#41
![]()
Igorn
-

- Dr.Web Staff
-

- 475 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:00
Почему при загрузке тестового трояна c расширением .exe он дает его скачать ?
В логе смотрели?
- Наверх
#42
![]()
Igorn
Igorn
-

- Dr.Web Staff
-

- 475 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:18
Как вариант — может быть, он закешировался у сквида, когда Вы защиту отключали
- Наверх
#43
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:21
не успел нарадоваться как он снова отрубился последний кусок в логе messages
[root@proxy log]# tail -f /var/log/messages
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/dwn70002.vdb with 1729 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/dwn70001.vdb with 1523 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/dwn70000.vdb with 1805 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/drwrisky.vdb with 26456 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/drwnasty.vdb with 74279 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: loaded virus base /var/drweb/bases/dwp70000.vdb with 1 viruses
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG drw_get_virus_num: total viruses: 4522716
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG Closing fd 5
Oct 3 16:14:46 proxy drweb-icapd [13094]: DEBUG fcntl: successfully set O_NONBLOCK for fd 3
Oct 3 16:14:46 proxy drweb-icapd [13094]: INFO Start Dr.Web ® icapd ver 6.0.2.3
странно но сейчас он процессах висит , но squid уже ошибку вываливает что icap сервер недоступен
drweb 13094 0.0 0.0 93296 1088 ? Ss 16:14 0:00 /opt/drweb/drweb-icapd.real
сама ошибка вот такая
Сообщение было изменено parel77: 03 Октябрь 2013 — 15:25
- Наверх
#44
![]()
Igorn
Igorn
-

- Dr.Web Staff
-

- 475 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:25
Давайте целиком лог (можно теперь не с 29 сентября, а только сегодняшний)
- Наверх
#45
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:53
Давайте целиком лог (можно теперь не с 29 сентября, а только сегодняшний)
блин лог огроменный не могу даже открыть и отредактировать
- Наверх
#46
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 03 Октябрь 2013 — 15:58
- Наверх
#47
![]()
Igorn
Igorn
-

- Dr.Web Staff
-

- 475 Сообщений:
Member
Отправлено 04 Октябрь 2013 — 12:13
Судя по этому логу, теперь изначальной проблемы (Oct 1 12:44:23 proxy drweb-icapd [20657]: ERROR pselect: Нет дочерних процессов) нет:
root@igorn-Ubuntu:/!LOG# grep pselect messages
Oct 1 09:22:57 proxy drweb-icapd [1384]: ERROR pselect: Нет дочерних процессов
Oct 1 12:44:23 proxy drweb-icapd [20657]: ERROR pselect: Нет дочерних процессов
Oct 2 15:35:31 proxy drweb-icapd [13300]: ERROR pselect: Нет дочерних процессов
- Наверх
#48
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 04 Октябрь 2013 — 14:14
Судя по этому логу, теперь изначальной проблемы (Oct 1 12:44:23 proxy drweb-icapd [20657]: ERROR pselect: Нет дочерних процессов) нет:
root@igorn-Ubuntu:/!LOG# grep pselect messages
Oct 1 09:22:57 proxy drweb-icapd [1384]: ERROR pselect: Нет дочерних процессов
Oct 1 12:44:23 proxy drweb-icapd [20657]: ERROR pselect: Нет дочерних процессов
Oct 2 15:35:31 proxy drweb-icapd [13300]: ERROR pselect: Нет дочерних процессов
если так , у меня такое ощущение что апдейтер gjcksftn сигнал hup icapd процессу
я все поставил с репозитариев
- Наверх
#49
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 04 Октябрь 2013 — 14:29
симпотомы такие .. Я запускаю весь комплекс все работает . Но спустя некоторое время выпадает
- Наверх
#50
![]()
Igorn
Igorn
-

- Dr.Web Staff
-

- 475 Сообщений:
Member
Отправлено 04 Октябрь 2013 — 14:34
А можете временно перевести proxy в standalone-режим ( отключить от ЕС-сервера) и понаблюдать? Судя по логу, у Вас там до сих пор присутствует и локальный ключ (drweb32.key). В ЕС-режиме этот ключ не требуется.
