Шлюз 7.1Release, squid 2.7, PF.
В обход этого шлюза все открывается.
Проблема скорее всего со сквидом...
Конфиг:
В логах сквида:hierarchy_stoplist cgi-bin ?
acl QUERY urlpath_regex cgi-bin \?
no_cache deny QUERY
acl all src all
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl localnet src 192.168.0.0/23 # RFC1918 possible internal network
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl CONNECT method CONNECT
acl flv urlpath_regex -i \.flv$
acl mov urlpath_regex -i \.mov$
acl mp3 urlpath_regex -i \.mp3$
acl wav urlpath_regex -i \.wav$
acl ogg urlpath_regex -i \.ogg$
acl asf urlpath_regex -i \.asf$
acl avi urlpath_regex -i \.avi$
acl mpeg urlpath_regex -i \.mpeg$
acl inet_full src "/usr/local/etc/squid/inet_full"
acl deny_domains dstdomain "/usr/local/etc/squid/deny_domains"
acl work_time time MTWHF 10:30-18:00
# тут прописал адреса, которые не кешируем
acl no_cache src "/usr/local/etc/squid/no_cache"
cache deny no_cache
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access allow inet_full
http_access deny work_time deny_domains
http_access deny avi
http_access deny wav
http_access deny mp3
http_access deny mpeg
http_access deny flv
http_access deny mov
http_access deny ogg
http_access deny asf
http_access allow localnet
http_access deny all
icp_access allow localnet
icp_access deny all
http_port 3128
http_port 3129 transparent
access_log /squid/logs/access.log squid
cache_store_log none
cache_log /squid/logs/cache.log
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
acl shoutcast rep_header X-HTTP09-First-Line ^ICY.[0-9]
upgrade_http0.9 deny shoutcast
acl apache rep_header Server ^Apache
broken_vary_encoding allow apache
cache_mem 256 MB
cache_dir ufs /squid/cache 51200 64 512
Кэш пересоздавал, кеширование пробовал отключать.1242200201.640 32 192.168.0.10 TCP_MISS/200 920 GET http://80.70.111.222/css.css - DIRECT/80.70.111.222 text/plain
1242200201.690 152 192.168.0.10 TCP_MISS/200 4467 GET http://80.70.111.222/ - DIRECT/80.70.230.153 text/html
1242200201.839 143 192.168.0.10 TCP_MISS/200 367 GET http://80.70.111.222/jpg/arrow03.gif - DIRECT/80.70.111.222 image/gif
1242200201.917 223 192.168.0.10 TCP_MISS/200 2232 GET http://80.70.111.222/jpg/login_5.jpg - DIRECT/80.70.111.222 image/jpeg
1242200201.926 233 192.168.0.10 TCP_MISS/200 4101 GET http://80.70.111.222/jpg/login_3.jpg - DIRECT/80.70.111.222 image/jpeg
1242200201.980 281 192.168.0.10 TCP_MISS/200 2146 GET http://80.70.111.222/jpg/login_7.jpg - DIRECT/80.70.111.222 image/jpeg
1242200202.022 322 192.168.0.10 TCP_MISS/200 4084 GET http://80.70.111.222/jpg/login_8.jpg - DIRECT/80.70.111.222 image/jpeg
1242200214.831 2091 192.168.0.10 TCP_MISS/200 349 POST http://80.70.111.222/home.cgi - DIRECT/80.70.111.222 text/html