d3v1lg0

3.5.23.1 with open ssl ??????

Feb 16th, 2017
87
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 13.41 KB | None | 0 0
  1. #
  2. #
  3. acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
  4. acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
  5. acl localnet src fc00::/7 # RFC 4193 local private network range
  6. acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines
  7. acl localnet src 192.168.1.0/24
  8. acl localnet src 192.168.2.0/24
  9. acl localnet src 192.168.3.0/24
  10. acl localnet src 192.168.4.0/24
  11. acl localnet src 192.168.5.0/24
  12. #
  13. acl SSL_ports port 443
  14. acl SSL_ports port 5353
  15. acl Safe_ports port 21
  16. acl Safe_ports port 22
  17. acl Safe_ports port 53
  18. acl Safe_ports port 70
  19. acl Safe_ports port 80
  20. acl Safe_ports port 210
  21. acl Safe_ports port 280
  22. acl Safe_ports port 1025-65535
  23. acl Safe_ports port 443
  24. acl Safe_ports port 488
  25. acl Safe_ports port 591
  26. acl Safe_ports port 777
  27. acl Safe_ports port 5353
  28. acl Safe_ports port 18901-18909
  29. acl Safe_ports port 1818
  30. acl Safe_ports port 39190
  31. acl Safe_ports port 40000-40010
  32. acl Safe_ports port 7777
  33. acl Safe_ports port 19101
  34. acl Safe_ports port 27780
  35. acl Safe_ports port 29000
  36. acl Safe_ports port 22100
  37. acl Safe_ports port 5121
  38. acl Safe_ports port 6000-6152
  39. acl Safe_ports port 2001
  40. acl Safe_ports port 9601-9602
  41. acl Safe_ports port 8085
  42. acl Safe_ports port 11011-11041
  43. acl Safe_ports port 13413
  44. acl Safe_ports port 19000
  45. acl Safe_ports port 5105
  46. acl Safe_ports port 10009
  47. acl Safe_ports port 12060-12070
  48. acl Safe_ports port 6000-6001
  49. acl Safe_ports port 29200
  50. acl Safe_ports port 10402
  51. acl Safe_ports port 9600
  52. acl Safe_ports port 15002
  53. acl Safe_ports port 16402-16502
  54. acl Safe_ports port 5126
  55. acl Safe_ports port 3010
  56. acl Safe_ports port 11031
  57. acl Safe_ports port 11440-11460
  58. acl Safe_ports port 11100-11125
  59. acl Safe_ports port 4300
  60. acl Safe_ports port 12011
  61. acl Safe_ports port 12110
  62. acl Safe_ports port 15001
  63. acl Safe_ports port 15002
  64. acl Safe_ports port 7341
  65. acl Safe_ports port 7451
  66. acl Safe_ports port 7808
  67. acl Safe_ports port 30000
  68. acl Safe_ports port 9001
  69. acl Safe_ports port 9030
  70. acl Safe_ports port 953
  71. acl Safe_ports port 42051-42052
  72. acl Safe_ports port 36567
  73. acl Safe_ports port 8001
  74. acl Safe_ports port 14000-14050
  75. acl Safe_ports port 27019
  76. acl Safe_ports port 28901-28920
  77. acl Safe_ports port 7201-7208
  78. acl Safe_ports port 17001-17002
  79. acl Safe_ports port 14300-14440
  80. acl Safe_ports port 15100-15150
  81. acl Safe_ports port 7770-7790
  82. acl Safe_ports port 16320-16340
  83. acl Safe_ports port 9000-9160
  84. acl Safe_ports port 7200
  85. acl Safe_ports port 7400
  86. acl Safe_ports port 7106
  87. acl Safe_ports port 7999
  88. acl Safe_ports port 47611
  89. acl Safe_ports port 36567
  90. acl Safe_ports port 10087
  91. acl Safe_ports port 27000-27050
  92. acl Safe_ports port 27014-27050
  93. acl Safe_ports port 4380
  94. acl Safe_ports port 3478
  95. acl Safe_ports port 4379
  96. acl Safe_ports port 8890
  97. acl Safe_ports port 9339
  98. acl Safe_ports port 8890
  99. acl Safe_ports port 7200-7210
  100. acl Safe_ports port 7450-7460
  101. acl Safe_ports port 8000
  102. acl Safe_ports port 64990-65010
  103. acl CONNECT method CONNECT
  104. #ads
  105. acl adsites url_regex -i "/etc/squid/adslist.txt"
  106. acl ads dstdom_regex "/etc/squid/ad_block.txt"
  107. http_access deny ads
