squid

Download Squid

If you can't read please download the document

Upload: muhammad-rizky

Post on 17-Dec-2015

213 views

Category:

Documents


0 download

TRANSCRIPT

# ACLacl QUERY urlpath_regex -i cgi-bin \? \.php$ \.asp$ \.shtml$ \.cfm$ \.cfml$ \.phtml$ \.php3$ localhostacl manager proto cache_objectacl localhost src 127.0.0.0/8acl localnet src 192.168.137.0/24acl jaringan_wifi src 172.168.1.0/24#acl jaringan_nwifi src 172.168.1.10-172.168.1.50/32acl SSL_ports port 443 563 873 # https snew rsyncacl Safe_ports port 80 21 443 70 210 1025-65535 280 488 591 777 631 873 901 # http ftp https gopher wais unregistered ports http-mgmt gss-http filemaker multilinghttp $acl purge method PURGEacl CONNECT method CONNECTacl urlblock dstdomain "/etc/squid3/web/urlblock.txt"acl keyurl url_regex -i "/etc/squid3/web/keyurl.txt"acl download url_regex -i "/etc/squid3/web/download.txt"acl siang time 08:00-17:00acl sore time 18:00-22:00acl malam time 01:00-05:00acl subuh time 03:00-07:00http_access allow urlblock !sorehttp_access deny urlblockhttp_access allow keyurl !sorehttp_access deny keyurlhttp_access allow manager localhosthttp_access deny managerhttp_access allow localhosthttp_access allow purge localhosthttp_access deny purgehttp_access allow CONNECT Safe_ports localnethttp_access allow CONNECT Safe_ports jaringan_wifihttp_access deny !Safe_portshttp_access allow jaringan_wifi#http_access allow jaringan_wifi !jaringan_nwifihttp_access deny jaringan_wifihttp_access deny CONNECT !SSL_portshttp_access deny allicp_access deny allhttp_port 3128 transparenthierarchy_stoplist cgi-bin ?cache_mem 64 MBmaximum_object_size_in_memory 16 KBmemory_replacement_policy heap GDSFcache_replacement_policy heap LFUDAcoredump_dir /var/spool/squid3cache_dir ufs /var/spool/squid3/cache 200 16 256maximum_object_size 10240 KBcache_swap_low 85cache_swap_high 90access_log /var/spool/squid3/access.logcache_log /var/spool/squid3/cache.logcache_store_log nonelogfile_rotate 5log_icp_queries offcache deny QUERYrefresh_pattern ^ftp: 1440 20% 10080refresh_pattern ^gopher: 1440 0% 1440refresh_pattern -i \.(gif|png|jp?g|ico|bmp|tiff?|tar|ppt|xls)$ 10080 95% 43200 override-expire override-lastmod reload-into-ims ignore-no-cache ignore-privaterefresh_pattern -i \.(html|htm|css|js)$ 1440 75% 40320refresh_pattern -i \.index.(html|htm)$ 0 75% 10080refresh_pattern -i (/cgi-bin/|\?) 0 0% 0refresh_pattern . 1440 90% 10080quick_abort_min 0 KBquick_abort_max 0 KBquick_abort_pct 100store_avg_object_size 13 KBvary_ignore_expire onrequest_header_access From deny allrequest_header_access Server deny allrequest_header_access Link deny allrequest_header_access Via deny allrequest_header_access X-Forwarded-For deny allforward_timeout 240 secondconnect_timeout 30 secondpeer_connect_timeout 5 secondread_timeout 600 secondrequest_timeout 60 secondshutdown_lifetime 10 secondcache_mgr webmastercache_effective_user proxyhttpd_suppress_version_string onvisible_hostname localhostdns_timeout 10 secondsdns_nameservers 8.8.8.8 8.8.4.4memory_pools offclient_db offreload_into_ims onpipeline_prefetch onoffline_mode offdelay_pools 3delay_class 1 1delay_parameters 1 36000/64000delay_access 1 allow jaringan_wifi !soredelay_access 1 deny alldelay_class 2 2delay_parameters 2 64000/100000 -1/-1delay_access 2 allow jaringan_wifi !malamdelay_access 2 allow download !subuhdelay_access 2 deny alldelay_class 3 3delay_parameters 3 36000/64000 28000/56000 -1/-1delay_access 3 allow jaringan_wifi !siangdelay_access 3 deny all