Página 1 de 2 12 ÚltimoÚltimo
+ Responder ao Tópico



  1. #1
    slackrio
    galera e o seguinte tenho o squid configurado desta forma abaixo:

    http_port 3128
    visible_hostname Servidor
    # Criando o Cache
    cache_mem 32 MB
    maximum_object_size_in_memory 64 KB
    maximum_object_size 512 MB
    minimum_object_size 0 KB
    cache_swap_low 90
    cache_swap_high 95
    cache_dir ufs /usr/local/squid/var/cache 2048 16 256
    cache_access_log /usr/local/squid/var/logs/access.log
    refresh_pattern ^ftp: 15 20% 2280
    refresh_pattern ^gopher: 15 0% 2280
    refresh_pattern . 15 20% 2280

    auth_param basic program /usr/bin/ncsa_auth /usr/local/squid/etc/passwd
    auth_param basic children 5
    auth_param basic realm Squid proxy-caching web server
    auth_param basic credentialsttl 2 hours
    auth_param basic casesensitive off

    # Regras ACL
    acl all src 0.0.0.0/0.0.0.0
    acl manager proto cache_object
    acl localhost src 127.0.0.1/255.255.255.255
    acl SSL_ports port 443 563
    acl Safe_ports port 80 # http
    acl Safe_ports port 21 # ftp
    acl Safe_ports port 443 563 # https, snews
    acl Safe_ports port 70 # gopher
    acl Safe_ports port 210 # wais
    acl Safe_ports port 1025-65535 # unregistered ports
    acl Safe_ports port 280 # http-mgmt
    acl Safe_ports port 488 # gss-http
    acl Safe_ports port 591 # filemaker
    acl Safe_ports port 777 # multiling http
    acl Safe_ports port 901 # SWAT
    acl Safe_ports port 110 # e-mail pop3
    acl Safe_ports port 25 # e-mail smtp
    acl purge method PURGE
    acl CONNECT method CONNECT

    acl rede_interna src 192.168.0.0/24
    acl user1 proxy_auth "/usr/local/squid/etc/passwd"

    #Acessos dos usuários
    acl permit_user1 url_regex -i "/usr/local/squid/etc/acessos/user1


    #Efetivando a acl

    error_directory /usr/local/squid/share/errors/Portuguese

    http_access allow manager localhost
    http_access deny manager
    http_access deny !Safe_ports
    http_access deny CONNECT !SSL_ports
    http_access allow user1 permit_user1 rede_interna
    http_access deny all
    http_reply_access allow all
    icp_access allow all

    a pasta citada na conf acima existe (acessos) e tb o arquivo passwd
    o que acontece quando rodo o squid ele sobe blz no navegador ele pede usuario e senha blz tb so que nao navega coloque o site do under-linux.org dentro da pasta acesso do usuario e mesmo assim nao vai da aquela pagina de acesso negado..
    o que vcs podem fazer para resolver este pequena dificuldade ?
    o que estara faltando nesta conf?

    grato

  2. Verificou os Logs!?
    Primeira coisa após o problema..

    Verifica la e qualquer coisa posta as algumas linhas dele..

    Valeu



  3. #3
    slackrio
    resolvi fazer a conf desta forma e funcionou blz mais so que nao ta bloqueando os sites proibidos que antes funcionava rs

    ha um detalhe fica pedindo toda hora o user e senha toda vez que abre o navegador!

    http_port 3128
    visible_hostname Servidor

    # Criando o Cache

    cache_mem 32 MB
    maximum_object_size_in_memory 64 KB
    maximum_object_size 512 MB
    minimum_object_size 0 KB
    cache_swap_low 90
    cache_swap_high 95
    cache_dir ufs /usr/local/squid/var/cache 2048 16 256
    cache_access_log /usr/local/squid/var/logs/access.log
    refresh_pattern ^ftp: 15 20% 2280
    refresh_pattern ^gopher: 15 0% 2280
    refresh_pattern . 15 20% 2280
    error_directory /usr/local/squid/share/errors/Portuguese

    # Autenticando Usuario
    auth_param basic program /usr/bin/ncsa_auth /usr/local/squid/etc/passwd
    auth_param basic children 5
    auth_param basic realm Digite o Login para Navegar
    auth_param basic credentialsttl 2 hours
    auth_param basic casesensitive off

    # Regras ACL
    acl manager proto cache_object
    acl all src 0.0.0.0/0.0.0.0
    acl localhost src 127.0.0.1/255.255.255.255
    acl SSL_ports port 443 563
    acl Safe_ports port 80 # http
    acl Safe_ports port 21 # ftp
    acl Safe_ports port 443 563 # https, snews
    acl Safe_ports port 70 # gopher
    acl Safe_ports port 210 # wais
    acl Safe_ports port 1025-65535 # unregistered ports
    acl Safe_ports port 280 # http-mgmt
    acl Safe_ports port 488 # gss-http
    acl Safe_ports port 591 # filemaker
    acl Safe_ports port 777 # multiling http
    acl Safe_ports port 901 # SWAT
    acl Safe_ports port 110 # e-mail pop3
    acl Safe_ports port 25 # e-mail smtp
    acl purge method PURGE
    acl CONNECT method CONNECT

