<<
Squid Conf
http_port 3128
hierarchy_stoplist cgi-bin ?
acl QUERY urlpath_regex cgi-bin ?
cache deny QUERY
acl apache rep_header Server ^Apache
broken_vary_encoding allow apache
access_log /var/log/squid/access.log squid
auth_param basic program /usr/lib/squid/ncsa_auth /etc/squid/passwd
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern . 0 20% 4320
acl all src 0.0.0.0/0.0.0.0
acl auth proxy_auth REQUIRED
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 8080 # tomcat
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl isa03 port 8080
acl isa03 port 21
acl isa03 port 20
acl CONNECT method CONNECT
acl denied_domains dstdomain "/etc/squid/denied_domains.acl"
#acl students src "/etc/squid/student_domains.acl"
acl filetypes urlpath_regex -i "/etc/squid/denied_filetypes.acl"
acl url_ads url_regex "/etc/squid/denied_ads.acl"
deny_info NOTE_ADS_FILTERED url_ads
deny_info NOTE_FILETYPES_FILTERED filetypes
cache_peer cdgisa03.cdg.caudwell.com parent 80 0
cache_peer_access cdgisa03.cdg.caudwell.com allow isa03
cache_peer_access cdgisa03.cdg.caudwell.com deny all
never_direct allow isa03
always_direct allow !isa03
http_access deny !auth
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access deny url_ads
#http_access deny students filetypes
http_access deny denied_domains
#http_access allow localhost
http_access allow all
http_reply_access allow all
icp_access allow all
coredump_dir /var/spool/squid