Hello, okay, this actually works: acl DENY_ACCESS http_status 403 access_log /tmp/squid.deny.log squid DENY_ACCESS Okay, but how can i now Debug which acl rule caused TCP_DENIED/403? I only want to set my debug_options for the TCP_DENIED/403 requests... Thanks, Mario