  108. http_access deny adsites
  109. # ACCESS RULES
  110. http_access deny !Safe_ports
  111. http_access deny CONNECT !SSL_ports
  112. http_access allow localnet
  113. http_access allow localhost
  114. http_access deny all
  115. # LISTENING PORT SQUID
  116. #http_port 127.0.0.1:3128 ssl-bump cert=/etc/squid/cert/de-isle.blogspot.co.id.cert key=/etc/squid/cert/de-isle.blogspot.co.id generate-host-certificates=on version=1 options=NO_SSLv2,NO_SSLv3,SINGLE_DH_USE
  117. http_port 3128
  118. http_port 3129 tproxy
  119. https_port 127.0.0.1:3130 cert=/etc/squid/cert/de-isle.blogspot.co.id.cert key=/etc/squid/cert/de-isle.blogspot.co.id ssl-bump intercept generate-host-certificates=on version=1 options=NO_SSLv2,NO_SSLv3,SINGLE_DH_USE
  120. #
  121. # SSL Bump Config
  122. ssl_bump stare all
  123. ssl_bump bump all
  124. #
  125. #http_port 3128
  126. #https_port 3131 tproxy ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_certs/squid.crt key=/etc/squid/ssl_certs/squid.key cipher=ECDHE-RSA-RC4-SHA:ECDHE-RSA-AES128-SHA:DHE-RSA-AES128-SHA:DHE-RSA-CAMELLIA128-SHA:AES128-SHA:RC4-SHA:HIGH:!aNULL:!MD5:!ADH
  127. # CONNECTION HANDLING
  128. qos_flows local-hit=0x30
  129. collapsed_forwarding on
  130. balance_on_multiple_ip on
  131. detect_broken_pconn on
  132. client_persistent_connections off
  133. server_persistent_connections on
  134. # DNS OPTIONS
  135. #dns_packet_max 4096
  136. dns_nameservers 127.0.0.1
  137. dns_defnames on
  138. dns_v4_first on
  139. connect_retries 2
  140. negative_dns_ttl 1 second
  141. quick_abort_min 0
  142. quick_abort_max 0
  143. quick_abort_pct 80
  144. range_offset_limit 0
  145. ipcache_low 98
  146. ipcache_high 99
  147. ipcache_size 4096
  148. fqdncache_size 2048
  149. pipeline_prefetch 0
  150. # MISCELEANOUS
  151. memory_pools off
  152. reload_into_ims on
  153. max_filedescriptors 65536
  154. # CACHE MANAGEMENT
  155. cache_mem 512 MB
  156. maximum_object_size_in_memory 128 KB
  157. memory_replacement_policy heap GDSF
  158. cache_dir ufs /cache/0 6000 14 256
  159. cache_dir ufs /cache/1 6000 14 256
  160. cache_dir ufs /cache/2 6000 14 256
  161. coredump_dir /cache
  162. cache_mgr fox.skd@gmail.com
  163. visible_hostname de-isle.blogspot.co.id
  164. minimum_object_size 0 KB
  165. maximum_object_size 1 GB
  166. read_ahead_gap 64 KB #Amount of data to buffer from server to client
  167. cache_replacement_policy heap LFUDA
  168. store_dir_select_algorithm least-load
  169. cache_swap_low 90
  170. cache_swap_high 95
  171. # LOG FILE OPTIONS
  172. logfile_daemon /usr/lib/squid/log_file_daemon
  173. access_log daemon:/var/log/squid/access.log squid
  174. cache_log /dev/null #cache_log /var/log/squid/cache.log(to enable)
  175. cache_store_log none
  176. logfile_rotate 3
  177. pid_filename /var/run/squid.pid
  178. # FILTERING HTTPS
  179. acl 1 dstdomain .fbcdn.net .akamaihd.net .fbsbx.com
  180. #acl 2a dstdomain .mahadana.com .mql4.com .metaquotes.net
  181. acl 2 url_regex -i ^https?:\/\/attachment\.fbsbx\.com\/.*\?(id=[0-9]*).*
  182. acl 2 url_regex -i \.fbsbx\.com\/.*\/(.*\.(unity3d|pak|zip|exe|dll|jpg|png|gif|swf)/)$
  183. acl 2 url_regex -i ^https?:\/\/.*\.ytimg\.com(.*\.(webp|jpg|gif))
  184. acl 2 url_regex -i ^https?:\/\/([^\.]*)\.yimg\.com\/(.*)
  185. acl 2 url_regex -i ^https?:\/\/.*\.gstatic\.com\/images\?q=tbn\:(.*)
  186. acl 2 url_regex -i ^https?:\/\/.*\.reverbnation\.com\/.*\/(ec_stream_song|download_song_direct|stream_song)\/([0-9]*).*
  187. acl 2 url_regex -i ^https?:\/\/([a-z0-9.]*)(\.doubleclick\.net|\.quantserve\.com|.exoclick\.com|interclick.\com|\.googlesyndication\.com|\.auditude\.com|.visiblemeasures\.com|yieldmanager|cpxinteractive)(.*)
  188. acl 2 url_regex -i ^https?:\/\/(.*?)\/(ads)\?(.*?)
