{"id":323,"date":"2010-12-16T08:04:05","date_gmt":"2010-12-16T08:04:05","guid":{"rendered":"http:\/\/cdblog.cdstealer.com\/?p=323"},"modified":"2010-12-16T08:25:24","modified_gmt":"2010-12-16T08:25:24","slug":"squid-cache-server","status":"publish","type":"post","link":"https:\/\/cdblog.cdstealer.com\/?p=323","title":{"rendered":"Squid Cache Server"},"content":{"rendered":"<h1><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-322\" title=\"img4\" src=\"http:\/\/cdblog.cdstealer.com\/wp-content\/uploads\/2010\/12\/img4.jpg\" alt=\"\" width=\"877\" height=\"140\" srcset=\"https:\/\/cdblog.cdstealer.com\/wp-content\/uploads\/2010\/12\/img4.jpg 877w, https:\/\/cdblog.cdstealer.com\/wp-content\/uploads\/2010\/12\/img4-300x47.jpg 300w\" sizes=\"auto, (max-width: 877px) 100vw, 877px\" \/>How to setup a Squid Proxy.<\/h1>\n<p>The \/etc\/squid\/squid.conf File<\/p>\n<p>The main Squid configuration file is squid.conf, and, like most Linux  applications, Squid needs to be restarted for changes to the  configuration file can take effect.<br \/>\nThe config file is extensive and very well commented.\u00a0 Here is an example.<\/p>\n<p><a href=\"http:\/\/cdstealer.com\/filez\/blog\/squid.conf\" target=\"_blank\">the config<\/a><\/p>\n<h2>The Visible Host Name (optional)<\/h2>\n<p>Squid can fail to start if you don't give your server a hostname.  You can set this with the visible_hostname parameter.<\/p>\n<h2>Logging Options<\/h2>\n<p>Be default, the time stamp in the log files are EPOCH.\u00a0 To change this to a more human readable format, uncomment\/add this line in the \"log_format\" section of \/etc\/squid\/squid.conf.<\/p>\n<pre>logformat squid %tl %6tr %&gt;a %Ss\/%03&gt;Hs %&lt;st %rm %ru %un %Sh\/%&lt;A %mt PORT_REQUEST = %&gt;p<\/pre>\n<h2>Access Control Lists<\/h2>\n<p>You can limit users' ability to browse the Internet with access  control lists (ACLs). Each ACL line defines a particular type of  activity, such as an access time or source network, they are then linked  to an http_access statement that tells Squid whether or not to deny or  allow traffic that matches the ACL.<\/p>\n<p>Squid matches each Web access request it receives by checking the  http_access list from top to bottom. If it finds a match, it enforces  the allow or deny statement and stops reading further. You have to be  careful not to place a deny statement in the list that blocks a similar  allow statement below it. The final http_access statement denies  everything, so it is best to place new http_access statements above it<\/p>\n<p>Note: The very last http_access statement in the squid.conf file  denies all access. You therefore have to add your specific permit  statements above this line. In the chapter's examples, I've suggested  that you place your statements at the top of the http_access list for  the sake of manageability, but you can put them anywhere in the section  above that last line.<\/p>\n<p>Squid has a minimum required set of ACL statements in the  ACCESS_CONTROL section of the squid.conf file. It is best to put new  customized entries right after this list to make the file easier to  read.<\/p>\n<h2>Restricting Web Access By Time<\/h2>\n<p>You can create access control lists with time parameters. For  example, you can allow only business hour access from the home network,  while always restricting access to host 192.168.1.23.<\/p>\n<pre>#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl home_network src 192.168.1.0\/24\r\nacl business_hours time M T W H F 9:00-17:00\r\nacl RestrictedHost src 192.168.1.23\r\n\r\n#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access deny RestrictedHost\r\nhttp_access allow home_network business_hours\r\n<\/pre>\n<p>Or, you can allow morning access only:<\/p>\n<pre>#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl mornings time 08:00-12:00\r\n\r\n#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access allow mornings\r\n<\/pre>\n<h2>Restricting Access to specific Web sites<\/h2>\n<p>Squid is also capable of reading files containing lists of web sites  and\/or domains for use in ACLs. In this example we create to lists in  files named \/usr\/local\/etc\/allowed-sites.squid and  \/usr\/local\/etc\/restricted-sites.squid.<\/p>\n<pre># File: \/usr\/local\/etc\/allowed-sites.squid\r\nwww.openfree.org\r\nlinuxhomenetworking.com\r\n\r\n# File: \/usr\/local\/etc\/restricted-sites.squid\r\nwww.porn.com\r\nillegal.com\r\n<\/pre>\n<p>These can then be used to always block the restricted sites and  permit the allowed sites during working hours. This can be illustrated  by expanding our previous example slightly.