Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhu

1. Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhu

Perfil removido
removido

(usa Nenhuma)

Enviado em 15/05/2016 - 15:30h

Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhum IP

Segue minha configuração que funciona, porém apenas sem autenticação necessária pra um IP:

Pra segurança do servidor estarei substituindo o fim do IP do servidor por ##

Gostaria de saber o que devo alterar para torná-lo acessível por qualquer IP sem a necessidade de autenticação.

==========================
#A Port you would like to use to access the proxy. Change this to make it more secure.
http_port 3128


acl manager proto cache_object
acl localhost src 127.0.0.1/32 ::1
acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1
acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
acl localnet src fc00::/7 # RFC 4193 local private network range
acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines


acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT


http_access allow manager localhost
http_access deny manager
http_access allow localnet
http_access allow localhost
hierarchy_stoplist cgi-bin ?
coredump_dir /var/spool/squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|?) 0 0% 0
refresh_pattern . 0 20% 4320
#Your Personal IP to allow without authentication (Remove this line and one below to disable this)
acl myclients src 177.35.16.228
#Allow this IP without authentication
http_access allow myclients

#If you are on a 32 bit machine, remove the 64 from /lib64/
auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/squid_access
auth_param basic childred 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
acl ncsaauth proxy_auth REQUIRED
http_access allow ncsaauth
forwarded_for off

#Enter your servers IP here.
acl ip1 myip 167.88.123.##
#Enter your servers IP here.
tcp_outgoing_address 167.88.123.## ip1
request_header_access Allow allow all
request_header_access Authorization allow all
request_header_access WWW-Authenticate allow all

#Allocate 3GB for Caching
cache_dir ufs /var/spool/squid 3000 16 256
#Maximum Cache Object 1GB
maximum_object_size 1024 KB
#Use 1GB RAM for Cache
cache_mem 512 MB


  


2. Re: Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhu

Perfil removido
removido

(usa Nenhuma)

Enviado em 18/05/2016 - 02:30h

Alguém aí pra me ajudar!?


3. Re: Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhu

André Romero Alves de Souza
arasouza

(usa Debian)

Enviado em 18/05/2016 - 07:49h

maresiapunk escreveu:

Squid funcionando apenas para um IP, quero deixar transparent sem precisar de autenticacao pra nenhum IP

Segue minha configuração que funciona, porém apenas sem autenticação necessária pra um IP:

Pra segurança do servidor estarei substituindo o fim do IP do servidor por ##

Gostaria de saber o que devo alterar para torná-lo acessível por qualquer IP sem a necessidade de autenticação.

==========================
#A Port you would like to use to access the proxy. Change this to make it more secure.
http_port 3128


acl manager proto cache_object
acl localhost src 127.0.0.1/32 ::1
acl to_localhost dst 127.0.0.0/8 0.0.0.0/32 ::1
acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
acl localnet src fc00::/7 # RFC 4193 local private network range
acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines


acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT


http_access allow manager localhost
http_access deny manager
http_access allow localnet
http_access allow localhost
hierarchy_stoplist cgi-bin ?
coredump_dir /var/spool/squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|?) 0 0% 0
refresh_pattern . 0 20% 4320
#Your Personal IP to allow without authentication (Remove this line and one below to disable this)
acl myclients src 177.35.16.228
#Allow this IP without authentication
http_access allow myclients

#If you are on a 32 bit machine, remove the 64 from /lib64/
auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/squid_access
auth_param basic childred 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
acl ncsaauth proxy_auth REQUIRED
http_access allow ncsaauth
forwarded_for off

#Enter your servers IP here.
acl ip1 myip 167.88.123.##
#Enter your servers IP here.
tcp_outgoing_address 167.88.123.## ip1
request_header_access Allow allow all
request_header_access Authorization allow all
request_header_access WWW-Authenticate allow all

#Allocate 3GB for Caching
cache_dir ufs /var/spool/squid 3000 16 256
#Maximum Cache Object 1GB
maximum_object_size 1024 KB
#Use 1GB RAM for Cache
cache_mem 512 MB


Cara :

https://www.vivaolinux.com.br/artigo/Servidor-proxy-com-Squid-Instalacao-e-configuracao
basta pesquisar o artigo... :/







Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts