sábado, 21 de febrero de 2015

PRACTICA 30 SQUID

Squid es el servidor proxy de ubuntu.

Lo primero upgrade y update

Para instalarlo utilizamos el siguiente comando:


Realizaremos una copia de seguridad, del fichero de configuración, por si cometiéramos un error.


Ahora entramos en el fichero original:


Borraremos todo el fichero y copiaremos esto en el:

#    WELCOME TO SQUID 3.3.8
#    ----------------------------
#    
#    This is the documentation for the Squid configuration file.
#    This documentation can also be found online at:
#        
http://www.squid-cache.org/Doc/config/
#    
#    You may wish to look at the Squid home page and wiki for the
#    FAQ and other documentation:
#        
http://www.squid-cache.org/
#        
http://wiki.squid-cache.org/SquidFaq
#        
http://wiki.squid-cache.org/ConfigExamples
#    

# Recommended minimum configuration:
#

# Example rule allowing access from your local networks.
# Adapt to list your (internal) IP networks from where browsing
# should be allowed
#acl localnet src 
10.0.0.0/8    # RFC1918 possible internal network
#acl localnet src 
172.16.0.0/12    # RFC1918 possible internal network
#acl localnet src 
192.168.0.0/16    # RFC1918 possible internal network
#acl localnet src fc00::/7       # RFC 4193 local private network range
#acl localnet src fe80::/10      # RFC 4291 link-local (directly plugged) machines

#Set ai1
acl ai1 src 
192.168.1.0/24 

acl SSL_ports port 443
acl Safe_ports port 80        # http
acl Safe_ports port 21        # ftp
acl Safe_ports port 443        # https
acl Safe_ports port 70        # gopher
acl Safe_ports port 210        # wais
acl Safe_ports port 1025-65535    # unregistered ports
acl Safe_ports port 280        # http-mgmt
acl Safe_ports port 488        # gss-http
acl Safe_ports port 591        # filemaker
acl Safe_ports port 777        # multiling http
acl CONNECT method CONNECT


#
# Recommended minimum Access Permission configuration:
#
# Deny requests to certain unsafe ports
http_access deny !Safe_ports

# Deny CONNECT to other than secure SSL ports
http_access deny CONNECT !SSL_ports

# Only allow cachemgr access from localhost
http_access allow localhost manager
http_access deny manager


#
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#

# Example rule allowing access from your local networks.
# Adapt localnet in the ACL section to list your (internal) IP networks
# from where browsing should be allowed
#http_access allow localnet
http_access allow localhost
http_access allow ai1

# And finally deny all other access to this proxy
http_access deny all


# Squid normally listens to port 3128
http_port 3128



#Default:
cache_mem 256 MB


# Uncomment and adjust the following to add a disk cache directory.
cache_dir ufs /var/spool/squid3 100 16 256

#  TAG: cache_log
#    Squid administrative logging file.

#Default:
cache_log /var/log/squid3/cache.log

#  TAG: debug_options

# Leave coredumps in the first cache dir
coredump_dir /var/spool/squid3

A continuación configuramos el proxy en el navegador del cliente:
en dirección ponemos la ip del server y el puerto el que corresponde a squid 3128



No hay comentarios:

Publicar un comentario