Enviado em 27/04/2015 - 13:33h
Olá Pessoal.# ./configure --build=i486-linux-gnu --prefix=/usr --includedir=${prefix}/include --mandir=${prefix}/share/man --infodir=${prefix}/share/info --sysconfdir=/etc --localstatedir=/var --libexecdir=${prefix}/lib/squid --srcdir=. --datadir=/usr/share/squid --sysconfdir=/etc/squid --mandir=/usr/share/man --with-cppunit-basedir=/usr --with-logdir=/var/log/squid --with-pidfile=/var/run/squid.pid --with-filedescriptors=65536 --with-large-files --with-default-user=proxy --enable-ssl --enable-ssl-crtd --with-openssl
http_port 3128 intercept
http_port 8080
https_port 3130 intercept ssl-bump cert=/etc/squid/openssl.crt key=/etc/squid/openssl.key
visible_hostname MIRACULIX
always_direct allow all
ssl_bump server-first all
sslproxy_cert_error allow all
sslproxy_flags DONT_VERIFY_PEER
sslcrtd_program /usr/lib/squid/ssl_crtd -s /var/lib/ssl_db -M 4MB
sslcrtd_children 8 startup=1 idle=1
acl QUERY urlpath_regex cgi-bin?
no_cache deny QUERY
cache_mem 64 MB
maximum_object_size_in_memory 64 KB
maximum_object_size 512 MB
minimum_object_size 0 KB
cache_swap_low 90
cache_swap_high 95
cache_dir ufs /var/spool/squid 2048 16 256
cache_mgr thiago.nogueira@prestus.com.br
cache_access_log /var/log/squid/access.log
cache_log /var/log/squid/access.log
access_log stdio:/var/log/squid/access.log squid
cache_store_log /var/log/squid/store.log
cache_swap_log /var/log/squid/swap.log
logformat squid %ts.%03tu %6tr %>a %Ss/%03Hs %<st %rm %ru %un %Sh/%<A %mt
pid_filename /var/log/squid/squid.pid
refresh_pattern ^ftp: 15 20% 2280
refresh_pattern ^gopher: 15 0% 2280
refresh_pattern . 15 20% 2280
acl SSL_ports port 443 563
acl Safe_ports port 21 22 80 443 563 70 210 280 488 59 777 901 8080 1025-65535
acl purge method PURGE
acl CONNECT method CONNECT
acl localnet src 192.168.100.0/24
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
acl sites_bloqueados url_regex -i "/etc/squid/sites_bloqueados.txt"
#acl liberados src "/etc/squid/ips_liberados.txt"
http_access deny sites_bloqueados
http_access allow localnet
http_access allow localhost
http_access deny all
iptables -t nat -A PREROUTING -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -p tcp --dport 443 -j REDIRECT --to-port 3130