- Наверх
#51
![]()
parel77
parel77
-

- Posters
- 111 Сообщений:
Member
Отправлено 04 Октябрь 2013 — 15:40
А можете временно перевести proxy в standalone-режим ( отключить от ЕС-сервера) и понаблюдать? Судя по логу, у Вас там до сих пор присутствует и локальный ключ (drweb32.key). В ЕС-режиме этот ключ не требуется.
хорошо отключу от ЕС сервера
- Наверх
#52
![]()
volcano
volcano
-

- Posters
- 7 Сообщений:
Newbie
Отправлено 08 Апрель 2015 — 16:50
не нашлось решение этой проблемы? столкнулся с тем же самым, кто-то может подсказать как поправить?
- Наверх
#53
![]()
maxic
maxic
-

- Moderators
- 12 659 Сообщений:
Keep yourself alive
Отправлено 08 Апрель 2015 — 18:49
volcano, некропостинг — зло. Создавайте свою тему.
- Наверх
Не хочет с-icap почему-то принимать соединения.
сквид 3.1.10 и c-icap-060708_2,1 из портов
конфиги
Код: Выделить всё
cat squid.conf
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl localnet src 192.168.84.0/24
acl localnet src 192.168.85.0/24
acl SSL_ports port 443
acl SSL_ports port 8443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localnet
http_access deny all
icp_access allow localnet
icp_access deny all
htcp_access allow localnet
htcp_access deny all
http_port 3128 transparent
hierarchy_stoplist cgi-bin ?
cache_dir ufs /storage/squidcache 4096 64 256
maximum_object_size 512 KB
access_log /var/log/squid/access.log squid
cache_log /var/log/squid/cache.log
icap_log /var/log/squid/icap.log
cache_store_log none
logfile_rotate 10
url_rewrite_program /usr/local/rejik/redirector /usr/local/etc/redirector.conf
url_rewrite_children 8
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern (cgi-bin|?) 0 0% 0
refresh_pattern . 0 20% 4320
visible_hostname server.local
icp_port 3130
icap_enable on
icap_preview_enable on
icap_preview_size 128
icap_send_client_ip on
icap_service service_avi_req reqmod_precache 0 icap://192.168.84.253/srv_clamav
icap_service service_avi respmod_precache 1 icap://192.168.84.253/srv_clamav
adaptation_service_set service_avi service_avi_req
adaptation_access service_avi allow all
adaptation_access service_avi_req allow all
икап, разрешено всем намеренно, в процессе поиска
Код: Выделить всё
cat c-icap.conf | grep -v '^#' | sed '/^$/d'
cat: c-icap.conf: No such file or directory
niko-gw# cd /usr/local/etc
niko-gw# cat c-icap.conf | grep -v '^#' | sed '/^$/d'
PidFile /var/run/c-icap.pid
CommandsSocket /var/run/c-icap/c-icap.ctl
Timeout 300
KeepAlive On
MaxKeepAliveRequests 600
KeepAliveTimeout 600
StartServers 3
MaxServers 10
MinSpareThreads 10
MaxSpareThreads 20
ThreadsPerChild 10
MaxRequestsPerChild 0
Port 1344
User cicap
Group cicap
TmpDir /tmp/
MaxMemObject 131072
ServerLog /var/log/c_icap/server.log
AccessLog /var/log/c_icap/access.log
DebugLevel 1
ModulesDir /usr/local/lib/c_icap
Module logger sys_logger.so
sys_logger.Prefix "C-ICAP:"
sys_logger.Facility local1
Logger sys_logger
acl squid_respmod src 192.168.84.0/255.255.255.0 type respmod
acl squid_options src 192.168.84.0/255.255.255.0 type options
acl any src 0.0.0.0/0.0.0.0
icap_access allow squid_respmod
icap_access allow squid_options
icap_access allow any
ServicesDir /usr/local/lib/c_icap
Service echo_module srv_echo.so
Service url_check_module srv_url_check.so
Service antivirus_module srv_clamav.so
ServiceAlias avscan srv_clamav?allow204=on&sizelimit=off&mode=simple
srv_clamav.ScanFileTypes TEXT DATA EXECUTABLE ARCHIVE GIF JPEG MSOFFICE
srv_clamav.SendPercentData 5
srv_clamav.StartSendPercentDataAfter 2M
srv_clamav.MaxObjectSize 5M
srv_clamav.ClamAvTmpDir /tmp/
srv_clamav.ClamAvMaxFilesInArchive 0
srv_clamav.ClamAvMaxFileSizeInArchive 100M
srv_clamav.ClamAvMaxRecLevel 5
srv_clamav.VirSaveDir /var/infected
srv_clamav.VirHTTPServer "DUMMY"
srv_clamav.VirUpdateTime 15
srv_clamav.VirScanFileTypes ARCHIVE EXECUTABLE
tcpdump обмена прокси и с-icap
Код: Выделить всё
