Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # Server
- cache_effective_user proxy
- cache_effective_group proxy
- shutdown_lifetime 1 seconds
- coredump_dir /var/spool/squid
- # ACL's
- acl SSL_ports port 443
- acl SSL_ports port 64000
- acl SSL_ports port 64001
- acl SSL_ports port 64002
- acl SSL_ports port 64003
- acl SSL_ports port 64004
- acl CONNECT method CONNECT
- acl Safe_ports port 21 # ftp
- acl Safe_ports port 70 # gopher
- acl Safe_ports port 80 # http
- acl Safe_ports port 210 # wais
- acl Safe_ports port 280 # http-mgmt
- acl Safe_ports port 443 # https
- acl Safe_ports port 488 # gss-http
- acl Safe_ports port 591 # filemaker
- acl Safe_ports port 777 # multiling http
- acl Safe_ports port 1025-64999 # unregistered ports
- http_access deny !Safe_ports
- http_access deny CONNECT !SSL_ports
- http_access deny manager localhost
- http_access deny manager
- http_access allow localhost
- http_access allow all
- # Proxy
- # РАБОТАЮТ ОБА ПРАВИЛА
- https_port 8.8.8.8:64000 tls-cert=/etc/letsencrypt/.../fullchain.pem tls-key=/etc/letsencrypt/.../privkey.pem tls-dh=/etc/squid/squidCAdh.pem options=SINGLE_DH_USE,SINGLE_ECDH_USE
- http_port 10.10.10.10:64001 tls-cert=/etc/squid/squidCA.pem tls-dh=/etc/squid/squidCAdh.pem options=SINGLE_DH_USE,SINGLE_ECDH_USE
- # НЕ РАБОТАЕТ
- https_port 10.10.30.10:64002 tls-cert=/etc/squid/squidCA.pem tls-dh=/etc/squid/squidCAdh.pem options=SINGLE_DH_USE,SINGLE_ECDH_USE
- # РАБОТАЮТ ОБА ПРАВИЛА
- http_port 10.10.30.10:64003 intercept tls-cert=/etc/squid/squidCA.pem tls-dh=/etc/squid/squidCAdh.pem options=SINGLE_DH_USE,SINGLE_ECDH_USE
- https_port 10.10.30.10:64004 intercept ssl-bump tls-cert=/etc/squid/squidCA.pem tls-dh=/etc/squid/squidCAdh.pem options=SINGLE_DH_USE,SINGLE_ECDH_USE
- sslproxy_cert_error allow all
- always_direct allow all
- acl step1 at_step SslBump1
- ssl_bump peek step1
- ssl_bump bump all
- # Refresh patterns
- refresh_pattern ^ftp: 1440 20% 10080
- refresh_pattern ^gopher: 1440 0% 1440
- refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
- refresh_pattern . 0 20% 4320
- # Cache
- cache_mem 2048 MB
- maximum_object_size_in_memory 32 MB
- memory_replacement_policy heap LFUDA
- cache_dir rock /var/spool/squid 2048
- maximum_object_size 32 MB
- cache_replacement_policy heap LFUDA
- ipcache_size 4096
- fqdncache_size 4096
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement