[squid-users] Squid vs WCCPv2

From: Yanis Sauvé <yanis.sauve_at_csjonquiere.qc.ca>
Date: Thu, 14 Jan 2010 15:51:26 -0500

(Reposted to the list, sorry...)

-----Message d'origine-----
De : Amos Jeffries [mailto:squid3_at_treenet.co.nz] Envoyé : 14 janvier 2010 04:44 À : Yanis Sauvé; Squid Objet : [squid-users] Re: RE : [squid-users] Squid vs WCCPv2 - Need help involving interpretation in Wireshark

Yanis Sauvé wrote:
>
> The packets I see in WS have my router's IP as source, and the cache
> server's as destination. WS shows the packet that's encapsulated in GRE.

Uhm, thats not what I recall seeing. You may need to check that they are being gre-decapsulated by iptables.

OKay, I'll be more descriptive, since I'm not sure anymore if the packets are decapsulated or not.

What I see in the packet list are the packets redirected, that is, src ports from clients, dst ports to servers on the net.

In the "description" pane, under it, I can see the router's ip as source, my cache server as destination. And under it, I can see the GRE encapsulation, with the original packet. Is it WS being smart and showing me in the encapsulated packet, or is the packet actually decapsulated and intercepted as is in WS?

The easy way is to set Squid debugging level "debug_options 5,6". When working you should be able to see the client connections being accept()ed by Squid.

Up to now, we haven't been able to see any activity in squid while redirecting packets.

Yanis

Yanis Sauvé
Technicien informatique
Commission scolaire De La Jonquière
@: yanis.sauve_at_csjonquiere.qc.ca
Received on Thu Jan 14 2010 - 20:51:34 MST

This archive was generated by hypermail 2.2.0 : Fri Jan 15 2010 - 12:00:02 MST