uehara
(usa Ubuntu)
Enviado em 15/12/2011 - 18:52h
Renato, não me dei bem com o cacti, hehehe...
Fiz o seguinte: desativei o redirect para o Squid no meu firewall. A taxa do download pulou de 201bps para +- 10kbps. Segue abaixo o meu squid.conf.
# Definicao da porta de acesso ao proxy (considerando a porta http = 3131)
http_port 3131 transparent
# Definicao do nome do proxy
visible_hostname srvdebian
# Added by Kaspersky Anti-Virus installer
icap_enable on
icap_send_client_ip on
icap_service is_kav_req reqmod_precache 0 icap://127.0.0.1:1344/av/reqmod
icap_service is_kav_resp respmod_precache 0 icap://127.0.0.1:1344/av/respmod
adaptation_access is_kav_req allow all
adaptation_access is_kav_resp allow all
# /Added by Kaspersky Anti-Virus installer
# Definicao de cache na RAM (considerando 8GB de RAM)
cache_mem 2048 MB
maximum_object_size_in_memory 2048 KB
# Definicao de cache em disco (considerando HD com 10GB livres para essa funcao)
maximum_object_size 10240 MB
minimum_object_size 0 KB
# Definicao do percentual para o inicio de descarte de arquivo
cache_swap_low 90
cache_swap_high 95
# Definicao da quantidade de subpastas para cache de disco (considerando HD com 10GB livres para essa funcao)
cache_dir ufs /var/spool/squid3 10240 16 256
# Definicao do local de armazenamento do logs de acesso do Squid3
cache_access_log /var/log/squid3/access.log
# Definicao do tempo de atualizacao do cache (15 = 15 minutos e 2280 = 2 dias)
refresh_pattern ^ftp: 15 20% 2280
refresh_pattern ^gopher: 15 0% 2280
refresh_pattern . 15 20% 2280
# Definicao de acl e http
# acl all src all
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl SSL_ports port 443 563
acl Safe_ports port 21 # ftp
acl Safe_ports port 70 # gopher
acl Safe_ports port 80 # http
acl Safe_ports port 210 # wais
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 443 # https
acl Safe_ports port 488 # gss-http
acl Safe_ports port 563 # snews
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 901 # swat
acl Safe_ports port 1025-65535 # portas altas
acl purge method PURGE
acl CONNECT method CONNECT
http_access allow manager localhost
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
# Utilizando squidGuard
# redirect_program /usr/bin/squidGuard
# Considerando a IP range = 192.168.10.0/24
acl localnetwork src 192.168.10.0/24
http_access allow localhost
http_access allow localnetwork
http_access deny all
Obs.: o squidGuard está desativado mesmo.
Um abraço,
Rogerio Uehara