Hi All,
I apologize
for the length of this post, but I'm really at my wits' end and am
completely out of ideas as to how I might fix this or why this is
happening.We are NOT running a Tproxy or any other sort of intercepting proxy, all the clients are explicitly aware of the proxy's existence through a .pac configuration file pushed out through Group Policy.
I've tried disabling ssl_bump (which shouldn't be enabled anyway) for the facebook domains, setting cache deny for those domains, and setting always direct for those domains, none of which has had any effect.
I've also tried reverting to a more "simple" config, even the exact config that we were using on the "old" Squid that was working on Solaris, but that too fails. I've also changed from using Squid 3.5.10 to the version packaged by CentOS (squid-3.3.8-12.el7_0.x86_64), tried this with both configurations to no avail.
The only thing that has worked is setting up a "test" squid at our primary datacenter, same configurations, but this one does work. We've checked and verified that there are no custom routes or any other network configurations that vary between the servers, only IP addresses. Both are on unrestricted vlans that allow direct access to the internet. We are checking with our networking team to see if there is any custom routing that is in place on their end, but it's very doubtful that is the case.
I believe I've covered everything here, I can provide any other information or configurations if necessary (I didn't provide those here because of the length already). If anyone out there has encountered this issue, I would GREATLY appreciate any information or troubleshooting assistance you could provide.
Best Regards,
This email and any attachments may contain information that is proprietary,
confidential and/or privileged and for the sole use of the intended recipients(s)
only.
If you are not the intended recipient, please notify the sender by return
email and delete all copies of this email and any attachments. Ahold and/or its
subsidiaries shall neither be liable for the inaccurate or incomplete transmission
of the information contained in this email or any attachments, nor for any delay
in its receipt. To the extent this email is intended to create any legal obligation,
the obligation shall bind only the contracting entity and not any other entity within
the Ahold Group.
This email and any attachments may contain information that is proprietary,
confidential and/or privileged and for the sole use of the intended recipients(s)
only.
If you are not the intended recipient, please notify the sender by return
email and delete all copies of this email and any attachments. Ahold and/or its
subsidiaries shall neither be liable for the inaccurate or incomplete transmission
of the information contained in this email or any attachments, nor for any delay
in its receipt. To the extent this email is intended to create any legal obligation,
the obligation shall bind only the contracting entity and not any other entity within
the Ahold Group.
_______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users