aironzimerer
(usa Ubuntu)
Enviado em 10/08/2015 - 15:11h
Boa tarde pessoal, estou com um problema na minha rede. Usamos o squid3 transparente e estamos rodando ele normalmente porém quando acesso esse seguinte link
https://madagascar.tce.mg.gov.br:8443/sgiPortal/web/login.jsf o proxy recusa a conexão e o erro que me retorna vai depender do navegador que estou usando. Lembrando que o meu proxy já está configurado para aceitar sites https. Já procurei solução para esse problema em vários fóruns e em nenhum deles eu achei e minha última alternativa foi criar este tópico.
Segue meu squid. conf
http_port 3128
#Recomendamos que voce use as duas linhas seguintes
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
# Cache de memória
cache_mem 200 MB
# TAG: cache_swap_low (percentual, 0-100)
# TAG: cache_swap_high (percentual, 0-100)
cache_swap_low 80
cache_swap_high 85
# Permite guardar no cache arquivos de atualizacao
refresh_pattern windowsupdate.com/.*\.(cab|exe|dll|msi) 10080 100% 43200 reload-into-ims
refresh_pattern download.microsoft.com/.*\.(cab|exe|dll|msi) 10080 100% 43200 reload-into-ims
refresh_pattern
www.microsoft.com/.*\.(cab|exe|dll|msi) 10080 100% 43200 reload-into-ims
refresh_pattern au.download.windowsupdate.com/.*\.(cab|exe|dll|msi) 4320 100% 43200 reload-into-ims
# TAG: maximum_object_size (bytes)
maximum_object_size 1024 MB
# TAG: minimum_object_size (bytes)
minimum_object_size 0 KB
# TAG: maximum_object_size_in_memory (bytes)
maximum_object_size_in_memory 64 KB
# TAG: cache_replacement_policy
cache_replacement_policy lru
# TAG: memory_replacement_policy
memory_replacement_policy lru
# TAG: cache_dir
cache_dir ufs /var/spool/squid 4096 32 512
# TAG: pid_filename
pid_filename /var/log/squid/squid.pid
access_log /var/log/squid/access.log
acl acesso_direto url_regex -i "/etc/squid/bloqueados/direto.txt"
http_access allow acesso_direto
#acl msn url_regex -i "/etc/squid/sites/msn"
#http_access deny !acesso_total msn
# TAG: auth_param
#Recommended minimum configuration:
auth_param basic program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic children 5
auth_param basic credentialsttl 10 second
auth_param basic realm SAAE-GV - Sistema de Acesso a Internet - Digite seu Login e Senha
# TAG: refresh_pattern
#Suggested default:
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern . 0 20% 4320
############## Recommended minimum configuration #############################
#acl todos src 0.0.0.0/0
acl manager proto cache_object
acl redelocal src 192.168.1.0/24
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80 21 22 23 443 563 70 210 1025-65535
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 8443 # TCE
acl Safe_ports port 407 # msn
acl CONNECT method CONNECT
http_access deny manager
http_access allow manager localhost
http_access deny CONNECT !SSL_ports
################################## SAAE ###########################################
acl receita dstdomain "/etc/squid3/bloqueados/receita"
#acl receita1 url_regex -i "/etc/squid3/bloqueados/receita1"
acl palavrasbloqueadas url_regex -i "/etc/squid/bloqueados/bloqueados.txt"
acl palavrasliberadas url_regex -i "/etc/squid/bloqueados/liberados.txt"
acl bloquearmsn url_regex -i "/etc/squid/bloqueados/msn.txt"
acl palavraspesadas url_regex -i "/etc/squid/bloqueados/pesado.txt"
#acl msnaccess url_regex -i "/etc/squid/bloqueados/msnaccess.txt"
acl sites_liberados dstdomain -i "/etc/squid/bloqueados/sites_liberados.txt"
acl site_interno dstdomain -i "/etc/squid/bloqueados/site_interno.txt"
acl atendimentopub dstdomain -i "/etc/squid/bloqueados/atendimento.txt"
################## REDIRECIONAMENTO PARA O SITE DO SAAE ##########################
acl TIMER_SQUID dstdomain .saaegoval.com.br
http_access allow TIMER_SQUID
error_directory /usr/share/squid/errors/pt-br
####################### Acesso via autenticacao #################################################
external_acl_type NT_global_group children=10 %LOGIN /usr/lib/squid/wbinfo_group.pl
acl sembloqueio external NT_global_group irrestrito
acl liberado external NT_global_group Released
acl cominternet external NT_global_group internet
acl acesso-msn external NT_global_group msn
acl velox external NT_global_group ummega
acl starone external NT_global_group extreme
acl bloqueiopesado external NT_global_group heavyblock
acl users_restritos external NT_global_group Restritos
acl 2via external NT_global_group 115
acl nolimits external NT_global_group limits
acl atendpub external NT_global_group atendimento
acl lentox external NT_global_group 300k
#Receita Federal NFe
http_access allow receita
#http_access allow receita1
#Fim Receita Federal NFe
http_access allow liberado
http_access allow lentox
http_access deny bloquearmsn !acesso-msn
http_access allow palavrasliberadas
http_access deny palavraspesadas
http_access deny palavrasbloqueadas
http_access allow cominternet !bloquearmsn !palavrasbloqueadas
#http_access allow msnaccess
http_access allow acesso-msn
http_access allow sembloqueio
#http_access allow acesso-msn !msnaccess
http_access allow nolimits !palavrasbloqueadas
http_access deny users_restritos !sites_liberados
http_access deny 2via !site_interno
http_access allow bloqueiopesado
http_access allow velox !bloquearmsn !palavrasbloqueadas
http_access allow starone !bloquearmsn !palavrasbloqueadas
http_access allow atendimentopub
http_access deny atendpub !atendimentopub
http_access deny all
# TAG: http_reply_access
#Default:
# http_reply_access allow all
http_reply_access allow all
#Default:
# icp_access deny all
#Allow ICP queries from everyone
icp_access allow all
# TAG: visible_hostname
#Default:
visible_hostname spd@saaegoval.com.br
#Controle de Banda
delay_pools 7
delay_class 1 2
delay_parameters 1 500000/500000 500000/500000
delay_access 1 allow cominternet
delay_class 2 2
delay_parameters 2 300000/300000 300000/300000
delay_access 2 allow velox
delay_class 3 2
delay_parameters 3 21000/21000 21000/21000
delay_access 3 allow sembloqueio
delay_class 4 2
delay_parameters 4 4000/4000 4000/4000
delay_access 4 allow starone
delay_class 5 2
delay_parameters 5 -1/-1 -1/-1
#delay_parameters 5 84000/84000 84000/84000
delay_access 5 allow nolimits
delay_class 6 2
delay_parameters 6 500000/500000 500000/500000
delay_access 6 allow liberado
delay_class 7 2
delay_parameters 7 35000/35000 35000/35000
delay_access 7 allow lentox
#Default:
# relaxed_header_parser on
cache_effective_group users