Вот конфиг сквида
Код: Выделить всё
auth_param basic program /usr/local/libexec/squid/ncsa_auth /usr/local/etc/squid/ncsa.sams
auth_param basic children 5
auth_param basic realm IntWay WiFi Server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
http_port 8080
icp_port 0
hierarchy_stoplist cgi-bin ?
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
cache_mem 128 MB
maximum_object_size 8092 KB
maximum_object_size_in_memory 512 KB
error_directory /usr/local/etc/squid/errors/Russian-1251
cache_dir ufs /usr/local/squid/cache 2048 64 256
access_log /usr/local/squid/logs/access.log squid
cache_log /usr/local/squid/logs/cache.log
cache_store_log /usr/local/squid/logs/store.log
cache_mgr h-a-k-e-r@inbox.ru
visible_hostname inet.local.biz
tcp_outgoing_address 10.100.2.1
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern . 0 20% 4320
#TAG: acl
acl all src 0.0.0.0/0.0.0.0
acl localhost src 127.0.0.0/8
acl squidusers proxy_auth REQUIRED
#TAG: http_access
http_access allow squidusers
http_access allow localhost
http_access deny all
http_port 127.0.0.1:8080
coredump_dir /usr/local/squid/cache
pid_filename /usr/local/squid/logs/squid.pid
вот правила ipfw на всякий
Код: Выделить всё
00050 check-state
00100 allow ip from any to any via lo0
00400 deny ip from any to 127.0.0.0/8
00450 deny ip from 127.0.0.0/8 to any
00500 deny ip from 10.100.1.0/24 to any in via rl0
00550 deny ip from 10.100.2.0/24 to any in via rl1
00610 deny ip from any to 172.16.0.0/12 in via rl0
00620 deny ip from any to 0.0.0.0/8 in via rl0
00630 deny ip from any to 169.254.0.0/16 in via rl0
00700 deny ip from any to 224.0.0.0/4 in via rl0
00710 deny ip from any to 240.0.0.0/4 in via rl0
00800 deny icmp from any to any frag
00810 deny icmp from any to any in icmptypes 5,9,13,14,15,16,17
00900 reject tcp from any to any tcpflags syn,fin,ack,psh,rst,urg
00910 reject tcp from any to any tcpflags !syn,!fin,!ack,!psh,!rst,!urg
00920 reject tcp from any to any not established tcpflags fin
00930 reject log logamount 100 ip from any to any not verrevpath in
01000 deny tcp from any to any dst-port 113 in via rl0
01100 deny tcp from any to any dst-port 137 in via rl0
01110 deny tcp from any to any dst-port 138 in via rl0
01120 deny tcp from any to any dst-port 139 in via rl0
01200 deny log logamount 100 icmp from any to 255.255.255.255 in via rl0
01210 deny log logamount 100 icmp from any to 255.255.255.255 out via rl0
01300 fwd 127.0.0.1,8080 tcp from 10.100.1.0/24 to any dst-port 80 via rl0
01400 divert 8668 ip from 10.100.1.0/24 to any out via rl0
01450 divert 8668 ip from any to 10.100.2.1 in via rl0
01510 deny ip from 172.16.0.0/12 to any out via rl0
01520 deny ip from 0.0.0.0/8 to any out via rl0
01530 deny ip from 169.254.0.0/16 to any out via rl0
01600 deny ip from 224.0.0.0/4 to any out via rl0
01650 deny ip from 240.0.0.0/4 to any out via rl0
01750 allow icmp from any to any icmptypes 0,8,11
01800 allow ip from any to 10.100.1.0/24 in via rl1
01850 allow ip from 10.100.1.0/24 to any out via rl1
01900 allow tcp from any to any established
02000 allow udp from any to 10.100.2.1 dst-port 53 in via rl0
02010 allow udp from 10.100.2.1 53 to any out via rl0
02020 allow udp from any 53 to 10.100.2.1 in via rl0
02030 allow udp from 10.100.2.1 to any dst-port 53 out via rl0
02100 allow tcp from any to 10.100.2.1 dst-port 53 in via rl0
02200 allow tcp from any to 10.100.2.1 dst-port 35665 in via rl0 setup
02700 deny log logamount 100 tcp from any to 10.100.2.1 in via rl0 setup
02900 allow tcp from 10.100.2.1 to any out via rl0 setup
02950 allow tcp from any to 10.100.2.1 in via rl1 setup
03000 allow tcp from 10.100.1.0/24 to any dst-port 25,110,443,5190 in via rl1 setup
03010 allow tcp from 10.100.1.101 to any in via rl1 setup
03020 allow tcp from 10.100.1.102 to any in via rl1 setup
03030 allow tcp from 10.100.1.103 to any in via rl1 setup
03040 allow tcp from 10.100.1.104 to any in via rl1 setup
65534 deny ip from any to any
65535 allow ip from any to any
Кстати вот что написано в access.log
Код: Выделить всё
0 10.100.1.103 TCP_DENIED 407 1707 GET http://qip.ru/download/qipinfium9030.exe - NONE /- text/html