Squid from the scratch: Unterschied zwischen den Versionen

Aus Xinux Wiki
Zur Navigation springen Zur Suche springen
 
(15 dazwischenliegende Versionen von einem anderen Benutzer werden nicht angezeigt)
Zeile 1: Zeile 1:
 
*[[Squid Grundlagen]]
 
*[[Squid Grundlagen]]
 +
*[[Squid Anbindungen]]
 +
*[[Proxy Konzepte]]
 
*[[Squid erste Schritte]]
 
*[[Squid erste Schritte]]
−
 
+
*[[Squid handling]]
−
 
+
*[[Squid ACL Basic]]
−
=Lan und DMZ freischalten=
+
*[[Squid acl types]]
−
==acl bilden==
+
*[[Squid Logging]]
−
acl lan src 172.16.150.0/24
+
*[[Squid Authentifizierung]]
−
acl dmz src  10.40.115.0/24
+
*[[Squid zeitliche Beschränkung]]
−
 
+
*[[Squid https aufbrechen]]
−
==acl anwenden(Reihenfolge ist entscheidend)==
+
*[[Squid und ClamAV]]
−
http_access allow lan
+
*[[Iptables mit Squid Transparenter Proxy]]
−
http_access allow dmz
+
*[[Proxy Pac]]
−
=Squid handling=
+
*[[Proxy auf Linux Console]]
−
==Squid stop==
 
−
*systemctl stop squid
 
−
==Squid start==
 
−
*systemctl start squid
 
−
==Squid restart==
 
−
*systemctl restart squid
 
−
==Squid reload==
 
−
*systemctl reload squid
 
−
 
 
−
==Squid status==
 
−
*systemctl status squid
 
−
==Squidport checken==
 
−
*netstat -ltnp | grep 3128
 
−
tcp6      0      0 :::3128                :::*                    LISTEN      4396/(squid-1)
 
−
==Squidprozesse checken==
 
−
*ps -elf | grep squid
 
−
<pre>
 
−
0 S root      3010  2361  0  80  0 - 14458 poll_s 11:34 pts/1    00:00:00 vim squid.conf
 
−
1 S root      4394    1  0  80  0 - 27319 wait  15:18 ?        00:00:00 /usr/sbin/squid -YC -f /etc/squid/squid.conf
 
−
4 S proxy    4396  4394  0  80  0 - 37351 ep_pol 15:18 ?        00:00:00 (squid-1) -YC -f /etc/squid/squid.conf
 
−
4 S proxy    4397  4396  0  80  0 -  3320 unix_s 15:18 ?        00:00:00 (logfile-daemon) /var/log/squid/access.log
 
−
</pre>
 
−
=Webseite einschränken=
 
−
==Acl bilden==
 
−
acl facebook url_regex -i facebook
 
−
 
 
−
==Acl anwenden==
 
−
http_access deny facebook
 
−
 
 
−
=Logs checken=
 
−
*tail -f /var/log/squid/access.log
 
−
1490008947.188      2 192.168.244.144 TCP_MISS/503 4447 GET http://detectportal.firefox.com/success.txt - HIER_NONE/- text/html
 
−
=Blacklist erstellen=
 
−
*Wird erstellt, um diverse Seiten zu deaktivieren
 
−
==http-liste erstellen==
 
−
<pre>
 
−
vi /etc/squid/bad-sites.list
 
−
</pre>
 
−
==http-seiten hinzufügen==
 
−
<pre>
 
−
facebook.com
 
−
pr0gramm.com
 
−
</pre>
 
−
==erstellen der acl==
 
−
<pre>
 
−
acl bad-sites  url_regex -i "/etc/squid/bad-sites.list"
 
−
</pre>
 
−
==erstellen der http_access==
 
−
<pre>
 
−
http_access deny bad-sites
 
−
</pre>
 
−
 
 
−
=Authentifizierung=
 
−
*Wird genutzt um sich bei dem Browser zu authentifizieren, und somit bestimmte Seiten freigeschaltet werden können
 
−
==User anlegen==
 
−
<pre>
 
−
root@batman-ThinkPad-R60:~# htpasswd -c /etc/squid/passwordfile sterling
 
−
New password:
 
−
Re-type new password:
 
−
Adding password for user sterling
 
−
</pre>
 
−
==Konfiguration der Authentifizierung==
 
−
<pre>
 
−
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwordfile
 
−
auth_param basic children 20 startup=0 idle=1
 
−
auth_param basic concurrency 0
 
−
auth_param basic credentialsttl 500
 
−
auth_param basic realm xinux-user-access
 
−
auth_param basic casesensitive off
 
−
</pre>
 
−
==erstellen der acl==
 
−
<pre>
 
−
acl xinux-user proxy_auth REQUIRED
 
−
</pre>
 
−
==erstellen der http_access==
 
−
<pre>
 
−
http_access allow xinux-user
 
−
</pre>
 
−
*Nun müssen sich alle erstellten User authentifizieren
 
−
 
 
−
=Time=
 
−
*Um eine Website zu einer gewissen Zeit freizugeben, benutzt man "time"
 
−
==erstellen der acl==
 
−
<pre>
 
−
acl break-time time 12:00-13:00
 
−
</pre>
 
−
==erstellen der http_access==
 
−
<pre>
 
−
http_access allow bad-sites break-time
 
−
</pre>
 
−
*In diesem Beispiel werden die bad-sites um 12:00-13:00 freigeschaltet
 

Aktuelle Version vom 7. August 2023, 21:43 Uhr