$ sudo cat /usr/local/etc/squid/acl/Blacklist1 | grep "livingsoilssymposium.ca"$ sudo cat /usr/local/etc/squid/acl/Blacklist1 | grep "107.180.24.240"$
2020-12-05T21:50:05 squid .066 kid1| 33,2| client_side.cc(586) swanSong: local=107.180.24.240:443 remote=10.63.19.139:59058 flags=332020-12-05T21:50:05 squid .066 kid1| 33,2| client_side.cc(895) kick: local=107.180.24.240:443 remote=10.63.19.139:59058 flags=33 Connection was closed2020-12-05T21:50:05 squid .057 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: 'ip-107-180-24-240.ip.secureserver.net' found2020-12-05T21:50:05 squid .057 kid1| 28,3| DomainData.cc(110) match: aclMatchDomainList: checking 'ip-107-180-24-240.ip.secureserver.net'2020-12-05T21:50:05 squid .057 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: '107.180.24.240' NOT found2020-12-05T21:50:05 squid .057 kid1| 28,3| DomainData.cc(110) match: aclMatchDomainList: checking '107.180.24.240'2020-12-05T21:50:05 squid .057 kid1| 28,3| RegexData.cc(43) match: checking '107.180.24.240:443'2020-12-05T21:50:05 squid .057 kid1| 28,3| RegexData.cc(43) match: checking '107.180.24.240:443'2020-12-05T21:50:05 squid .056 kid1| 33,2| client_side.cc(2742) httpsSslBumpAccessCheckDone: sslBump action peekneeded for local=107.180.24.240:443 remote=10.63.19.139:59058 FD 1097 flags=332020-12-05T21:50:04 squid .565 kid1| 33,2| client_side.cc(586) swanSong: local=107.180.24.240:443 remote=10.63.19.139:59056 flags=332020-12-05T21:50:04 squid .565 kid1| 33,2| client_side.cc(895) kick: local=107.180.24.240:443 remote=10.63.19.139:59056 flags=33 Connection was closed2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: 'ip-107-180-24-240.ip.secureserver.net' found2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(110) match: aclMatchDomainList: checking 'ip-107-180-24-240.ip.secureserver.net'2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: '107.180.24.240' NOT found2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(110) match: aclMatchDomainList: checking '107.180.24.240'2020-12-05T21:50:04 squid .546 kid1| 28,3| DestinationDomain.cc(96) match: Can't yet compare 'remoteblacklist_Blacklist1' ACL for 107.180.24.2402020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: '107.180.24.240' NOT found2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(110) match: aclMatchDomainList: checking '107.180.24.240'2020-12-05T21:50:04 squid .546 kid1| 28,3| RegexData.cc(43) match: checking '107.180.24.240:443'2020-12-05T21:50:04 squid .546 kid1| 28,3| RegexData.cc(43) match: checking '107.180.24.240:443'2020-12-05T21:50:04 squid .546 kid1| 33,2| client_side.cc(2742) httpsSslBumpAccessCheckDone: sslBump action peekneeded for local=107.180.24.240:443 remote=10.63.19.139:59056 FD 1048 flags=33
$ sudo cat /usr/local/etc/squid/acl/Blacklist1 | grep "secureserver.net".ip.secureserver.net.phx3.secureserver.net.ams3.secureserver.net.sin3.secureserver.net.iad2.secureserver.net.sxb1.secureserver.net$
user@host:~/Downloads/blacklists$ grep -rni "secureserver.net"webmail/domains:62:email.secureserver.netphishing/domains:151369:ams3.secureserver.netphishing/domains:216639:iad2.secureserver.netphishing/domains:221982:ip.secureserver.netphishing/domains:264752:phx3.secureserver.netphishing/domains:288384:sin3.secureserver.netadult/domains:242315:ams3.secureserver.netadult/domains:1215507:iad2.secureserver.netadult/domains:1247472:ip.secureserver.netadult/domains:1701605:phx3.secureserver.netadult/domains:2083560:sin3.secureserver.netmalware/domains:151574:ams3.secureserver.netmalware/domains:218268:iad2.secureserver.netmalware/domains:223617:ip.secureserver.netmalware/domains:267343:phx3.secureserver.netmalware/domains:299440:sxb1.secureserver.netpublicite/domains:2283:images-pw.secureserver.netuser@host:~/Downloads/blacklists$
where this match for the ip is comming from
2020-12-05T21:50:04 squid .546 kid1| 28,3| DomainData.cc(115) match: aclMatchDomainList: 'ip-107-180-24-240.ip.secureserver.net' found
adult/domains:1247472:ip.secureserver.net
how to resolve the issue
Quote where this match for the ip is comming fromnot ip. ptr record:
Code: [Select]you can see it address in blacklist also:adult/domains:1247472:ip.secureserver.net
you can see it address in blacklist also:adult/domains:1247472:ip.secureserver.net
try to add livingsoilssymposium.ca to whitelist at Forward Proxy -> Access Control List
So is it like this: Squid checks the domain livingsoilssymposium.ca (no match), asks a DNS server and receives the IP address 107.180.24.240, checks the IP address (no match), does a reverse DNS lookup for the IP address and receives the domain ip.secureserver.net, checks the domain (match found!)? Did I get it right?