Thank you for the helpful advise. > So you _know_ its not DG but only guess that it is Squid. Did you check > the error page received back to see what software produced it? if squid > did the browser received HTTP headers will contain the name of the squid > error template. The page footer should also say "Generated by blah". > With the non-visible source also having the error page template name. > > "The server is refusing connections" is not a part of the squid > templates. So if it is a squid page that message has been received from > somewhere else. It says that gmail itself are rejecting connections. Yes, it seems not Squid is blocking it regarding that the error message on the browser does NOT have Squid info at all. > Logging in to squid? or to the gmail website itself? > > The quick answer seems to be add or reassign users from group2 to > group1. Beyond that we will need to know details of the squid.conf. The authentication to LDAP pops up when open the browser and websites that NOT been clocked by both DansGuardian and Squid work. However, only gmail cannot be accessed by group2 that I have been stressed. I will create another group and assign a few users from group2, and see how it goes. There are about 3000 users in here, so cannot reassign the group easily, unfortunately. I am very appreciate your advise. Thank you! Jay