One of server's ip addresses that i've found belongs to cloudflare . Cloudflare does not accept anything other than HTTP on port 80 . So it seems an attack to some servers . Maybe our clients are infected and they are zombies . Anyone knows some good ways to defend squid . I mean when squid forwards these requests it becomes crazy . I manage to create some iptables rules on squid box to only accept http protocol . But i know it will have at least 2 problems . 1. Performance will be degraded 2. Some sites/apps may have problems Any suggestion ? -- View this message in context: http://squid-web-proxy-cache.1019090.n4.nabble.com/Squid-cpu-usage-100-from-few-days-ago-tp4678894p4678937.html Sent from the Squid - Users mailing list archive at Nabble.com. _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users