On 9/01/20 10:22 pm, netadmin wrote: > I try to use the configuration given in the previous post FYI: this post started a brand new thread, there is no previous post visible to us. Please provide a direct reference to the post and/or config file in question. > with: Squid 4.9 and > Sophos SAVDI 2.6. > If I download a virus file, the Squid sends the file for scanning and is > detected by Sophos SAVDI (I find it in logs) but it is not blocked by Squid > (I can download it). > The problem I think is in the response received by the Squid after the scan > but I do not know where. > Has anyone managed to make this solution functional? > I assume the config uses the AV software as an ICAP service? That has been made working by many AFAIK, with several different AV software. It is most likely that the ICAP service is either telling Squid it can start delivering the response early before it finds the virus payload. Or, producing the wrong response and thus causing Squid to deliver the content. To help we are likely to need your squid.conf details, the access.log entries that show the transaction(s) you know are wrong, and the icap.log content. Amos _______________________________________________ squid-users mailing list squid-users@xxxxxxxxxxxxxxxxxxxxx http://lists.squid-cache.org/listinfo/squid-users