Hello all,

I've installed Squid3 on Ubuntu 9.04 as a transparent proxy on 3 different servers on 3 different subnets etc.
I have exactly the same configuration on 3 but acl dstdomain restrictions for youtube.com for example are working only on 1st server. I've double checked the configuration file and there is any parameter specific with the subnet etc and have no clue why the rest 2 squid3 servers are not parsing the acl properly.

All I have in the squid.conf file is:

acl manager proto cache_object
acl localhost src
acl bad dstdomain "/etc/squid3/squid-block.acl"
acl manager proto cache_object
acl to_localhost dst
acl SSL_ports port 443		# https
acl Safe_ports port 80		# http
acl Safe_ports port 21		# ftp
acl Safe_ports port 443		# https
acl Safe_ports port 70		# gopher
acl Safe_ports port 210		# wais
acl Safe_ports port 1025-65535	# unregistered ports
acl Safe_ports port 280		# http-mgmt
acl Safe_ports port 488		# gss-http
acl Safe_ports port 591		# filemaker
acl Safe_ports port 777		# multiling http
acl Safe_ports port 10000	# webmin
acl Safe_ports port 22		# ssh
http_access allow manager localhost
http_access deny manager
http_access deny bad
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
acl our_networks src
acl Foxmarks dstdomain sync.foxmarks.com
acl MSN_ICQ dstdomain .amsn-project.net c.icq.com gateway.messenger.hotmail.com login.messaging.aol.com messenger.hotmail.com
http_access allow our_networks
http_access allow localhost
http_access deny all
http_reply_access allow all
icp_access allow all
http_port 3128 transparent
visible_hostname myhostname.com
cache_mgr        somename@mydomain.com
hierarchy_stoplist cgi-bin ?
cache_mem 64 MB
maximum_object_size 256 MB
cache_dir ufs /var/spool/squid3 10240 16 256 
access_log /var/log/squid3/access.log squid
acl QUERY urlpath_regex cgi-bin \?
cache deny SSL_ports QUERY
refresh_pattern ^ftp:		1440	20%	10080
refresh_pattern ^gopher:	1440	0%	1440
refresh_pattern .		0	20%	4320
icp_port 3130
coredump_dir /var/spool/squid3
File /etc/squid3/squid-block.acl exist and include .facebook.com

Any help is much appreciated.