<\/p>\n<pre>#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl home_network src 192.168.1.0\/24\r\nacl business_hours time M T W H F 9:00-17:00\r\nacl GoodSites dstdomain \"\/usr\/local\/etc\/allowed-sites.squid\"\r\nacl BadSites  dstdomain \"\/usr\/local\/etc\/restricted-sites.squid\"\r\n\r\n#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access deny BadSites\r\nhttp_access allow home_network business_hours GoodSites\r\n<\/pre>\n<h2>Restricting Web Access By IP Address<\/h2>\n<p>You can create an access control list that restricts Web access to  users on certain networks. In this case, it's an ACL that defines a home  network of 192.168.1.0.<\/p>\n<pre>#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl home_network src 192.168.1.0\/255.255.255.0\r\n<\/pre>\n<p>You also have to add a corresponding http_access statement that allows traffic that matches the ACL:<\/p>\n<pre>#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access allow home_network\r\n<\/pre>\n<h2>Password Authentication Using NCSA<\/h2>\n<p>You can configure Squid to prompt users for a username and password.  Squid comes with a program called ncsa_auth that reads any  NCSA-compliant encrypted password file. You can use the htpasswd program  that comes installed with Apache to create your passwords. Here is how  it's done:<\/p>\n<p>1) Create the password file. The name of the password file should  be \/etc\/squid\/squid_passwd, and you need to make sure that it's  universally readable.<\/p>\n<pre>[root@cdstealer tmp]# touch \/etc\/squid\/squid_passwd\r\n[root@cdstealer tmp]# chmod o+r \/etc\/squid\/squid_passwd\r\n<\/pre>\n<p>2) Use the htpasswd program to add users to the password file. You  can add users at anytime without having to restart Squid. In this case,  you add a username called www:<\/p>\n<pre>[root@cdstealer tmp]# htpasswd \/etc\/squid\/squid_passwd www\r\nNew password:\r\nRe-type new password:\r\nAdding password for user www\r\n[root@cdstealer tmp]#\r\n<\/pre>\n<p>3) Find your ncsa_auth file using the locate command.<\/p>\n<pre>[root@cdstealer tmp]# locate ncsa_auth\r\n\/usr\/lib\/squid\/ncsa_auth\r\n[root@cdstealer tmp]#\r\n<\/pre>\n<p>4) Edit squid.conf; specifically, you need to define the  authentication program in squid.conf, which is in this case ncsa_auth.  Next, create an ACL named ncsa_users with the REQUIRED keyword that  forces Squid to use the NCSA auth_param method you defined previously.  Finally, create an http_access entry that allows traffic that matches  the ncsa_users ACL entry. Here's a simple user authentication example;  the order of the statements is important:<\/p>\n<pre>#\r\n# Add this to the auth_param section of squid.conf\r\n#\r\nauth_param basic program \/usr\/lib\/squid\/ncsa_auth \/etc\/squid\/squid_passwd\r\n\r\n#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl ncsa_users proxy_auth REQUIRED\r\n\r\n#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access allow ncsa_users\r\n<\/pre>\n<p>5) This requires password authentication and allows access only  during business hours. Once again, the order of the statements is  important:<\/p>\n<pre>#\r\n# Add this to the auth_param section of squid.conf\r\n#\r\nauth_param basic program \/usr\/lib\/squid\/ncsa_auth \/etc\/squid\/squid_passwd\r\n\r\n#\r\n# Add this to the bottom of the ACL section of squid.conf\r\n#\r\nacl ncsa_users proxy_auth REQUIRED\r\nacl business_hours time M T W H F 9:00-17:00\r\n\r\n#\r\n# Add this at the top of the http_access section of squid.conf\r\n#\r\nhttp_access allow ncsa_users business_hours\r\n<\/pre>\n<p>Remember to restart Squid for the changes to take effect.<\/p>\n<h1>Forcing Users To Use Your Squid Server<\/h1>\n<p>If you are using access controls on Squid, you may also want to  configure your firewall to allow only HTTP Internet access to only the  Squid server. This forces your users to browse the Web through the Squid  proxy.<\/p>\n<h2>Making Your Squid Server Transparent To Users<\/h2>\n<p>It is possible to limit HTTP Internet access to only the Squid server  without having to modify the browser settings on your client PCs. This  called a transparent proxy configuration. It is usually achieved by  configuring a firewall between the client PCs and the Internet to  redirect all HTTP (TCP port 80) traffic to the Squid server on TCP port  3128, which is the Squid server's default TCP port.