rubenssales
(usa Ubuntu)
Enviado em 27/11/2009 - 22:14h
Boa Noite Comunidade!
Preciso de uma ajuda ou dicas de como configurar links distintos em um unico squid e dhcp,
sendo que cada link possue difrentes velocidades de conexoes, ja havia me deperado com esse problema mas de uma forma involuntaria, e vi que o mesmo funcionou sem ter adicionados maiores config no entanto quando o primeiro link caia o outro assumia, so que, quando o outro voltava nao era repassado a velocidade de ambos em conjunto, tendo assim de restartar os serviços manuamente.
Uso Fedora 11 - Squid no transparet e Dhcpserver
eth0 link01 189.X.X.X link01
eth1 link02 200.X.X.X link02
eth2 intranet via dhcp 10.0.0.10/24
Squid 3
Vou postar Meus .conf
DHCPD.conf
#########################################################################
# #
# DHCP.CONF by Rubens Sales #
# #
#########################################################################
# Atualizaç do DNS
ddns-update-style none;
# Tempo de Ip
default-lease-time 600;
# Tempo maximo de IP
max-lease-time 7200;
# Este Server eh quem manda
authoritative;
# Ip de Intranet
subnet 10.0.0.0 netmask 255.0.0.0 {
# Quantidades de Ip na rede
range 10.0.0.11 10.0.0.99;
#Ip no qual sera roteado
option routers 10.0.0.10;
#Servidores DNS de internet eth0
option domain-name-servers 189.X.X.X,200.X.X.0;
#Endecos Broadcats intranet eth1
option broadcast-address 10.0.0.255;
}
#########################################################################
Squid.conf
#################################################################
# #
# SQUID.CONF 1.0 by Crede Rubens Sales #
# #
#################################################################
#################################################################
http_port 3128
visible_hostname Localhost
#################################################################
#Cache de Paginas e Arquivos
#################################################################
cache_mem 512 MB
maximum_object_size_in_memory 10 MB
maximum_object_size 512 MB
ipcache_size 3072
ipcache_low 90
ipcache_high 93
minimum_object_size 1 KB
cache_swap_low 90
cache_swap_high 95
cache_dir ufs /var/spool/squid 2048 16 256
cache_access_log /var/log/squid/access.log
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern (cgi-bin|\?) 0 0% 0
refresh_pattern . 0 20% 4320
##################################################################
#acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl BADPORTS port 7 9 11 19 22 23 25 53 110 119 513 514 3128 8080
acl SSL_ports port 443 563
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 901 # SWAT
acl purge method PURGE
acl CONNECT method CONNECT
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
########## Cache Videos #########################################
refresh_pattern -i \.flv$ 10080 90% 999999 ignore-no-cache override-expire ignore-private
acl youtube dstdomain .youtube.com
cache allow youtube
##################################################################
##################################################################
#Download abortados
quick_abort_min -1 KB
quick_abort_max 0 KB
quick_abort_pct 100%
##################################################################
http_access allow manager localhost
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny BADPORTS
http_access deny CONNECT !SSL_ports
################################################################
#Lista de Bloqueios
################################################################
####### Liberando IP Acesso Total ##############################
acl IP_LIBERADO src "/etc/squid/ips_liberados.cf"
http_access allow IP_LIBERADO
################################################################
acl bloquear_palavras url_regex -i "/etc/squid/bloqueio/bloquear_palavras"
http_access deny bloquear_palavras
acl NOCACHE url_regex "/etc/squid/direto.txt"
http_access allow NOCACHE
##### Banner Msn ###############################################
acl ADSAdClien url_regex ADSAdClien
http_access deny ADSAdClien
deny_info
http://www.crede05.hdfree.com.br/index1.html ADSAdClien
##### Banner Google ############################################
acl google url_regex
http://www.google.com.br/intl/pt-BR_br/images/logo.gif
http_access deny google
deny_info
http://www.crede05.hdfree.com.br/googlecrede.jpg google
################################################################
##### Banner orkut ############################################
acl orkut url_regex
www.coca-cola.com.br
http_access deny orkut
deny_info
http://www.crede05.hdfree.com.br/googlecrede.jpg orkut
################################################################
acl redelocal src 10.0.0.0/24
http_access allow localhost
http_access allow redelocal
http_access deny all
memory_pools off
forwarded_for off
detect_broken_pconn on
###################################################################
#Mensagens de erro
error_directory /usr/share/squid/errors/Portuguese
visible_hostname advancedmultimidia@hotmail.com
###################################################################
#Destina Direto
#acl site dstdomain
www.cursos.caedufjf.net
#always_direct allow site
###################################################################
# ---- Cache do Windows Update ----
refresh_pattern au.download.windowsupdate.com/.*\.(cab|exe|msi) 10080 100% 43200 reload-into-ims
refresh_pattern download.microsoft.com/.*\.(cab|exe|msi) 10080 100% 43200 reload-into-ims
refresh_pattern msgruser.dlservice.microsoft.com/.*\.(cab|exe|msi) 10080 100% 43200 reload-into-ims
refresh_pattern windowsupdate.com/.*\.(cab|exe|msi) 10080 100% 43200 reload-into-ims
refresh_pattern
www.microsoft.com/.*\.(cab|exe|msi) 10080 100% 43200 reload-into-ims
refresh_pattern -i download\.macromedia\.com/ 0 100% 20160 reload-into-ims
####################################################################
#End para maiores informacoes advancedmultimidia@hotmail.com
########################################################################
...preferi em nao usar um bom firewall, mas isso nao implica que a regra possa seguir uma nova direção, agradeço as sugestoes vinda de todos. Desculpem minhas limitaçoes no Linux, mais acredito que com uma boa influencia de conhecimentos poderemos evoluir bastante no que se diz Liberdade de resolver situaçoes e desafios que nos aparece a cada instante...