tcpdump -npi tap0 port 1344
tcpdump: WARNING: tap0: no IPv4 address assigned
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on tap0, link-type EN10MB (Ethernet), capture size 96 bytes
12:32:31.157214 IP 192.168.84.254.34482 > 192.168.84.253.1344: Flags [S], seq 1466692851, win 65535, options [mss 1337,nop,wscale 3,sackOK,TS val 136294970 ecr 0], length 0
12:32:31.157389 IP 192.168.84.253.1344 > 192.168.84.254.34482: Flags [S.], seq 187600070, ack 1466692852, win 65535, options [mss 1337,nop,wscale 3,sackOK,TS val 2911239331 ecr 136294970], length 0
12:32:31.161123 IP 192.168.84.254.34482 > 192.168.84.253.1344: Flags [.], ack 1, win 8281, options [nop,nop,TS val 136294972 ecr 2911239331], length 0
12:32:31.161536 IP 192.168.84.254.34482 > 192.168.84.253.1344: Flags [F.], seq 1, ack 1, win 8281, options [nop,nop,TS val 136294972 ecr 2911239331], length 0
12:32:31.161681 IP 192.168.84.253.1344 > 192.168.84.254.34482: Flags [.], ack 2, win 8281, options [nop,nop,TS val 2911239336 ecr 136294972], length 0
12:32:31.162434 IP 192.168.84.253.1344 > 192.168.84.254.34482: Flags [F.], seq 1, ack 2, win 8281, options [nop,nop,TS val 2911239336 ecr 136294972], length 0
12:32:31.163591 IP 192.168.84.254.34482 > 192.168.84.253.1344: Flags [.], ack 2, win 8281, options [nop,nop,TS val 136294977 ecr 2911239336], length 0
Сквид в браузер пишет:
Код: Выделить всё
При получении URL http://dealextreme.com/ произошла следующая ошибка
Ошибка протокола ICAP.
Система вернула: [No Error]
Это означает, что какой-то этап связи по протоколу ICAP не удался.
Возможные проблемы:
Сервер ICAP недоступен
Получен недопустимый ответ от сервера ICAP.
Запуска c-icap в отладке:
Код: Выделить всё
c-icap -D -N -d 10
Enabling parameter -D
Disabling parameter -N
Setting parameter :-d=10
Searching 0x805d02c for default value
Setting parameter :PidFile=/var/run/c-icap.pid
Searching 0x805d030 for default value
Setting parameter :CommandsSocket=/var/run/c-icap/c-icap.ctl
Searching 0x805d050 for default value
Setting parameter :Timeout=300
Searching 0x805d058 for default value
Setting parameter :MaxKeepAliveRequests=600
Searching 0x805d054 for default value
Setting parameter :KeepAliveTimeout=600
Searching 0x805d060 for default value
Setting parameter :StartServers=3
Searching 0x805d064 for default value
Setting parameter :MaxServers=10
Searching 0x805d06c for default value
Setting parameter :MinSpareThreads=10
Searching 0x805d070 for default value
Setting parameter :MaxSpareThreads=20
Searching 0x805d068 for default value
Setting parameter :ThreadsPerChild=10
Searching 0x805d864 for default value
Setting parameter :MaxRequestsPerChild=0
Searching 0x805d020 for default value
Setting parameter :Port=1344
Searching 0x805d034 for default value
Setting parameter :User=cicap
Searching 0x805d038 for default value
Setting parameter :Group=cicap
Searching 0x805d028 for default value
Setting parameter :TmpDir=/tmp/
Searching 0x805d844 for default value
Setting parameter :MaxMemObject=131072
Searching 0x805d3d0 for default value
Setting parameter :ServerLog=/var/log/c_icap/server.log
Searching 0x805d3d4 for default value
Setting parameter :AccessLog=/var/log/c_icap/access.log
Searching 0x805d85c for default value
Setting parameter :DebugLevel=1
Setting parameter :ModulesDir=/usr/local/lib/c_icap
Loading service :logger path sys_logger.so
Going to search variable Prefix in table sys_logger
Setting parameter :Prefix=C-ICAP:
Going to search variable Facility in table sys_logger
Setting parameter :Logger=sys_logger
Setting parameter :ServicesDir=/usr/local/lib/c_icap
Loading service :echo_module path srv_echo.so
Found handler C_handler for service with extension:.so
Loading service :url_check_module path srv_url_check.so
Found handler C_handler for service with extension:.so
Initialization of url_check module......