<\/p>\n<h3>Squid Transparent Proxy Configuration<\/h3>\n<p>Your first step will be to modify your squid.conf to create a  transparent proxy. The procedure is different depending on your version  of Squid.<\/p>\n<p><strong>Prior to version 2.6:<\/strong> In older versions of Squid,  transparent proxy was achieved through the use of the httpd_accel  options which were originally developed for http acceleration. In these  cases, the configuration syntax would be as follows:<\/p>\n<pre>httpd_accel_host virtual\r\nhttpd_accel_port 80\r\nhttpd_accel_with_proxy on\r\nhttpd_accel_uses_host_header on\r\n<\/pre>\n<p><strong>Version 2.6 and Beyond:<\/strong> Newer versions of Squid simply require  you to add the word \"transparent\" to the default \"http_port 3128\"  statement. In this example, Squid not only listens on TCP port 3128 for  proxy connections, but will also do so in transparent mode.<\/p>\n<pre>http_port 3128 transparent\r\n<\/pre>\n<h3>Configuring iptables to Support the Squid Transparent Proxy<\/h3>\n<p>Only the Squid server has access to the Internet on port 80  (HTTP), because all HTTP traffic, except that coming from the Squid  server, is redirected.<\/p>\n<p>If the Squid server and firewall are the same server, all HTTP  traffic from the home network is redirected to the firewall itself on  the Squid port of 3128 and then only the firewall itself is allowed to  access the Internet on port 80.<\/p>\n<pre>iptables -t nat -A PREROUTING -i eth1 -p tcp --dport 80 \\\r\n        -j REDIRECT --to-port 3128\r\niptables -A INPUT -j ACCEPT -m state \\\r\n        --state NEW,ESTABLISHED,RELATED -i eth1 -p tcp \\\r\n        --dport 3128\r\niptables -A OUTPUT -j ACCEPT -m state \\\r\n        --state NEW,ESTABLISHED,RELATED -o eth0 -p tcp \\\r\n        --dport 80\r\niptables -A INPUT -j ACCEPT -m state \\\r\n        --state ESTABLISHED,RELATED -i eth0 -p tcp \\\r\n        --sport 80\r\niptables -A OUTPUT -j ACCEPT -m state \\\r\n        --state ESTABLISHED,RELATED -o eth1 -p tcp \\\r\n        --sport 80\r\n<\/pre>\n<p><strong>Note:<\/strong> This example is specific to HTTP traffic. You won't be  able to adapt this example to support HTTPS web browsing on TCP port  443, as that protocol specifically doesn't allow the insertion of a \"man  in the middle\" server for security purposes. One solution is to add IP  masquerading statements for port 443, or any other important traffic,  immediately after the code snippet. This will allow non HTTP traffic to  access the Internet without being cached by Squid.<\/p>\n<p>If the Squid server and firewall are different servers, the  statements are different. You need to set up iptables so that all  connections to the Web, not originating from the Squid server, are  actually converted into three connections; one from the Web browser  client to the firewall and another from the firewall to the Squid  server, which triggers the Squid server to make its own connection to  the Web to service the request. The Squid server then gets the data and  replies to the firewall which then relays this information to the Web  browser client. The iptables program does all this using these NAT  statements:<\/p>\n<pre>iptables -t nat -A PREROUTING -i eth1 -s\u00a0! 192.168.1.100 \\\r\n        -p tcp --dport 80 -j DNAT --to 192.168.1.100:3128\r\niptables -t nat -A POSTROUTING -o eth1 -s 192.168.1.0\/24 \\\r\n        -d 192.168.1.100 -j SNAT --to 192.168.1.1\r\niptables -A FORWARD -s 192.168.1.0\/24 -d 192.168.1.100 \\\r\n        -i eth1 -o eth1 -m state\r\n         --state NEW,ESTABLISHED,RELATED \\\r\n        -p tcp --dport 3128 -j ACCEPT\r\n iptables -A FORWARD -d 192.168.1.0\/24 -s 192.168.1.100 \\\r\n        -i eth1 -o eth1 -m state --state ESTABLISHED,RELATED \\\r\n        -p tcp --sport 3128 -j ACCEPT\r\n<\/pre>\n<p>In the first statement all HTTP traffic from the home network except  from the Squid server at IP address 192.168.1.100 is redirected to the  Squid server on port 3128 using destination NAT. The second statement  makes this redirected traffic also undergo source NAT to make it appear  as if it is coming from the firewall itself. The FORWARD statements are  used to ensure the traffic is allowed to flow to the Squid server after  the NAT process is complete. The unusual feature is that the NAT all  takes place on one interface; that of the home network (eth1).<\/p>\n<p>You will additionally have to make sure your firewall has rules  to allow your Squid server to access the Internet on HTTP TCP port 80.