Hello, I notice some of our client is typing an additional dot at the end of the domain, which make the squid ACL failed, e.g. acl dstdomain_index dstdomain .example.com So if client is using, e.g. http://www.example.com./, then ACL blocked the client from accessing. But in real sites this should be allowed? e.g. www.facebook.com./ Howard