengok mas..ini squid.conf proxy saya

# Port and Transparent
http_port transparent tproxy
http_port localhost:3128
server_http11 on
icp_port 0

# Lusca Cache Directory
cache_dir aufs /cache 70000 164 256
cache_replacement_policy heap LFUDA
memory_replacement_policy heap GDSF

# Lusca Log Options
emulate_httpd_log off
logfile_rotate 1
log_icp_queries off

icon_directory /usr/share/squid/icons
cache_swap_log /var/log/squid/swap.state
cache_access_log /var/log/squid/access.log
cache_log /var/log/squid/cache.log
cache_store_log none
pid_filename /var/run/
coredump_dir /var/spool/squid
error_directory /usr/share/squid/errors/English
mime_table /etc/squid/mime.conf

# DNS and FTP option

# Access Control List (ACL) Option
acl all src
acl localhost src
acl localnet src
acl localnet src
acl to_localhost dst

acl SSL_ports port 443 563 873
acl Safe_ports port 21 70 80 210 280 443 488 563 591 631 777 873 901 1025-65535
acl manager proto cache_object
acl purge method PURGE
#acl dynamic urlpath_regex cgi-bin \?

#acl snmppublic snmp_community public
#snmp_port 3401
#snmp_access allow snmppublic all

#extension yg gk boleh di cache
acl DENYCACHE urlpath_regex \.(ini|ui|lst|inf|pak|ver|patch|md5|cfg|lst|list|rsc|log|conf|dbd|db)$
acl DENYCACHE urlpath_regex (notice.html|afs.dat|dat.asp|patchinfo.xml|version.list||updates.txt|patchlist.txt)
acl DENYCACHE urlpath_regex (pointblank.css|login_form.css|form.css)$
acl DENYCACHE urlpath_regex (Loader|gamenotice|sources|captcha|notice|reset)
acl DENYCACHE urlpath_regex -i \.(dbd|db|ver|ini|cfg|lst|1st|rsc|log|conf|rsc|jsp|cgi|asx|txt|partialinfo)$
acl DENYCACHE urlpath_regex -i \.(pointblank.css|login_form.css|form.css)$
acl DENYCACHE urlpath_regex -i \/(update.exe|noupdate.ui|afs.dat|PatchTimeCheck.dat|PatchPath.dat|wpad.dat|cacheKey=|sources|captcha|reset|version|latest|login|notice|index|default|patchinfo.xml|patcherContent.php|gs_service_login.php||str_mission_id.stg|str_id.stg|main.exe)
acl DENYCACHE urlpath_regex -i ^*
acl DENYCACHE urlpath_regex -i ^*
cache deny DENYCACHE
always_direct allow DENYCACHE

acl whitelist url_regex -i "/etc/squid/whitelist.txt"
http_access allow whitelist

acl porno url_regex -i "/etc/squid/porno.txt"
http_access deny porno internetsehat
deny_info porno

http_access allow manager localhost
http_access allow purge localhost
http_access deny manager
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localnet
http_access allow localhost
#http_access deny to_localhost
http_access deny all

icp_access allow all

# Don't upgrade ShoutCast responses to HTTP
acl shoutcast rep_header X-HTTP09-First-Line ^ICY.[0-9]
upgrade_http0.9 deny shoutcast

# Apache mod_gzip and mod_deflate known to be broken so don't trust Apache to signal ETag correctly on such responses
acl apache rep_header Server ^Apache
broken_vary_encoding allow apache

#sembunyikan proxy
header_access Accept-Encoding deny all
header_access X-Forwarded-For deny all

header_access Accept-Encoding allow all
header_access Content-Encoding allow all
header_access Content-Length allow all
header_access Content-Range allow all
header_access Content-Type allow all
header_access If-Modified-Since allow all

# Administrative Parameters
cache_effective_user proxy
cache_effective_group proxy
cache_mgr FPUI
cachemgr_passwd none all
visible_hostname kurnia

# Accelerator Options
half_closed_clients off
range_offset_limit 0 KB
quick_abort_min 0
quick_abort_max 0
quick_abort_pct 100
vary_ignore_expire on
reload_into_ims on
log_fqdn off
memory_pools off
#memory_pools_limit 5 MB
cache_swap_low 97
cache_swap_high 99
max_filedescriptors 65536
fqdncache_size 1024 # Mohon sesuaikan dengan RAM
ipcache_size 1024 # Mohon sesuaikan dengan RAM
ipcache_low 97
ipcache_high 99
pipeline_prefetch on
forwarded_for on
via on
client_db on
client_persistent_connections on
server_persistent_connections on
icp_hit_stale on
query_icmp on
strip_query_terms off # Harus ada jika pakai r25
negative_ttl 30 seconds
positive_dns_ttl 6 hours
negative_dns_ttl 60 seconds
store_dir_select_algorithm round-robin
uri_whitespace strip
shutdown_lifetime 10 seconds

# Options Which Affect The Cache Size
cache_mem 8 MB
maximum_object_size_in_memory 512 bytes
minimum_object_size 0 KB
maximum_object_size 512 MB

# ZPH Option
zph_mode tos
zph_local 0x30
zph_parent 0
zph_option 136

# ACL Caching
include /etc/squid/acl.conf

Post 04 Jun 2014, 23:31

klo ane lihat squid.conf nya sprtinya gk ada masalah om.. tmen2 cmiiw

walau ada kemungkinan broken parent cache, 1 atau bbrp cache proxy ente bermasalah

btw boleh tau jg topologi network nya... biar tau ini si proxy ama si host dri sub domain

bisa jdi konfigurasi pd sisi host ada yg berubah/bermasalah