Loading service :antivirus_module path srv_clamav.so
Found handler C_handler for service with extension:.so
Alias:avscan of service srv_clamav
Going to search variable ScanFileTypes in table srv_clamav
Iam going to scan data for simple scanning of type:,GIF,JPEG,MSOFFICE,TEXT,DATA,EXECUTABLE,ARCHIVE
Going to search variable SendPercentData in table srv_clamav
Setting parameter :SendPercentData=5
Going to search variable StartSendPercentDataAfter in table srv_clamav
Setting parameter :StartSendPercentDataAfter=2097152
Going to search variable MaxObjectSize in table srv_clamav
Setting parameter :MaxObjectSize=5242880
Going to search variable ClamAvTmpDir in table srv_clamav
Setting parameter :ClamAvTmpDir=/tmp/
Going to search variable ClamAvMaxFilesInArchive in table srv_clamav
Setting parameter :ClamAvMaxFilesInArchive=0
Going to search variable ClamAvMaxFileSizeInArchive in table srv_clamav
Setting parameter :ClamAvMaxFileSizeInArchive=104857600
Going to search variable ClamAvMaxRecLevel in table srv_clamav
Setting parameter :ClamAvMaxRecLevel=5
Going to search variable VirSaveDir in table srv_clamav
Setting parameter :VirSaveDir=/var/infected
Going to search variable VirHTTPServer in table srv_clamav
Setting parameter :VirHTTPServer=DUMMY
Going to search variable VirUpdateTime in table srv_clamav
Setting parameter :VirUpdateTime=15
Going to search variable VirScanFileTypes in table srv_clamav
Iam going to scan data for vir_mode scanning of type:,EXECUTABLE,ARCHIVE
My hostname is:niko-gw.o56.ru
Вс это вываливается при запуске, в момент обращения к сквиду — ничо больше не пишет
Хотя си-икап виси и слушает порт:
Код: Выделить всё
cicap c-icap 95318 3 tcp4 *:1344 *:*
cicap c-icap 95318 4 dgram -> /var/run/logpriv
cicap c-icap 95317 3 tcp4 *:1344 *:*
cicap c-icap 95317 4 dgram -> /var/run/logpriv
cicap c-icap 95316 3 tcp4 *:1344 *:*
cicap c-icap 95316 4 dgram -> /var/run/logpriv
cicap c-icap 95315 3 tcp4 *:1344 *:*
cicap c-icap 95315 4 dgram -> /var/run/logpriv
Proto Recv-Q Send-Q Local Address Foreign Address (state)
tcp4 0 0 *.1344 *.* LISTEN
This topic has been deleted. Only users with topic management privileges can see it.
-
Pfsense 2.1.3 32-bit
Ram 4 GB
HDD 128 GB SSD
CPU AMD Athlon 3400+ 64-bit
1 Wan
1 LanPackages:
pfBlocker 1.0.2
Squid3-dev 3.3.10 pkg 2.2.2I am using Squid3-dev with antivirus and SSL enabled. Works very well, but often it will give this error:
ICAP Protocol Error, with a «no error» error code
ERROR in the browser
The following error was encountered while trying to retrieve the URL: http://google.com
ICAP protocol error.The system returned: [No Error]
This means that some aspect of the ICAP communication failed.
Some possible problems are:
*
The ICAP server is not reachable.
*An Illegal response was received from the ICAP server.
The only way to fix it is to restart squid.
I have read here: http://squidclamav.darold.net/tuning.html that changing some variables might help. I have doubled the default amounts described on the darold.net page, but it does not seem to help. Does anyone have any hints on what to look at next? This page also mentions that this works «with bypass enabled» — any idea what that means?
Thanks!
-
Potentially solved… the «bypass» feature can be added in the squid.inc file, as the squid.conf gets overwritten. I’m not sure about adding it to the Custom fields in the GUI — maybe that would work(?), but I opted for the .inc edit instead.
