<div dir="ltr"><div>I think, that it's not good solution too, but <a href="http://uploadXXX.files.mail.ru">uploadXXX.files.mail.ru</a> has about 100 servers.<br><br></div><div>Now i write small script on python, that creates a file with ip addresses of <a href="http://uploadXXX.files.mail.ru">uploadXXX.files.mail.ru</a>.<br><br></div><div>Script and list of ip addresses in attachment.<br></div></div><div class="gmail_extra"><br><div class="gmail_quote">On 13 February 2015 at 22:32, Yuri Voinov <span dir="ltr"><<a href="mailto:yvoinov@gmail.com" target="_blank">yvoinov@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><span class="">-----BEGIN PGP SIGNED MESSAGE-----<br>
Hash: SHA1<br>
<br>
</span>You have no bump whole .<a href="http://mail.ru" target="_blank">mail.ru</a> domain, which is contains minimum 40%<br>
and over overall traffic...... Not good solution.<br>
<br>
I think, be better to no bump only attachments servers.<br>
<br>
14.02.15 1:28, Dima Ermakov пишет:<br>
<span class="">> Thank you for your help, but your solution doesn't work on my<br>
> server. I have same error, but other ip addresses of<br>
> <a href="http://uploadXXX.mail.ru" target="_blank">uploadXXX.mail.ru</a> servers. Now I use: acl mail_ru dstdomain<br>
> .<a href="http://mail.ru" target="_blank">mail.ru</a> ssl_bump none mail_ru<br>
><br>
><br>
> Good day!<br>
><br>
> On 13 February 2015 at 21:37, Yuri Voinov <<a href="mailto:yvoinov@gmail.com">yvoinov@gmail.com</a>><br>
> wrote:<br>
><br>
</span><div><div class="h5">> Dmitry,<br>
><br>
> you need to pass <a href="http://mail.ru" target="_blank">mail.ru</a> attachments servers as dst no bump ACL's<br>
> to work.<br>
><br>
> In my configuration I use following workaround:<br>
><br>
> squid.conf:<br>
><br>
> # Only ip-based dst acl! acl dst_nobump dst<br>
> "/usr/local/squid/etc/dst.nobump"<br>
><br>
> # SSL bump rules sslproxy_cert_error allow all ssl_bump none<br>
> localhost ssl_bump none url_nobump ssl_bump none dst_nobump<br>
> ssl_bump server-first net_bump<br>
><br>
> (squid 3.4.11)<br>
><br>
> dst.nobump contents contains:<br>
><br>
> # Attachments Mail.ru <a href="http://94.100.180.215/32" target="_blank">94.100.180.215/32</a> <a href="http://94.100.180.216/32" target="_blank">94.100.180.216/32</a><br>
> <a href="http://217.69.139.215/32" target="_blank">217.69.139.215/32</a> <a href="http://217.69.139.216/32" target="_blank">217.69.139.216/32</a> <a href="http://217.69.139.126/32" target="_blank">217.69.139.126/32</a><br>
><br>
> That's all. Works for me.<br>
><br>
> Hope this helps.<br>
><br>
> WBR, Yuri<br>
><br>
> 14.02.15 0:32, Dima Ermakov пишет:<br>
>>>> Good day!<br>
>>>><br>
>>>> I have a problem with squid proxy in intercept ssl_bump<br>
>>>> mode.<br>
>>>><br>
>>>> If I want to attach big file (>25MB) to my e-mail message on<br>
>>>> <a href="https://mail.ru" target="_blank">https://mail.ru</a> web site, I have error "Can not upload<br>
>>>> file".<br>
>>>><br>
>>>> Into access.log I have errors: TCP_MISS_ABORTED/000<br>
>>>><br>
>>>> My squid configuration, access.log, cache.log in attachment.<br>
>>>> Thank you!<br>
>>>><br>
>>>><br>
>>>><br>
>>>> _______________________________________________ squid-users<br>
>>>> mailing list <a href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
>>>> <a href="http://lists.squid-cache.org/listinfo/squid-users" target="_blank">http://lists.squid-cache.org/listinfo/squid-users</a><br>
>>>><br>
>> _______________________________________________ squid-users<br>
>> mailing list <a href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
>> <a href="http://lists.squid-cache.org/listinfo/squid-users" target="_blank">http://lists.squid-cache.org/listinfo/squid-users</a><br>
>><br>
><br>
><br>
><br>
><br>
><br>
> _______________________________________________ squid-users mailing<br>
> list <a href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
> <a href="http://lists.squid-cache.org/listinfo/squid-users" target="_blank">http://lists.squid-cache.org/listinfo/squid-users</a><br>
><br>
-----BEGIN PGP SIGNATURE-----<br>
Version: GnuPG v2<br>
<br>
</div></div>iQEcBAEBAgAGBQJU3lEwAAoJENNXIZxhPexGuFgH/i//Is36huA3zIdvC8cAKLU1<br>
feLbkiTnbMsvUDE7NfbCgkByguc4qt0/xcbke2HshpXVJQON79C4BG5LVunTPg61<br>
N+c3nxNXJIWYmSXJFytfXQNtj8dI6SOav7//IvmNXpgBK/KVTXOhGdS5+E61IM20<br>
32MJ3GpDs1BtEcOTseTbHEYiJ+St6zq0DhMd5sA7tWU+zYpo/6aTpeP3VMO4/hjW<br>
IE/AA8AQIc11WLizX3GxVYt08umGIhyZ9jM8ISUjZJ4Dcijo5Ku6ixf44ZwKeWot<br>
x5gpjE1iOyxzSJ6zjsxADeyKumgTdiTmiQw/Zwpo3rvj8xyktBphEip5mV6jrIk=<br>
=kIDJ<br>
<div class="HOEnZb"><div class="h5">-----END PGP SIGNATURE-----<br>
_______________________________________________<br>
squid-users mailing list<br>
<a href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br>
<a href="http://lists.squid-cache.org/listinfo/squid-users" target="_blank">http://lists.squid-cache.org/listinfo/squid-users</a><br>
</div></div></blockquote></div><br><br clear="all"><br>-- <br><div class="gmail_signature"><div dir="ltr">С уважением, Дмитрий Ермаков.<br></div></div>
</div>