1448445753.714 6 10.22.100.3 TCP_MISS/200 799 GET http://officecdn.microsoft.com/pr/39168D7E-077B-48E7-872C-B232C3E72675/Office/Data/v32.cab - HIER_DIRECT/127.0.0.1 text/html But i do have the denied access page, I can't download the .cab from the browser 1448445766.529 5 10.22.100.3 TCP_MISS/200 834 GET http://au.v4.download.windowsupdate.com/d/msdownload/update/software/updt/2013/12/windows8.1-kb2909569-x64_da69540676fbda6cd24305056220322b8ef91729.cab - HIER_DIRECT/127.0.0.1 text/html But i do have the denied access page, I can't download the .cab from the browser 1448445807.418 50 10.22.100.3 TCP_MISS/200 7450 GET http://v4.download.windowsupdate.com/d/msdownload/update/others/2015/11/19457798_2c503230affa03a9d1065dbf33a681b0fd9a0176.cab - HIER_DIRECT/37.58.147.9 application/octet-stream No denied access page, I can download the .cab from the browser > To: squid-users@xxxxxxxxxxxxxxxxxxxxx > From: eliezer@xxxxxxxxxxxx > Date: Wed, 25 Nov 2015 10:25:23 +0200 > Subject: Re: squidguard and windows update > > What do you see in the access.log? There should be some "TCP_X/Y" value, > What is the value? > > Eliezer > > On 25/11/2015 10:07, Magic Link wrote: > > Hi, > > i block domains related to Windows Update with squidguard that I see in the sarg reports. Most of these domains are blocked like I want, but some of them are still in sarg-reports so users can download updates and I don't want this. > > Here are the urls still in sarg-reports : > > http://au.v4.download.windowsupdate.com/d/msdownload/update/software/secu/2015/10/windows8.1-kb3097997-x64_28a367b2325b96943065ae5e83b5979da8f1bb8d.cabhttp://au.ds.download.windowsupdate.com/c/msdownload/update/software/crup/2015/11/outlook-x-none_7e582fc36876ff7a05f286125b7823c0ddcd4e71.cabhttp://v4.download.windowsupdate.com/c/msdownload/update/others/2015/11/19460743_8a29f07cae571a85d60b3791a1525c681b85fe4a.cabhttp://au.v4.download.windowsupdate.com/c/msdownload/update/software/secu/2014/04/windows8.1-kb2962123-x64-express_c45186ad36998f29faa19cec54a46d3c7d25cd50.cab > > Strange thing is when I click on these urls, the squidguard deny page do appear ! But they are listed in sarg-reports in the "downloads" page. > > Here are the domains I block : > > download.windowsupdate.comau.download.windowsupdate.comupdate.microsoft.comupdate.microsoft.com.nsatc.netwindowsupdate.comwindowsupdate.microsoft.comds.download.windowsupdate.comdl.ws.microsoft.comau.v4.download.windowsupdate.comfg.v4.download.windowsupdate.combg1.v4.emdl.ws.microsoft.comofficecdn.microsoft.commarketplacecontent.windowsphone.comcdn.marketplacecontent.windowsphone.comfg.v4.b1.download.windowsupdate.comb1.download.windowsupdate.comv4.b1.download.windowsupdate.comaupl.v4.download.windowsupdate.comaq.v4.emdl.ws.microsoft.combg.ds.emdl.ws.microsoft.combg.v4.emdl.ws.microsoft.combg1.ds.emdl.ws.microsoft.combg1.v4.emdl.ws.microsoft.combg2.ds.emdl.ws.microsoft.combg2.v4.emdl.ws.microsoft.combg3.ds.emdl.ws.microsoft.combg3.v4.emdl.ws.microsoft.combg4.ds.emdl.ws.microsoft.combg4.v4.emdl.ws.microsoft.combg5.ds.emdl.ws.microsoft.combg5.v4.emdl.ws.microsoft.combg6.ds.emdl.ws.microsoft.combg6.v4.emdl.ws.microsoft.combg7.v4.emdl.ws.microsoft.comds.emdl.ws.microsoft.comfg.v4.emdl > .ws.microsoft.comv4.emdl.ws.microsoft.comds.emdl.ws.microsoft.comemdl.ws.microsoft.comws.microsoft.comcare.dlservice.microsoft.comfg.ds.b1.download.windowsupdate.comds.b1.download.windowsupdate.comb1.download.windowsupdate.com > > Do I miss some domains ? Do I have to put ip instead or add to this list ? > > Thank you ! > > > > _______________________________________________ > squid-users mailing list > squid-users@xxxxxxxxxxxxxxxxxxxxx > http://lists.squid-cache.org/listinfo/squid-users |
_______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users