On 28/10/2015 5:15 a.m., De Lazzari Matteo wrote: > Something like this? http_access allow password internetfull Internetfullthrottle is a "fake" rule because the following http_access allow password internetfull is less restrictive. Is it right? > > http_access allow password internetfull Internetfullthrottle > http_access allow password internetfull > > external_acl_type internetfullthrottle_grp children=20 ttl=3600 > negative_ttl=3600 %LOGIN /usr/lib64/squid/ext_kerberos_ldap_group_acl -g InternetFullThrottle -D xxx > acl internetfullthrottle external internetfullthrottle_grp > > delay_pools 1 > delay_class 1 1 > delay_parameters 1 1250000/1250000 > delay_access 1 allow internetfullthrottle > delay_access 1 deny all > Yes, but only because you are using class 1 pool in that config. The class 5 pool you asked about earlier would not work with that helper or delay_access rules. Amos _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users