<a title=\"Quick HOWTO : Ch14 : Linux Firewalls Using iptables\" href=\"http:\/\/www.linuxhomenetworking.com\/wiki\/index.php\/Quick_HOWTO_:_Ch14_:_Linux_Firewalls_Using_iptables\"><br \/>\n<\/a><\/p>\n<h2>Manually Configuring Web Browsers To Use Your Squid Server<\/h2>\n<p>If you don't have a firewall that supports redirection, then you need  to configure your firewall to only accept HTTP Internet access from the  Squid server, as well as configure your PC browser's proxy server  settings manually to use the Squid server. The method you use depends on  your browser.<\/p>\n<p>For example, to make these changes using Internet Explorer<\/p>\n<ol>\n<li> Click on the \"Tools\" item on the menu bar of the browser.<\/li>\n<li> Click on \"Internet Options\"<\/li>\n<li> Click on \"Connections\"<\/li>\n<li> Click on \"LAN Settings\"<\/li>\n<li> Configure with the address and TCP port (3128 default) used by your Squid server.<\/li>\n<\/ol>\n<p>Here's how to make the same changes using Mozilla or Firefox.<\/p>\n<ol>\n<li> Click on the \"Edit\" item on the browser's menu bar.<\/li>\n<li> Click on \"Preferences\"<\/li>\n<li> Click on \"Advanced\"<\/li>\n<li> Click on \"Proxies\"<\/li>\n<li> Configure with the address and TCP port (3128 default) used by your Squid server under \"Manual Proxy Configuration\"<\/li>\n<\/ol>\n<h1>Squid Disk Usage<\/h1>\n<p>Squid uses the \/var\/spool\/squid directory to store its cache files.  High usage squid servers need a large amount of disk space in the \/var  partition to get optimum performance.<\/p>\n<p>Every webpage and image accessed via the Squid server is logged  in the \/var\/log\/squid\/access.log file. This can get quite large on high  usage servers. Fortunately, the logrotate program automatically purges  this file.<\/p>\n<h1>Troubleshooting Squid<\/h1>\n<p>Squid logs both informational and error messages to files in the  \/var\/log\/squid\/ directory. It is best to review these files first  whenever you have difficulties.The squid.out file can be especially  useful as it contains Squids' system errors.<\/p>\n<p>Another source of errors could be unintended statements in the  squid.conf file that cause no errors; mistakes in the configuration of  hours of access and permitted networks that were forgotten to be added  are just two possibilities.<\/p>\n<h1>Conclusion<\/h1>\n<p>Tools such as Squid are popular with many company mangers. By caching  images and files on a server shared by all, Internet bandwidth charges  can be reduced.<\/p>\n<p>Squid's password authentication feature is well liked because it  allows only authorized users to access the Internet as a means of  reducing usage fees and distractions in the office. Unfortunately, an  Internet access password is usually not viewed as a major security  concern by most users who are often willing to share it with their  colleagues. Although it is beyond the scope of this book, you should  consider automatically tying the Squid password to the user's regular  login password. This will make them think twice about giving their  passwords away. Internet access is one thing, letting your friends have  full access to your e-mail and computer files is quite another.<\/p>\n<p>Taken from <a href=\"http:\/\/www.linuxhomenetworking.com\/wiki\/index.php\/Quick_HOWTO_:_Ch32_:_Controlling_Web_Access_with_Squid\" target=\"_blank\">LinuxHomeNetworking<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to setup a Squid Proxy. The \/etc\/squid\/squid.conf File The main Squid configuration file is squid.conf, and, like most Linux applications, Squid needs to be restarted for changes to the configuration file can take effect. The config file is extensive and very well commented.\u00a0 Here is an example. the config The Visible Host Name (optional) &hellip; <a href=\"https:\/\/cdblog.cdstealer.com\/?p=323\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Squid Cache Server<\/span> <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[50,18,49,48],"class_list":["post-323","post","type-post","status-publish","format-standard","hentry","category-gentoo","tag-cache","tag-linux","tag-proxy","tag-squid"],"_links":{"self":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=323"}],"version-history":[{"count":5,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/323\/revisions"}],"predecessor-version":[{"id":335,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=\/wp\/v2\/posts\/323\/revisions\/335"}],"wp:attachment":[{"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cdblog.cdstealer.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}