I also modified the other c-icap.conf file options that are relevant to these ICAP errors as stated on the developer’s site. I ended up tripling the values before turning on the bypass=1 feature. I might reduce the numbers now to double only, given that bypass seems to be working. Clamav is presently running multiple processes and using (?) 600 MB of RAM, but I may not be reading the system activity correctly.
So far, no ICAP error since turning bypass on. Apparently, squid will ignore errors generated by ICAPs and not pass it on to the browser. I’m not sure if this breaks clamav for some period. Squid3-dev is definately not for the ultra green ;D
-
Hi MIT, can you please show how you fixed it step by step?
Thanks.
-
Same problem…64-bit system here. ICAP problems start as soon as I enable antivirus in Squid interface. I tried the «bypass»trick and it works but I think it completely breaks the antivirus feature. I tested the same on EICAR test file and another test website; the antivirus didn’t show any warning.
So…that basically kills the purpose!
-
@golmaal:
Same problem…64-bit system here. ICAP problems start as soon as I enable antivirus in Squid interface. I tried the «bypass»trick and it works but I think it completely breaks the antivirus feature. I tested the same on EICAR test file and another test website; the antivirus didn’t show any warning.
So…that basically kills the purpose!
Strange.. I conitnue to have eicar blocking both http/https with bypass
-
@Bismarck:
Hi MIT, can you please show how you fixed it step by step?
Thanks.
In pfsense web gui…
For the bypass feature….
Go to Diagnostics > edit file
Browse to /usr/local/pkg
Load squid.inc
modify these two lines:icap_service service_req reqmod_precache bypass=0 icap://127.0.0.1:1344/squidclamav
icap_service service_resp respmod_precache bypass=0 icap://127.0.0.1:1344/squidclamavTO THIS:
icap_service service_req reqmod_precache bypass=1 icap://127.0.0.1:1344/squidclamav
icap_service service_resp respmod_precache bypass=1 icap://127.0.0.1:1344/squidclamavSave file.
Then I rebooted. Done
I ended up changing everyhing in the C-icap parameters back to the defaults (so you need not change those, found on the Antivurs tab of Squid3-dev) same goes for clam.conf, changed back to defaults. Only the bypass=1 change was needed and no more ICAP error. I have tested with EICAR and it continues to stop those everytime in http and https.
Good luck 😉
-
Does it work with squidguard included in the equation too. I tried but didn’t work.
-
@exograpix:
Does it work with squidguard included in the equation too. I tried but didn’t work.
I don’t use squidguard, so I am no help on that one.
-
I’ve got the same problem on PFSense 2.1.4-RELEASE (amd64)
Enabling debug on squid, I’ve seen the following messages :
2014/07/11 10:36:29.862 kid1| url.cc(386) urlParse: urlParse: Split URL ‘icap://127.0.0.1:1344/squidclamav ICAP/1.0
‘ into proto=’icap’, host=’127.0.0.1′, port=’1344′, path=’/squidclamav ICAP/1.0′
2014/07/11 10:36:29.862 kid1| url.cc(422) urlParse: urlParse: URI has whitespace: {icap://127.0.0.1:1344/squidclamav ICAP/1.0
RESPMOD icap://127.0.0.1:1344/squidclamav ICAP/1.0
ICAP/1.0 204 Unmodified
Server: C-ICAP/0.2.5
2014/07/11 10:36:29.869 kid1| ModXact.cc(742) parseHeaders: parse ICAP headers
2014/07/11 10:36:29.869 kid1| Xaction.cc(503) setOutcome: ICAP_ERR_OTHER
2014/07/11 10:36:29.870 kid1| Server.cc(828) handleAdaptationAborted: creating ICAP error entry after ICAP failure
2014/07/11 10:36:29.870 kid1| forward.cc(397) fail: ERR_ICAP_FAILURE «Internal Server Error»It seems the url used to contact ICAP server is malformed (there is a whitespace in it).
-
Sorry to necro this…
Has anyone found a solution to this? I get this same error message and if the issue is a malformed url in a config file, which one is it?
