08-24-2012
[solved] Block access to all sites except one using Squid
I need a Squid config that allows access to only one domain: .example.com
Traffic should only be allowed through if coming from 10.100.0.0/24
and only port 80 (http) and port 443 (https) traffic should be allowed through, but again, only to this ONE domain.
It Must be Squid (no iptables or other).
Using Squid 3.1 on Centos 6
Thanks!
9 More Discussions You Might Find Interesting
1. UNIX and Linux Applications
Hi ,
I am new user.
As you know when acl is defined in /etc/squid/squid.conf file according to its http_access users are able to access internet.
Before that .htaccess asks them to access internet.
It is fine.
I saw in some customised linux servers in place of .htaccess login ,html web page... (1 Reply)
Discussion started by: sandeepvson
1 Replies
2. UNIX for Advanced & Expert Users
Hi guys
On FC9 we are running squid-3.0.STABLE2-2.fc9.i386
HTTP traffic works fine, no problems there.
When I try to access a secure site, IE, Chrome and Firefox says the page cannot be loaded.
I do not see any log entries in the squid access log or the servers messages file.
... (3 Replies)
Discussion started by: wbdevilliers
3 Replies
3. IP Networking
Hi,
How i can block images from a particular site with squid?
for example i want images from www.yahoo.com not displayed but other site content displayed to user?
and
how can i authenticate squid users (for e.g webproxy) with windows server 2003 domain controller (Active Directory)
... (0 Replies)
Discussion started by: skynet_boy
0 Replies
4. Emergency UNIX and Linux Support
Hi all
We have squid-2.5.STABLE11-3.FC4 running in our environment.
LDAP authentication works fine. Active Directory 2003 Users are prompted to enter credentials every time they access the net. The system works perfectly, but I need to configure Squid to block users in a specific AD group.... (1 Reply)
Discussion started by: wbdevilliers
1 Replies
5. IP Networking
Hi i have created a proxy with squid and i need to block all domains of yahoo let's say . i have to configure squid.conf but idk how.. (1 Reply)
Discussion started by: g0dlik3
1 Replies
6. UNIX for Dummies Questions & Answers
squid 3.1.8 on fedora14
http_port 3128 transparent no-connection-auth
icp_port 0
icp_query_timeout 0
mcast_icp_query_timeout 2000
dead_peer_timeout 10 seconds
log_fqdn off
cache_dir aufs /var/spool/squid 1024 16 256
cache_access_log /var/log/squid/access.log
cache_access_log ... (0 Replies)
Discussion started by: slackman
0 Replies
7. IP Networking
Hello,
I have a pretty useless satellite link at home (far from any civilization), so I wanted to set up caching in order to speed things up. My Squid 2.6 runs "3128 transparent" and is set up quite well on a separate machine.
I also have my dd-wrt router to move all port 80 traffic through... (0 Replies)
Discussion started by: theWojtek
0 Replies
8. UNIX for Advanced & Expert Users
Can someone please give me the conf file line to allow access to myexample.com and only that site, and only through http and https?
So far I have only that site accessible via http, but all https sites are opened.
Squid 3.1 on Cent 6
---------- Post updated at 12:06 PM ---------- Previous... (0 Replies)
Discussion started by: glev2005
0 Replies
9. Proxy Server
Dear all experts here,
:)
I would like to install a proxy server on Linux server to perform solely to control the access of Web server.
In this case, some of my vendor asked me to try Squid and I have installed it onto my Linux server.
I would like know how can I set the configuration to... (1 Reply)
Discussion started by: kwliew999
1 Replies
LEARN ABOUT CENTOS
cachemgr.cgi
cachemgr.cgi(8) System Manager's Manual cachemgr.cgi(8)
NAME
cachemgr.cgi - Squid HTTP proxy manager CGI web interface
SYNOPSIS
http://your.server/cgi-bin/cachemgr.cgi
DESCRIPTION
The cache manager ( cachemgr.cgi ) is a CGI utility for displaying statistics about the Squid HTTP proxy process as it runs. The cache man-
ager is a convenient way to manage the cache and view statistics without logging into the server.
CONFIGURATION
Configuration examples for many common web servers can be found in the Squid FAQ wiki. http://wiki.squid-cache.org/SquidFaq
./cachemgr.conf
/etc/squid/cachemgr.conf
The access configuration file defining which Squid servers may be managed via this cachemgr.cgi program. Each line specifies a
server:port followed by an optional description
The server name may contain shell wildcard characters such as *, [] etc. A quick selection dropdown menu is automatically con-
structed from the simple server names.
Specifying :port is optional. If not specified then the default proxy port is assumed. :* or :any matches any port on the target
server.
SECURITY
cachemgr.cgi calls the requested server on the requested port using HTTP and returns a formatted version of the response. To avoid abuse it
is recommended to configure your web server to restrict access to the cachemgr.cgi program.
AUTHOR
Derived from Harvest. Further developed by numerous individuals from the internet community. Development is led by Duane Wessels of the
National Laboratory for Applied Network Research and funded by the National Science Foundation.
COPYRIGHT
Distributed under the GNU General Public License (GNU GPL) version 2 or later (GPLv2+).
QUESTIONS
Questions on the usage of this program can be sent to the Squid Users mailing list <squid-users@squid-cache.org>
REPORTING BUGS
See http://wiki.squid-cache.org/SquidFaq/BugReporting for details of what you need to include with your bug report.
Report bugs or bug fixes using http://bugs.squid-cache.org/
Report serious security bugs to Squid Bugs <squid-bugs@squid-cache.org>
Report ideas for new improvements to the Squid Developers mailing list <squid-dev@squid-cache.org>
SEE ALSO
squid(8), squidclient(1)
cachemgr.cgi(8)