настройка Squid

Discussion in 'Linux, Freebsd, *nix' started by Kavabango, 24 Dec 2010.

  1. Kavabango

    Kavabango New Member

    Joined:
    14 Nov 2008
    Messages:
    44
    Likes Received:
    0
    Reputations:
    0
    Не могу побороть Squid. Вроде не первый раз настраиваю, но не получается.
    Squid.conf:
    Code:
     1 acl user1 src 10.2.70.5/32
     2 acl user2 src 10.2.70.10/32
     3 acl localhost src 127.0.0.1/32
     4 acl other src 0.0.0.0/32
     5 
     6 acl proto proto HTTP FTP
     7 
     8 acl Safe_ports port 80
     9 acl Safe_ports port 20
    10 acl Safe_ports port 21
    11 acl Safe_ports port 443
    12 acl Safe_ports port 70
    13 acl Safe_ports port 210
    14 acl Safe_ports port 1025-65535
    15 
    16 http_access allow user1
    17 http_access allow user2
    18 http_access allow localhost
    19 http_access allow proto
    20 http_access deny !Safe_ports
    21 http_access deny other
    22 
    23 cache_mem 128 MB
    24 cache_dir ufs /data/squid/cache 2048 16 128
    25 cache_access_log /dev/null
    26 cache_log /dev/null
    27 cache_store_log none
    28 cache_mgr [email protected]
    29 
    30 http_port 7723
    
    Проблема в том, что проксик получается открытый. Зайти можно с любого IP.
    Что не так?
     
  2. emomasson

    emomasson Member

    Joined:
    27 Jul 2010
    Messages:
    174
    Likes Received:
    12
    Reputations:
    5
    acl Safe_ports port 1025-65535 попробуй прибить.
     
  3. WNZRS

    WNZRS Member

    Joined:
    3 Sep 2009
    Messages:
    294
    Likes Received:
    52
    Reputations:
    1
    Code:
    acl user1 src 10.2.70.5
    acl user2 src 10.2.70.10
    acl localhost src 127.0.0.1
    acl other src 0.0.0.0/0
    Если IP один, то маску можно не писать. Но проблема в other, потому что, все IP это - 0.0.0.0/0
     
    #3 WNZRS, 30 Dec 2010
    Last edited: 30 Dec 2010
  4. Looock

    Looock New Member

    Joined:
    30 Dec 2010
    Messages:
    12
    Likes Received:
    1
    Reputations:
    0
    http_access deny all пропиши в самом низу..