-
Thanks MIT for the details, however in squid 3.4.10_2 pkg 0.2.6 there are changes in the squid.inc file.
it’s like this:
icap_service service_avi_req reqmod_precache icap://[::1]:1344/squid_clamav bypass=off
adaptation_access service_avi_req allow all
icap_service service_avi_resp respmod_precache icap://[::1]:1344/squid_clamav bypass=on
adaptation_access service_avi_resp allow alli changed the squid_clamav bypass=off to on and the eicar detection is working.
thank you again 🙂
-
As I’ve posted on other many squid3 topics, clamav integration will work if you:
-
Enable antivirus on squid
-
fix config warnings alerts
-
wait first freshclam to finish
-
stop and start (not restart) squid and c-icap service
Configure a clamav bypass has the same effect as disabling the antivirus integration.
I’ve tested it on amd64 at least 3 times and had a working on all tests.
-
-
Can you fix the default config so that it works by default. While the GUI does tell you what to do if you save the page again, I’m sure that a lot of people on the forum and irc having issues with Squid do not go back there and save the page a second time.
-
@fragged:
Can you fix the default config so that it works by default. While the GUI does tell you what to do if you save the page again, I’m sure that a lot of people on the forum and irc having issues with Squid do not go back there and save the page a second time.
Decide what ip to use on sarg reports warn_php for example is not that simple. If I force Lan IP on package config then somebody will ask to listen on WLAN and/or internal http server.
This is a first run configuration. Once configured, you do not need to check again antivurus options.
-
I have this problem on the 64 bit version RC 2.2 and I just go to the antivirus page and click save again and then the system comes back up .. but wish it stop messing up
-
Friends, help, please, how to solve a problem with this error ICAP?
Configuring a clamav bypass=1 is disabling the antivirus integration!
PFsense 2.1.5 x64, squid 3.3.10 -
Did you read the topic first?
https://forum.pfsense.org/index.php?topic=77264.msg485524#msg485524
-
@marcelloc:
Did you read the topic first?
https://forum.pfsense.org/index.php?topic=77264.msg485524#msg485524Friend, yes, I read it. But to my regret, I didn’t understand part of instructions:
fix config warnings alerts
wait first freshclam to finish
Please, explain more in detail which needs to be made here.
Thanks! -
Antonio, don’t waste your time in pfSense 2.1.5 x64 i-cap ist still broken there, since it has never worked before.
I guess you need to upgrade to pfSense 2.2 x64 to get it work, if I get marcelloc right?
fix config warnings alerts = look in Status: System logs: General for errors and fix it
wait first freshclam to finish = execute freshclam in the console/shell and watch via top till its finished
Good luck.
-
Error in system log (PFsense 2.1.5 x64, squid 3.3.10):
kernel: pid 85487 (c-icap), uid 9595: exited on signal 11It is possible to fix it, or it really nonremovable error in 2.1.5 x64 in ICAP?
I don’t like 2.2. With it I have many more problems with Squid+SquidGuard+Lightsquid. May be later, build of PFsense will be stable and I update it. -
@Antonio_Grande:
It is possible to fix it, or it really nonremovable error in 2.1.5 x64 in ICAP?
Unfortunatelly no. the icap error are related to freebsd 8.x and icap, not pfsense itself. the same compile args and config options works fine on freebsd 8.x 32bit version.
An workaround for pfsense 2.1.x 64bits if you are not using ssl interception is to use clamav on dansguardian ou havp.
-
I am receiving ICAP errors with squid3 on amd64 pfSense 2.2 but only on http sites. I think I must have something misconfigured because HTTPS is fine. How does one use HAVP with squid, I feel like I have too many redundant proxies with HAVP and Dansguardian.
-
I was having a similar problem until I saw this: https://forum.pfsense.org/index.php?topic=87424.msg480232#msg480232
fresh 2.2 install
Install squid3
…
chech squid tabs, save, fix config options pointed by gui alerts
On antivirus tab, save config twice as first time it will load sample files and second check config options.
via console wait (repeating ps ax | grep -i fresclam or tail -f /var/log/clamav/freshclam.log) clamav database first slow update
enable transparent mode(do not select loopback on any squid option)
stop and start squid via gui to force c-icap to restart too after first freshclam.
…Edited original post to describe my steps. The key part is the «save twice» on the AV tab. Fix the problems presented, each has its solution right in the message. I am now able to browse HTTP sites without the ICAP errors.