  189. acl 2 url_regex -i ^https?:\/\/.*steampowered\.com\/.*\/([0-9]+\/(.*))
  190. acl 3 url_regex -i ^https?:\/\/(.*?)\/speedtest\/.*\.(jpg|txt|png|gif|swf)\?.*
  191. acl 3 url_regex -i speedtest\/.*\.(jpg|txt|png|gif|swf)\?.*
  192. acl 4 url_regex -i reverbnation.*audio_player.*ec_stream_song.*$
  193. acl 5 url_regex -i utm.gif.*
  194. acl 6 url_regex -i c.android.clients.google.com.market.GetBinary.GetBinary.*
  195. acl 7 url_regex -i youtube.*(ptracking|stream_204|player_204|gen_204).*$
  196. acl 7 url_regex -i \.c\.(youtube|google)\.com\/(get_video|videoplayback|videoplay).*$
  197. acl 7 url_regex -i (youtube|google).*\/videoplayback\?.*
  198. acl 8 http_status 302
  199. acl getmethod method GET
  200. #
  201. ssl_bump splice localhost
  202. #
  203. sslcrtd_program /usr/lib/squid/ssl_crtd -s /var/lib/squid/ssl_db -M 4MB
  204. sslcrtd_children 16 startup=1 idle=1
  205. sslproxy_capath /etc/ssl/certs
  206. sslproxy_cert_error allow all
  207. sslproxy_flags DONT_VERIFY_PEER #this line fixing www.gmail.com, mail.yahoo.com for some errors
  208. always_direct allow all
  209. ssl_unclean_shutdown on
  210. # STORE ID
  211. store_id_program /usr/bin/perl /etc/squid/store-id.pl
  212. store_id_children 10 startup=5 idle=2 concurrency=10
  213. store_id_access allow 1
  214. store_id_access allow 2
  215. store_id_access allow 3
  216. store_id_access allow 4
  217. store_id_access allow 5
  218. store_id_access allow 6
  219. store_id_access allow 7
  220. store_miss deny 7 8
  221. send_hit deny 7 8
  222. store_id_access deny all
  223. # TUNNING CACHE
  224. max_stale 1 years
  225. vary_ignore_expire on
  226. shutdown_lifetime 10 seconds
  227. # REFRESH PATTERN
  228. refresh_pattern -i https?:\/\/.*\.xx\.fbcdn\.net\/.*\.(jpg|png) 43830 99% 259200 override-expire override-lastmod ignore-reload
  229. refresh_pattern static\.(xx|ak)\.fbcdn\.net*\.(jpg|gif|png) 241920 99% 241920 ignore-reload override-expire ignore-no-store
  230. refresh_pattern ^https?\:\/\/profile\.ak\.fbcdn.net*\.(jpg|gif|png) 241920 99% 241920 ignore-reload override-expire ignore-no-store
  231. refresh_pattern (akamaihd|fbcdn)\.net 14400 99% 518400 ignore-no-store ignore-private ignore-reload ignore-must-revalidate store-stale
  232. refresh_pattern (audio|video)\/(webm|mp4) 129600 99% 129600 ignore-reload override-expire override-lastmod ignore-must-revalidate ignore-private ignore-no-store ignore-auth store-stale
  233. refresh_pattern -i \/speedtest\/.*\.(txt|jpg|png|swf) 0 99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
  234. refresh_pattern -i reverbnation.com 1440 99% 14400 override-expire override-lastmod ignore-no-cache ignore-private ignore-must-revalidate ignore-reload store-stale
  235. refresh_pattern -i (yimg|twimg)\.com\.* 1440 100% 129600 override-expire ignore-reload reload-into-ims
  236. refresh_pattern -i (ytimg|ggpht)\.com\.* 1440 80% 129600 override-expire override-lastmod ignore-auth ignore-reload reload-into-ims
  237. refresh_pattern -i (get_video\?|videoplayback\?|videodownload\?|\.mp4|\.webm|\.flv|((audio|video)\/(webm|mp4))) 241920 100% 241920 override-expire ignore-reload ignore-private ignore-no-store ignore-must-revalidate reload-into-ims ignore-auth store-stale
  238. refresh_pattern -i ^https?\:\/\/.*\.googlevideo\.com\/videoplayback.* 10080 99% 43200 override-lastmod override-expire ignore-reload reload-into-ims ignore-private reload-into-ims ignore-auth store-stale
