Guest User

Untitled

a guest
Aug 14th, 2020
80
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.70 KB | None | 0 0
  1. acl localnet src 172.16.0.0/12 # RFC 1918 local private network (LAN)
  2. acl SSL_ports port 443
  3. acl Safe_ports port 80 # http
  4. acl Safe_ports port 21 # ftp
  5. acl Safe_ports port 443 # https
  6. acl Safe_ports port 70 # gopher
  7. acl Safe_ports port 210 # wais
  8. acl Safe_ports port 1025-65535 # unregistered ports
  9. acl Safe_ports port 280 # http-mgmt
  10. acl Safe_ports port 488 # gss-http
  11. acl Safe_ports port 591 # filemaker
  12. acl Safe_ports port 777 # multiling http
  13. acl CONNECT method CONNECT
  14. http_access deny !Safe_ports
  15. http_access deny CONNECT !SSL_ports
  16. http_access allow localhost manager
  17. http_access deny manager
  18. include /etc/squid/conf.d/*
  19. http_access allow localhost
  20. http_access deny all
  21. http_port 172.16.30.16:3128 intercept
  22. https_port 172.16.30.16:3129 intercept ssl-bump options=ALL:NO_SSLv3 dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl/squid.pem key=/etc/squid/ssl/squid.key
  23. always_direct allow all
  24. ssl_bump server-first all
  25. ssl_bump none all
  26. sslcrtd_program /usr/lib/squid/security_file_certgen -s /var/lib/ssl_db -M 4MB
  27. sslproxy_cert_error allow all
  28. #sslproxy_flags DONT_VERIFY_PEER
  29. tls_outgoing_options flags=DONT_VERIFY_PEER
  30. coredump_dir /var/spool/squid
  31. refresh_pattern ^ftp: 1440 20% 10080
  32. refresh_pattern ^gopher: 1440 0% 1440
  33. refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
  34. refresh_pattern \/(Packages|Sources)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
  35. refresh_pattern \/Release(|\.gpg)$ 0 0% 0 refresh-ims
  36. refresh_pattern \/InRelease$ 0 0% 0 refresh-ims
  37. refresh_pattern \/(Translation-.*)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-ims
  38. refresh_pattern . 0 20% 4320
  39.  
  40.  
Add Comment
Please, Sign In to add comment