-
$ repeating ps ax | grep -i freshclam or tail -f /var/log/clamav/freshclam.log grep: freshclam: No such file or directory grep: or: No such file or directory grep: tail: No such file or directoryFor some reason I can’t freshclam
-
@jvamos:
$ repeating ps ax | grep -i freshclam or tail -f /var/log/clamav/freshclam.logThis line means
repeat this cmd on console every 30 seconds for example
ps ax | grep -i freshclamor this one once
tail -f /var/log/clamav/freshclam.log -
I think I just typed «freshclam» (without quotes) to update, as marcelloc says the other commands are to show the status of freshclam, not to execute it.
-
HI, Guys
I got errors:
ERROR
The requested URL could not be retrievedThe following error was encountered while trying to retrieve the URL: http://www.google.ca
Connection to 127.0.0.1 failed.
The system returned: (60) Operation timed out
The remote host or network may be down. Please try the request again.
Your cache administrator is admin@localhost.
ERROR
The requested URL could not be retrievedThe following error was encountered while trying to retrieve the URL: http://www.dslreports.com/forum/rogers
Unable to forward this request at this time.
This request could not be forwarded to the origin server or to any parent caches.
Some possible problems are:
An Internet connection needed to access this domains origin servers may be down.
All configured parent caches may be currently unreachable.
The administrator may not allow this cache to make direct connections to origin servers.Your cache administrator is admin@localhost.
I only installed snort, pfBlokerNG, and squid3, for Squid3, all the settings were setup by default, changed squid.inc, changed anti-virus configs, and execute freshclam, but I got above odd errors, can’t surf internet unless turn off the transparent HTTP proxy.
What am I doing wrong?
-
Olá,
Caso alguém ainda esteja com problemas. Segue abaixo como funcionou em minha rede:
Pfsense 2.2.3 + Squid3 0.2.8 + SquidGuard 1.9.14 + i-cap/clamav
Defina em squidclamav.conf:
redirect http://IP_SEU_SERVIDOR/squid_clwarn.php
Para o caso de possuir SquidGuard, descomente a linha:
squidguard /usr/local/squidGuard/bin/squidGuard
Adicione em i-cap.conf:
Service squid_clamav squidclamav.so
Apague essa linha de i-cap.conf(Mesmo que esteja comentada):
ldap://cn=Directory Manager:Apassword@ldap.chtsanti.net?o=chtsanti?mermberUid?(&(objectClass=posixGroup)(cn=%s))
Pra mim está funcionando ok.
I hope it helps someone. ;D
-
Just add domain in Whitelist with http and you`r issue will solve.
-
@mit the path is /usr/local/pkg/squid_antivirus.inc not squid.inc for latest pfsense 2.6 squid 0.4.45_9
I am trying to run squid (version 4.1) with squidclamav. This used to work fine but broke with an update to the current c-icap (0.5.5) version. When I try to access a webpage, I get the following error:
Code:
The following error was encountered while trying to retrieve the URL: http://www.eicar.com/
ICAP protocol error.
The system returned: [No Error]
This means that some aspect of the ICAP communication failed.
Some possible problems are:
- The ICAP server is not reachable.
- An Illegal response was received from the ICAP server.
The c-icap server is however running:
Code:
/usr/local/bin/c-icap-client -i 127.0.0.1 -p 1344 -d 10
OK done with options!
ICAP server:127.0.0.1, ip:127.0.0.1, port:1344
OPTIONS:
Allow 204: Yes
Preview: 1024
Keep alive: Yes
ICAP HEADERS:
ICAP/1.0 200 OK
Methods: RESPMOD, REQMOD
Service: C-ICAP/0.5.5 server - Echo demo service
ISTag: CI0001-XXXXXXXXX
Transfer-Preview: *
Options-TTL: 3600
Date: Sun, 21 Oct 2018 18:56:34 GMT
Preview: 1024
Allow: 204
X-Include: X-Authenticated-User, X-Authenticated-Groups
Encapsulated: null-body=0
I am not sure what is causing the issue. The redirect in the
squid.conf
looks like this:
Code:
icap_enable on
icap_send_client_ip on
icap_send_client_username on
icap_client_username_encode off
icap_client_username_header X-Authenticated-User
icap_preview_enable on
icap_preview_size 1024
adaptation_send_client_ip on
adaptation_send_username on
icap_service squidclamav1 reqmod_precache icap://127.0.0.1:1344/squidclamav bypass=0
icap_service squidclamav2 respmod_precache icap://127.0.0.1:1344/squidclamav bypass=0
adaptation_service_chain svcRequest squidclamav1
adaptation_service_chain svcResponse squidclamav2
adaptation_access svcRequest allow all
adaptation_access svcResponse allow all
Really appreciate any ideas what might help.
