[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[no subject]



In my setup 192.168.0.1 is my gateway, 192.168.0.4 is my proxy/Squid box
and 192.168.0.3 is my desktop. (Sorry about the long lines.


src admin {
    ip        192.168.0.3
}

# DESTINATION CLASSES:

dest adult {
    domainlist adult/domains
    urllist adult/urls
    expressionlist  adult/expressions
    log /var/log/squid/adult.log
}                                                                                                            

dest audio-video {
    domainlist audio-video/domains
    urllist audio-video/urls
}

dest forums {
    domainlist forums/domains
    urllist forums/urls
    expressionlist  forums/expressions
}

dest hacking {
    domainlist hacking/domains
    urllist hacking/urls
}

dest redirector {
    domainlist redirector/domains
    urllist redirector/urls
    expressionlist  redirector/expressions
}

dest warez {
    domainlist warez/domains
    urllist warez/urls
}

dest ads {
    domainlist ads/domains
    urllist ads/urls
}

dest violence {
    domainlist violence/domains
    urllist violence/urls
    expressionlist  violence/expressions
}


# ACLs
acl {
        admin {
        pass    any
        }

        default {
          pass !adult !audio-video !forums !hacking !redirector !warez !ads !aggressive !drugs !gambling !violence all
                redirect <a  rel="nofollow" href="http://www.rdlg.net/squidblocked.html";>http://www.rdlg.net/squidblocked.html</a>
       
        }
}






Thus spake James P. Kinney III (jkinney at localnetsolutions.com):

&gt; Has anyone setup squidGuard before? I can connect to the local gateway
&gt; machine OK but everything past it is blocked even though I have rules
&gt; set (I think) to allow access.
&gt; 
&gt; From
&gt; squidGuard.conf:                                                                                
&gt; source LAN {
&gt;         ip              192.168.1.2
&gt; }
&gt; 
&gt;                                                                                 
&gt; dest good {
&gt;         expressionlist          good.destexprlist
&gt;         urllist         good.desturllist
&gt;         domainlist      good.destdomainlist
&gt; }
&gt;                                                                                 
&gt; acl {
&gt;         LAN {
&gt;                 pass good all
&gt;         }else{
&gt;                 pass none
&gt;         }
&gt;                                                                                 
&gt;         default {
&gt;                 pass none
&gt;                 rewrite dmz
&gt;                 redirect
&gt; <a  rel="nofollow" href="http://192.168.1.1/cgi-bin/blocked?clientaddr=%a+clientname=%n+clientident=%i+srcclass=%s+targetclass=%t+url=%u";>http://192.168.1.1/cgi-bin/blocked?clientaddr=%a+clientname=%n+clientident=%i+srcclass=%s+targetclass=%t+url=%u</a>
&gt;         }
&gt; }
&gt; 
&gt; 192.168.1.1 is the gateway machine that is also a web server. It is the
&gt; squid proxy server
&gt; 
&gt; -- 
&gt; James P. Kinney III          \Changing the mobile computing world/
&gt; CEO &amp; Director of Engineering \          one Linux user         /
&gt; Local Net Solutions,LLC        \           at a time.          /
&gt; 770-493-8244                    \.___________________________./
&gt; <a  rel="nofollow" href="http://www.localnetsolutions.com";>http://www.localnetsolutions.com</a>
&gt; 
&gt; GPG ID: 829C6CA7 James P. Kinney III (M.S. Physics)
&gt; &lt;jkinney at localnetsolutions.com&gt;
&gt; Fingerprint = 3C9E 6366 54FC A3FE BA4D 0659 6190 ADC3 829C 6CA7



&gt; _______________________________________________
&gt; Ale mailing list
&gt; Ale at ale.org
&gt; <a  rel="nofollow" href="http://www.ale.org/mailman/listinfo/ale";>http://www.ale.org/mailman/listinfo/ale</a>


:wq!
---------------------------------------------------------------------------
Robert L. Harris                     | GPG Key ID: E344DA3B
                                         @ x-hkp://pgp.mit.edu
DISCLAIMER:
      These are MY OPINIONS ALONE.  I speak for no-one else.

With Dreams To Be A King First One Should Be A Man
					- Manowar

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Digital signature



</pre>
<!--X-Body-of-Message-End-->
<!--X-MsgBody-End-->
<!--X-Follow-Ups-->
<hr>
<!--X-Follow-Ups-End-->
<!--X-References-->
<ul><li><strong>References</strong>:
<ul>
<li><strong><a name="00603" href="msg00603.html">[ale] squidGuard</a></strong>
<ul><li><em>From:</em> jkinney at localnetsolutions.com (James P. Kinney III)</li></ul></li>
</ul></li></ul>
<!--X-References-End-->
<!--X-BotPNI-->
<ul>
<li>Prev by Date:
<strong><a href="msg00603.html">[ale] squidGuard</a></strong>
</li>
<li>Next by Date:
<strong><a href="msg00605.html">[ale] OT: DSL in older house (no NID)</a></strong>
</li>
<li>Previous by thread:
<strong><a href="msg00603.html">[ale] squidGuard</a></strong>
</li>
<li>Next by thread:
<strong><a href="msg00637.html">[ale] squidGuard</a></strong>
</li>
<li>Index(es):
<ul>
<li><a href="maillist.html#00604"><strong>Date</strong></a></li>
<li><a href="threads.html#00604"><strong>Thread</strong></a></li>
</ul>
</li>
</ul>

<!--X-BotPNI-End-->
<!--X-User-Footer-->
<!--X-User-Footer-End-->
</body>
</html>