Solved

squid proxy

Posted on 2013-10-24
3
988 Views
Last Modified: 2013-11-16
I have squid proxy on suse enterprise linux 11.2, for some maintenance puposes i have to swap the proxy ip with Windows ISA server. after that my squid is not working,so i am getting the following error in my access log file and none of user is able to browse the internet.

1382609509.685 239818 172.16.225.203 TCP_CLIENT_REFRESH_MISS/504 0 GET http://dnl-07.geo.kaspersky.com/index/u0607g.xml.dif - DIRECT/130.117.190.137 text/html
1382609515.918   9913 172.16.225.203 TCP_MISS/000 0 CONNECT 62.213.110.174:443 - NONE/- -
one more thing i am getting the different dns records in nslookup query

while i checked in the dns server there is only one record against the proxy with the new ip but on the linux machine itself there are three records.I have cleared the cache uodated the dns record even restarted the proxy server but in vain.

40.0.16.172.in-addr.arpa        name = isa.abc.local
40.0.16.172.in-addr.arpa        name = proxy-web.abc.local.
40.0.16.172.in-addr.arpa        name = proxy-server.abc.local
0
Comment
Question by:kastro Abbasi
  • 2
3 Comments
 
LVL 13

Accepted Solution

by:
Daniel Helgenberger earned 500 total points
ID: 39599153
I am not sure if I get what you have done?
1 shutdown squid
2 swapped IPs with another proxy
3 start squid
4 swiched back IPs
All was working well until after step 4.

TCP_CLIENT_REFRESH_MISS/504
TCP/504 is a gateway timeout - can you confirm squid can connect to the requested site? Maybe someth. went wrong when switching IPs or something (firewall) is blocking squid? Maybe iptables?

Basic debug on the cache server:
curl http://dnl-07.geo.kaspersky.com/index/u0607g.xml.dif

Open in new window

0
 

Author Comment

by:kastro Abbasi
ID: 39601837
no i can not even browse on the proxy itself. But why i am geting the two records against this server updating the old records in dns server and clear the cache on this machine.
0
 
LVL 13

Expert Comment

by:Daniel Helgenberger
ID: 39601904
no i can not even browse on the proxy itself
What does this mean? Proxy has no wan connectivity?

There are many reasons why you could get those PTR's, most likely they are in the DNS you do your lookup against - and a left over from the IP switching. But don't worry, they to no harm and have nothing to do with your current problem. Consider cleaning up your reverse lookup zones to get rid of those PTRs.
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

​Being a Managed Services Provider (MSP) has presented you  with challenges in the past— and by meeting those challenges you’ve reaped the rewards of success.  In 2014, challenges and rewards remain; but as the Internet and business environment evol…
Google Drive is extremely cheap offsite storage, and it's even possible to get extra storage for free for two years.  You can use the free account 15GB, and if you have an Android device..when you install Google Drive for the first time it will give…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

828 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question