trem
(usa Outra)
Enviado em 17/11/2010 - 15:26h
Pessoal, eu tenho dois tipos de permissoes. um compermissao total para acessar todos tipos de sites e outra q nao acessa youtube, orkut e msn. To com problema na senha de permissao restrita, ele fica pedindo senha toda hora, pra abrir qqlr flash. Podem me ajudar!!! Abaixo meu squid. Ah e tb nao consegui bloquear o orkut pra quem tem permissao total.
Obrigada
---
http_port 3128
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
cache_mem 16 MB
cache_dir ufs /var/lib/squid/cache 10000 16 256
cache_access_log /var/lib/squid/logs/access.log
# cache_log /var/lib/squid/logs/cache.log
# cache_store_log /var/lib/squid/logs/store.log
dns_nameservers 192.168.0.1
# auth_param digest program /usr/libexec/digest_auth_pw /usr/etc/digpass
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
#Recommended minimum configuration:
#parametros de autenticacao#
auth_param basic program /usr/bin/ncsa_auth /etc/squid/squid_passwd
auth_param basic children 5
auth_param basic realm Entre com seu nome de usuario e senha
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
#Regras padroes do Squid#
acl manager proto cache_object
acl all src 0.0.0.0/0.0.0.0
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
acl limitado src 192.168.0.13 192.168.0.73 192.168.0.49 192.169.0.133
acl permitido url_regex "/etc/squid/spc"
http_access deny limitado !permitido
acl rede_local src 192.168.0.0/24
acl senha proxy_auth REQUIRED
acl acesso_total proxy_auth "/etc/squid/acesso_total"
acl acltime time F 00:01-23:59
acl sites url_regex "/etc/squid/sites_proibidos"
acl palavras_bloqueadas url_regex "/etc/squid/palavras"
acl msn url_regex "/etc/squid/msn_orkut"
acl execoes url_regex "/etc/squid/execoes"
acl msn_bloq req_mime_type -i ^application/x-msn-messenger$
acl orkut dstdomain
www.orkut.com
acl orkutbr dstdomain
www.orkut.com.br
acl minhaempresa dstdomain
www.minhaempersa.com.br
acl torpedo dstdomain
www.clarotorpedoweb.com.br
acl claro dstdomain
www.claro.com.br
acl oi dstdomain
www.oi.com.br
acl msnregex url_regex loginnet.passport.com login.live.com config.messenge.com
acl msndll url_regex -i gateway.dll sqmserver.dll
acl mula_ports port 4662 3000 2222 3333 4444 5555 7777 4242 4661 26662
####
acl exe url_regex -i .exe
acl zip url_regex -i .zip
acl rar url_regex -i .rar
acl scr url_regex -i .scr
acl msi url_regex -i .msi
acl wmv url_regex -i .wmv
acl pif url_regex -i .pif
acl avi url_regex -i .avi
acl mp3 url_regex -i .mp3
####
http_access deny exe !acesso_total
http_access deny zip !acesso_total
http_access deny rar !acesso_total
http_access deny scr !acesso_total
http_access deny msi !acesso_total
http_access deny wmv !acesso_total
http_access deny pif !acesso_total
http_access deny avi !acesso_total
http_access deny mp3 !acesso_total
####
http_access allow acesso_total
http_access allow minhaempresa
http_access allow torpedo
http_access allow claro
http_access allow oi
#http_access deny msnregx !acesso_total
#http_access deny msndll !acesso_total
#http_access deny orkut !accesso_total
#http_access deny orkut.br !acesso_total
###
http_access allow acesso_total
http_access deny senha sites !acesso_total !execoes
http_access allow senha execoes
http_access deny senha palavras_bloqueadas !acesso_total !execoes
http_access deny senha msn !acesso_total !execoes
http_access allow acesso_total
http_access allow msn_bloq !acesso_total
http_access allow Safe_ports
http_access allow rede_local
http_access deny acltime
http_access deny all
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access deny all
http_reply_access allow all
icp_access allow all