Enviado em 26/09/2013 - 13:54h
Seguinte, tá estranho o e-mail aqui na empresa, do nada algumas maquinas ficão com o acesso ao e-mail lento(Todas usam o Outlook 2007).
http_port 3128 transparent
hierarchy_stoplist cgi-bin ?
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
cache_mem 512 MB
maximum_object_size_in_memory 200 KB
maximum_object_size 3 GB
minimum_object_size 0 KB
cache_swap_low 90
cache_swap_high 95
cache_dir ufs /var/spool/squid3 1000 16 256
cache_access_log /var/log/squid3/access.log
#Nome servidor
visible_hostname Servidor.Proxy.Metalfor
cache_mgr manutencao.pc.cia@gmail.com
coredump_dir /var/spool/squid
refresh_pattern ^ftp: 10 20% 2280
refresh_pattern ^gopher: 10 0% 1440
refresh_pattern . 15 20% 2280
dns_nameservers 8.8.4.4
dns_nameservers 8.8.8.8
#Recommended minimum configuration:
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 25 110
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
acl localnetwork src 192.168.7.0/24
acl liberados src "/etc/squid3/ips_livres"
acl lista_branca url_regex "/etc/squid3/sites_allow"
http_access deny !localnetwork
http_access allow liberados
http_access allow lista_branca
http_access allow localnetwork lista_branca
icp_access allow all
always_direct allow all
http_access deny all
#!/bin/bash
EXTIF="eth2"
INTIF="eth1"
echo -e "\nPermitindo roteamento de Pacotes: \n"
echo "1" > /proc/sys/net/ipv4/ip_forward
echo -e "\nRoteamento de Pacotes OK \n"
echo -e "\nLimpando Regras e Liberando conexoes necessarias\n"
iptables -F
iptables -t nat -F
iptables -P INPUT ACCEPT
iptables -F INPUT
iptables -P OUTPUT ACCEPT
iptables -F OUTPUT
iptables -P FORWARD ACCEPT
iptables -F FORWARD
echo -e "\nBloqueio de sites https (porta-443)\n"
iptables -A FORWARD -m string --algo bm --string "facebook.com" -j DROP
iptables -A FORWARD -m string --algo bm --string "youtube.com" -j DROP
iptables -A FORWARD -m string --algo bm --string "twitter.com" -j DROP
echo -e "\nBloqueio de sites . . . [ok] \n"
echo -e "\nLiberando destino Conexoes necessarias \n"
iptables -A FORWARD -i $EXTIF -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i $INTIF -o $EXTIF -j ACCEPT
iptables -A FORWARD -j LOG
iptables -t nat -A POSTROUTING -o $EXTIF -j MASQUERADE
echo -e "\nConexoes necessarias . . . [ok] \n"
echo -e "\nRoteando pacotes para a porta 3128 \n"
iptables -t nat -A PREROUTING -s 192.168.7.0/24 -p tcp --dport 80 -j REDIRECT --to-port 3128
iptables -t nat -A PREROUTING -s 192.168.7.0/24 -p udp --dport 80 -j REDIRECT --to-port 3128
echo -e "\nRoteando pacotes para a porta 3128 . . . [ok] \n"
echo -e "\nRedireciona porta 3389 servidor XADM.\n"
iptables -t nat -A PREROUTING -p tcp --dport 3389 -d 189.11.7.108 -j DNAT --to-destination 192.168.7.20:3389
iptables -t nat -A POSTROUTING -p tcp -d 192.168.7.20 -j MASQUERADE
echo -e "\nRedirecionamento Servidor XADM . . . [ok] \n"
echo -e "\nFrewall inicializado.\n"