xloko
(usa Debian)
Enviado em 04/05/2009 - 18:39h
opa !! galera .. to doido com issso
squid esta liberando tudo!!
nao esta respeitando minhas ACLs
segue as mihas configuracoes!
caso alguem encontre um tremno fim do tunel..
valeus!!
-----------------------------
http_port 3128 transparent
cache_mem 8 MB
maximum_object_size 4096 KB
cache_dir ufs /var/spool/squid 100 16 256
cache_access_log /var/log/squid/access.log
cache_log /var/log/squid/cache.log
cache_store_log /var/log/squid/store.log
emulate_httpd_log on
error_directory /usr/share/squid/errors/Portuguese
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80
acl Safe_ports port 70
acl Safe_ports port 21
acl Safe_ports port 443 563
acl Safe_ports port 70
acl Safe_ports port 210
acl Safe_ports port 1025-65535
acl Safe_ports port 280
acl Safe_ports port 488
acl Safe_ports port 591
acl Safe_ports port 777
acl CONNECT method CONNECT
acl network src 192.168.0.0/24
acl no_sites dstdomain "/etc/squid/nosite"
acl no_palavra url_regex -i "/etc/squid/nopalavra"
acl sim_palavra url_regex -i "/etc/squid/simpalavra"
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access deny no_sites
http_access allow sim_palavra
http_access deny no_palavra
http_access allow network
http_access deny all
--------------------------
dentro de "nosite" tem
orkut.com
playboy.com
-------------------------
firewall
echo 1 > /proc/sys/net/ipv4/ip_forward
iptables -t nat -A POSTROUTING -o eth1 -j MASQUERADE
iptables -t nat -A PREROUTING -s 192.168.0.0/255.255.255.0 -p tcp --dport 80 -j REDIRECT --to-port 3128
-----------------------------------------