Thank you
Доброго времени суток!
Пытаюсь настроить связку sqiud (3.3.8) и c-icap (0.3.3).
Сам с-icap работает:
Код:
root@icapSRV:/usr/local/c-icap/bin# ./c-icap-client
ICAP server:localhost, ip:127.0.0.1, port:1344
OPTIONS:
Allow 204: Yes
Preview: 1024
Keep alive: Yes
ICAP HEADERS:
ICAP/1.0 200 OK:
Methods:RESPMOD, REQMOD
Service:C-ICAP/0.3.3 server - Echo demo service
ISTag:CI0001-XXXXXXXXX
Transfer-Preview:*
Options-TTL:3600
Date:Wed, 04 Jun 2014 11:19:36 GMT
Preview:1024
Allow:204
X-Include:X-Authenticated-User, X-Authenticated-Groups
Encapsulated:null-body=0
А вот взаимодействия со сквидом нет.
c-icap.conf:
Код:
PidFile /var/run/c-icap/c-icap.pid
CommandsSocket /var/run/c-icap/c-icap.ctl
Timeout 300
MaxKeepAliveRequests 100
KeepAliveTimeout 600
StartServers 3
MaxServers 10
MinSpareThreads 10
MaxSpareThreads 20
ThreadsPerChild 10
MaxRequestsPerChild 0
Port 1344
ServerAdmin you@your.address
ServerName icapsrv
TmpDir /var/tmp
MaxMemObject 131072
DebugLevel 1
ModulesDir /usr/local/c-icap/lib/c_icap
ServicesDir /usr/local/c-icap/lib/c_icap
TemplateDir /usr/local/c-icap/share/c_icap/templates/
TemplateDefaultLanguage en
LoadMagicFile /usr/local/c-icap/etc/c-icap.magic
RemoteProxyUsers off
RemoteProxyUserHeader X-Authenticated-User
RemoteProxyUserHeaderEncoded on
acl ALLREQUESTS type OPTIONS RESPMOD REQMOD
acl localnet src 192.168.11.1
acl localhost src 127.0.0.1
icap_access allow ALLREQUESTS localnet
icap_access allow localhost
ServerLog /usr/local/c-icap/var/log/server.log
AccessLog /usr/local/c-icap/var/log/access.log
Service echo srv_echo.so
squid.conf:
Код:
acl mynetwork src 192.168.10.0/24 #Из этой подсети пользователи ломятся в интернет
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
http_access allow localhost
http_access allow mynetwork
http_access deny all
###
icap_enable on
icap_service service_req reqmod_precache bypass=1 icap://192.168.11.2:1344/request
adaptation_access service_req allow all
icap_service service_resp respmod_precache bypass=0 icap://192.168.11.2:1344/response
adaptation_access service_resp allow all
###
http_port 3129
http_port 3128 transparent
visible_hostname myproxy
cache_dir ufs /var/spool/squid3 4096 32 256
cache deny mynetwork
coredump_dir /var/spool/squid3
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320
error_directory /usr/share/squid3/errors/Russian-koi8-r
memory_pools on
memory_pools_limit 50 MB
Вот что говорит на это все squid:
Код: Выделить всё
blablabla
2014/06/04 17:04:45| WARNING: Squid got an invalid ICAP OPTIONS response from service icap://192.168.11.2:1344/request; error: unsupported status code of OPTIONS response
2014/06/04 17:04:45| optional ICAP service is down after an options fetch failure: icap://192.168.11.2:1344/request [down,!valid]
2014/06/04 17:04:45| WARNING: Squid got an invalid ICAP OPTIONS response from service icap://192.168.11.2:1344/response; error: unsupported status code of OPTIONS response
2014/06/04 17:04:45| optional ICAP service is down after an options fetch failure: icap://192.168.11.2:1344/response [down,!valid]
А вот это говорит c-icap:
Код: Выделить всё
04/Jun/2014:18:28:17 +0700, 192.168.11.2 192.168.11.1 OPTIONS request 404
04/Jun/2014:18:28:17 +0700, 192.168.11.2 192.168.11.1 OPTIONS response 404
Как я понял, они не могут договориться меж собой о конфигурации.
В чем я накосячил?