saulobr88
(usa Ubuntu)
Enviado em 20/01/2010 - 10:13h
Fala galera do VOL !!!
Primeiro gostaria de agradecer a todos os participantes do VOL por seguir tão bem a filosofia do software livre, sempre recomendo o VOL como fonte de pesquisa a todas as pessoas que me perguntam.
Pois bem, tenho um squid com autenticação via pam rodando num pequeno Gateway para um setor daqui da empresa, instalei o squidGuard para controlar as URLs por categoria porém o squid não está redirecionando as requisições para o squidGuard, alguem pode me ajudar com esse problema?
Segue squid.conf:
#####squid.conf############################
http_port 3128
hierarchy_stoplist cgi-bin ?
access_log /var/log/squid/access.log squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
acl apache rep_header Server ^Apache
broken_vary_encoding allow apache
extension_methods REPORT MERGE MKACTIVITY CHECKOUT
hosts_file /etc/hosts
coredump_dir /var/spool/squid
visible_hostname web-proxy
logformat meulog IP do cliente: %>a - Username: %un - Horario: [%tl]
access_log /var/log/squid/access.log meulog
url_rewrite_program /usr/bin/squidGuard -c /etc/squid/squidGuard.conf
url_rewrite_children 5
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl hora-almoco time MTWHF 12:00-14:00 # de almoco normal
acl hora-comercial time MTWHF 08:00-12:00
acl hora-comercial time MTWHF 14:00-18:00
acl hora-comercial-completa time MTWHF 08:00-18:00
acl localnet src 192.168.56.0/24 # RFC1918 possible internal network - VirtualBox
acl localnet src 192.168.0.0/24 # RFC1918 possible internal network
acl SSL_ports port 443 # https
acl SSL_ports port 563 # snews
acl SSL_ports port 873 # rsync
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 631 # cups
acl Safe_ports port 873 # rsync
acl Safe_ports port 901 # SWAT
acl purge method PURGE
acl CONNECT method CONNECT
auth_param basic program /usr/lib/squid/pam_auth
auth_param basic children 5
auth_param basic realm Controle de Acessos Web, Use-o com responsabilidade
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
acl www_total proxy_auth "/etc/squid/groups/www_total"
acl www_controlado proxy_auth "/etc/squid/groups/www_controlado"
acl liberado url_regex -i "/etc/squid/paginas-liberadas"
acl proibido url_regex -i "/etc/squid/paginas-bloqueadas"
http_access allow manager localhost
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access allow www_total
http_access deny proibido !liberado
http_access allow www_controlado
icp_access allow localnet
error_directory /usr/share/squid/errors/Portuguese
##### End of file ##########################
log do squid:
#### access.log ############################
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:30 -0200]
1263915990.820 1345 192.168.56.11 TCP_MISS/200 34899 CONNECT
www.centos.org:443 user01 DIRECT/72.232.19
4.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:30 -0200]
1263915991.502 651 192.168.56.11 TCP_MISS/200 2713 CONNECT
www.centos.org:443 user01 DIRECT/72.232.194
.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:31 -0200]
1263915992.290 631 192.168.56.11 TCP_MISS/200 5241 CONNECT
www.centos.org:443 user01 DIRECT/72.232.194
.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:32 -0200]
1263915992.308 627 192.168.56.11 TCP_MISS/200 3721 CONNECT
www.centos.org:443 user01 DIRECT/72.232.194
.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:32 -0200]
1263915992.525 841 192.168.56.11 TCP_MISS/200 9225 CONNECT
www.centos.org:443 user01 DIRECT/72.232.194.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:32 -0200]
1263915992.721 1039 192.168.56.11 TCP_MISS/200 15337 CONNECT
www.centos.org:443 user01 DIRECT/72.232.194.162 -
IP do cliente: 192.168.56.11 - Username: user01 - Horario: [19/Jan/2010:13:46:32 -0200]
1263915993.241 618 192.168.56.11 TCP_MISS/200 9681 GET
http://www.centos.org/donors/hcs-centos-servers-240x60.gif user01 DIRECT/72.232.194.162 image/gif
#### End of File ############################
Desde já agradeço.