This is the basic function ability in the NTLM negotiation mechanism. Ignore it, all logs that support NTLM authentication show two denied requests off hand, than the connect. HTH -----Original Message----- From: Tom Porch [mailto:tom.porch@xxxxxxxxxxxxx] Sent: 27 November 2008 14:24 To: squid-users@xxxxxxxxxxxxxxx Subject: TCP_MISS and TCP_DENIED Hi all I've got 2.7 on a Windows box and have configured it for NTLM authentication so I get the username logged. However I get TCP_MISS and TCP_DENIED logged even though access is allowed to the web sites requested. Is there a quick fix to get it correctly logging the requests? Thanks Tom