    #squidclamav
    redirect_program /usr/local/squidclamav/bin/squidclamav
    redirect_children 10
    redirector_access deny localhost

    acl senha proxy_auth "/usr/local/squid/etc/usuarios"

    http_access allow manager localhost
    http_access allow senha
    http_access deny manager
    http_access deny !Safe_ports
    http_access deny CONNECT !SSL_ports
    acl proibidos dstdom_regex "/usr/local/squid/etc/proibidos"
    http_access deny proibidos
    acl redelocal src 192.168.0.0/24


    tem alguma sugestao para fazer o acl aproibidos funcionar ?
    ja testei em outros locais dentro da conf e tb nao conseguri fazer funcionar

    grato

  4. #4
    slackrio
    Pessoal consegui resolver a conf esta desta forma


    http_port 3128
    visible_hostname Servidor

    # Criando o Cache

    cache_mem 32 MB
    maximum_object_size_in_memory 64 KB
    maximum_object_size 512 MB
    minimum_object_size 0 KB
    cache_swap_low 90
    cache_swap_high 95
    cache_dir ufs /usr/local/squid/var/cache 2048 16 256
    cache_access_log /usr/local/squid/var/logs/access.log
    refresh_pattern ^ftp: 15 20% 2280
    refresh_pattern ^gopher: 15 0% 2280
    refresh_pattern . 15 20% 2280
    error_directory /usr/local/squid/share/errors/Portuguese

    # Autenticando Usuario
    auth_param basic program /usr/bin/ncsa_auth /usr/local/squid/etc/passwd
    auth_param basic children 5
    auth_param basic realm Digite o Login para Navegar
    auth_param basic credentialsttl 2 hours
    auth_param basic casesensitive off

    # Regras ACL
    acl manager proto cache_object
    acl all src 0.0.0.0/0.0.0.0
    acl localhost src 127.0.0.1/255.255.255.255
    acl SSL_ports port 443 563
    acl Safe_ports port 80 # http
    acl Safe_ports port 21 # ftp
    acl Safe_ports port 443 563 # https, snews
    acl Safe_ports port 70 # gopher
    acl Safe_ports port 210 # wais
    acl Safe_ports port 1025-65535 # unregistered ports
    acl Safe_ports port 280 # http-mgmt
    acl Safe_ports port 488 # gss-http
    acl Safe_ports port 591 # filemaker
    acl Safe_ports port 777 # multiling http
    acl Safe_ports port 901 # SWAT
    acl Safe_ports port 110 # e-mail pop3
    acl Safe_ports port 25 # e-mail smtp
    acl purge method PURGE
    acl CONNECT method CONNECT

    #squidclamav
    redirect_program /usr/local/squidclamav/bin/squidclamav
    redirect_children 10
    redirector_access deny localhost

    acl senha proxy_auth "/usr/local/squid/etc/usuarios"

    http_access allow manager localhost
    http_access allow senha
    http_access deny manager
    http_access deny !Safe_ports
    http_access deny CONNECT !SSL_ports
    acl proibidos dstdom_regex "/usr/local/squid/etc/proibidos"
    http_access deny proibidos
    acl redelocal src 192.168.0.0/24


    na linha acl senha proxy_auth "/usr/local/squid/etc/usuarios" mudei para
    acl senha proxy_auth "/usr/local/squid/etc/usuario" mudei de usuarios para passwd e blz

    funcionaou tudo maravilha ou seja ele autentica no passwd
    no passwd tinha la os usuarios criados e na pasta usuarios tb por isso dava conflito
    colocando os 2 para procurar no passwd agora ta resolvido

    mais valew pela ajuda
    espero que ajudem outros colegas aqui do forum

    fui



  5. So ta errado uma coisa veja abaixo:

    1 - nao precisa da acl redelocal
    2 - voce deve colocar a acl proibidos antes da de autenticaçao, depois dele ler a primeira e liberar nao vai acabar lendo a segunda.

    acl proibidos dstdom_regex "/usr/local/squid/etc/proibidos"
    acl senha proxy_auth "/usr/local/squid/etc/usuarios"

    http_access deny proibidos
    http_access allow senha

    Abraçao






Tópicos Similares

  1. problema autentica mais não navega na maquina!!
    Por leonardojrj no fórum Redes
    Respostas: 2
    Último Post: 19-04-2009, 11:18
  2. Squid pinga mais nao navega
    Por amsistemas no fórum Servidores de Rede
    Respostas: 5
    Último Post: 13-02-2009, 16:40
  3. Host Post autentica mais nao navega.
    Por wznetviaradio no fórum Redes
    Respostas: 11
    Último Post: 06-01-2009, 22:50
  4. Linux Mandrake 8.1, conecta mais nao navega???
    Por no fórum Servidores de Rede
    Respostas: 1
    Último Post: 23-09-2003, 12:48
  5. Conectiva 8.0 conecta, mais nao navega..?
    Por no fórum Servidores de Rede
    Respostas: 2
    Último Post: 22-08-2003, 12:55

Visite: BR-Linux ·  VivaOLinux ·  Dicas-L