oseias77
(usa Kali)
Enviado em 18/08/2015 - 10:57h
########################################################
# Configurções Básicas #
#################################################################################
# Mensagens de erro em Português
error_directory /usr/share/squid/errors/Portuguese
#################################################################################
#Porta padrão do squid
http_port transparent
#################################################################################
# #
# #
############################ Regras ssl padrão #################################
acl SSL_ports port 443 #https
acl SSL_ports port 563 #snews
acl SSL_ports port 873 #rsync
############################ Regras acl padrão ##################################
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl Safe_ports port 23000 # Siafi WEB SERPRO
acl Safe_ports port 8999
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 #https
acl Safe_ports port 70 #gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 901 # swat
acl Safe_ports port 23 # telnet
acl Safe_ports port 383 #https
acl Safe_ports port 1025-65535 # portas altas
acl purge method PURGE
acl CONNECT method CONNECT
#######
acl siafi dstdomain .siafi.tesouro.gov.br
always_direct siafi
acl serpro dstdomain .serpro.gov.br
always_direct serpro
#######################Permissões e bloqueios padrão############################
# Permissão rede local e servidor
acl redelocal src
#Autenticação por senha
#auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd
#auth_param basic children 5
#auth_param basic credentialsttl 2 hours
#auth_param basic realm Servidor proxy . Entre com seu usuário e senha.
#################################################################################
## Bloco responsável por controlar o acesso por senha ##
#################################################################################
## caminho do arquivo que armazena as senhas
auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd
auth_param basic children 5
auth_param basic credentialsttl 5 hour
#Senha
acl senha proxy_auth REQUIRED
#Acesso Livre
acl acesso_livre proxy_auth "/etc/squid/listas/cmdo"
# Bloqueio de sites por URL
acl sites_proibidos url_regex -i "/etc/squid/sites_proibidos"
acl usuarios src
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow acesso_livre
http_access deny sites_proibidos
http_access allow senha
http_access allow localhost
http_access allow redelocal
# Bloqueio de usuários fora da rede
http_access deny all
http_access allow usuarios
cache_log /var/log/squid/access.log