  239. refresh_pattern ^\.*(streamate.doublepimp.com.*\.js\?|utm\.gif|ads\?|rmxads\.com|ad\.z5x\.net|bh\.contextweb\.com|bstats\.adbrite\.com|a1\.interclick\.com|ad\.trafficmp\.com|ads\.cubics\.com|ad\.xtendmedia\.com|\.googlesyndication\.com|advertising\.com|yieldmanager|game-advertising\.com|pixel\.quantserve\.com|adperium\.com|doubleclick\.net|adserving\.cpxinteractive\.com|syndication\.com|media.fastclick.net).* 1440 99% 14400 ignore-private override-expire ignore-reload ignore-auth max-stale=1440
  240. refresh_pattern \.(ico|video-stats) 1440 99% 14400 override-expire ignore-reload ignore-private ignore-auth override-lastmod ignore-must-revalidate
  241. refresh_pattern ^http://((cbk|mt|khm|mlt|tbn)[0-9]?)\.google\.co(m|\.uk|\.id) 1440 99% 14400 override-expire override-lastmod ignore-reload ignore-private ignore-auth ignore-must-revalidate
  242. refresh_pattern vid\.akm\.dailymotion\.com.*\.on2\? 1440 99% 14400 override-expire override-lastmod
  243. refresh_pattern galleries\.video(\?|sz) 1440 99% 14400 override-expire ignore-reload ignore-must-revalidate ignore-private
  244. refresh_pattern \.wikimapia\.org\/? 1440 99% 14400 override-expire override-lastmod ignore-reload ignore-private
  245. refresh_pattern -i (livescore.com|goal.com|bobet) 0 50% 60
  246. refresh_pattern (photobucket|pbsrc|flickr|yimg|ytimg|twimg|gravatar)\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private
  247. refresh_pattern (zynga|topeleven|ninjasaga|mafiawars|cityville|farmville|crowdstar|spilcdn|agame|popcap)\.com/.* 1440 99% 14400 override-expire ignore-reload ignore-private
  248. refresh_pattern -i \.(3gp|7z|ace|asx|bin|deb|divx|dvr-ms|ram|rpm|exe|inc|cab|qt) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  249. refresh_pattern -i \.(rar|jar|gz|tgz|bz2|iso|m1v|m2(v|p)|mo(d|v)|arj|lha|lzh|zip|tar|iop|nzp|pak|mar|msp) 10080 80% 10080 override-expire override-lastmod reload-into-ims ignore-reload
  250. refresh_pattern -i \.(jp(e?g|e|2)|gif|pn[pg]|bm?|tiff?|ico|swf|dat|ad|txt|dll) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  251. refresh_pattern -i \.(avi|ac4|mp(e?g|a|e|1|2|3|4)|mk(a|v)|ms(i|u|p)|og(x|v|a|g)|rm|r(a|p)m|snd|vob|webm) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  252. refresh_pattern -i \.(pp(t?x)|s|t)|pdf|rtf|wax|wm(a|v)|wmx|wpl|cb(r|z|t)|xl(s?x)|do(c?x)|flv|x-flv) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  253. refresh_pattern -i \.(3gp|7z|ace|asx|bin|deb|cup|dvr-ms|ram|rpm|exe|inc|cab|qt) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  254. refresh_pattern -i \.(rar|jar|gz|tgz|bz2|iso|m1v|m2(v|p)|mo(d|v)|arj|lha|lzh|zip|tar|pak|cup) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  255. refresh_pattern -i \.(jp(e?g|e|2)|gif|pn[pg]|bm?|tiff?|ico|swf|dat|ad|txt|dll) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  256. refresh_pattern -i \.(avi|ac4|mp(e?g|a|e|1|2|3|4)|mk(a|v)|ms(i|u|p)|og(x|v|a|g)|rm|r(a|p)m|snd|vob) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  257. refresh_pattern -i \.(pp(t?x)|s|t)|pdf|rtf|wax|wm(a|v)|wmx|wpl|cb(r|z|t)|xl(s?x)|do(c?x)|flv|x-flv) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  258. refresh_pattern -i .(html|htm|css|js|xml)$ 1440 75% 40320
  259. refresh_pattern -i .index.(html|htm)$ 0 75% 43800
  260. refresh_pattern -i ^http.*squid\.internal.* 43200 100% 799000 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth
  261. #KEEP THESE LINES AT BOTTOM OF CONFIGURATION
  262. refresh_pattern ^ftp: 1440 20% 10080
  263. refresh_pattern ^gopher: 1440 0% 1440
  264. refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
  265. refresh_pattern . 0 20% 4320
Add Comment
Please, Sign In to add comment