Check access.log and verify whether the traffic is passing through squid from the client machine. -Sent via Blackberry -----Original Message----- From: J Webster <jw.jwebster@xxxxxxxxx> Date: Fri, 10 Aug 2012 20:34:31 To: <squid-users@xxxxxxxxxxxxxxx> Subject: squidguard not blocking squidguard correctly blocks when I run from the command line: [root squidguard]# echo "http://www.porn.com/ - - GET" | squidGuard -c /etc/squid/squidguard.conf -d 2012-08-10 17:45:22 [28923] New setting: dbhome: /var/lib/squidguard 2012-08-10 17:45:22 [28923] New setting: logdir: /var/log/squidguard 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/porn/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/porn/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/porn/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/porn/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/aggressive/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/aggressive/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/aggressive/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/aggressive/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/hacking/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/hacking/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/hacking/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/hacking/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/religion/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/religion/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/religion/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/religion/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/spyware/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/spyware/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/spyware/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/spyware/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/violence/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/violence/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/violence/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/violence/urls.db 2012-08-10 17:45:22 [28923] init domainlist /var/lib/squidguard/weapons/domains 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/weapons/domains.db 2012-08-10 17:45:22 [28923] init urllist /var/lib/squidguard/weapons/urls 2012-08-10 17:45:22 [28923] loading dbfile /var/lib/squidguard/weapons/urls.db 2012-08-10 17:45:22 [28923] squidGuard 1.3 started (1344617122.190) 2012-08-10 17:45:22 [28923] squidGuard ready for requests (1344617122.193) 2012-08-10 17:45:22 [28923] source not found 2012-08-10 17:45:22 [28923] no ACL matching source, using default http://localhost/block.html -/- - GET 2012-08-10 17:45:22 [28923] squidGuard stopped (1344617122.193) Does the url rewriter need to be further up the squid.conf? It is right at the end of the conf file at the moment: url_rewrite_program /usr/bin/squidGuard -c /etc/squid/squidguard.conf