Bonjours,
j’ai comme projet d’installer un serveur Squid couplé à squidguard dans mon entreprise apres m’etre rensseigné j’ai commencé à monter le dit serveur configuration des fichier conf de squid et squidguard et generation de la base de liste noirs.Or sa ne marche pas…
Le probleme est que mon squid marche tres bien (essai en refusant toute connexion) mais qu’aucune de mes listes n’est pris en compte.
je vous fournit les info de mon install
Debian 6 i386
squid 2.7
squidguard 1.4
Le tout sur une vm.
Je vous fournit aussi les fichier de config.
Squid:
[code]#Liste des acl
acl all src all
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8 0.0.0.0/32
acl localnet src 10.0.0.0/24 # RFC1918 possible internal network
acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
acl SSL_ports port 443 # https
acl SSL_ports port 563 # snews
acl SSL_ports port 873 # rsync
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl Safe_ports port 631 # cups
acl Safe_ports port 873 # rsync
acl Safe_ports port 901 # SWAT
acl purge method PURGE
acl CONNECT method CONNECT
acl local_clients src 10.6.5.0/24
#liste des acces
http_access allow manager localhost
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost
http_access allow local_clients
http_access deny all
icp_access allow localnet
icp_access allow all
#Autre config
http_port 3128
hierarchy_stoplist cgi-bin ?
access_log /var/log/squid/access.log squid
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320
acl shoutcast rep_header X-HTTP09-First-Line ^ICY.[0-9]
upgrade_http0.9 deny shoutcast
acl apache rep_header Server ^Apache
broken_vary_encoding allow apache
extension_methods REPORT MERGE MKACTIVITY CHECKOUT
hosts_file /etc/hosts
coredump_dir /var/spool/squid
#redirection vers squidguard
url_rewrite_program /usr/bin/squidGuard
[/code]
squidguard:
[code]#
CONFIG FILE FOR SQUIDGUARD
dbhome /var/lib/squidguard/db
logdir /var/log/squid
TIME RULES:
abbrev for weekdays:
s = sun, m = mon, t =tue, w = wed, h = thu, f = fri, a = sat
time workhours {
weekly mtwhf 08:00 - 16:30
date --01 08:00 - 16:30
}
REWRITE RULES:
SOURCE ADDRESSES:
#src admin {
ip 1.2.3.4 1.2.3.5
user root foo bar
within workhours
#}
#src foo-clients {
ip 172.16.2.32-172.16.2.100 172.16.2.100 172.16.2.200
#}
#src bar-clients {
ip 172.16.4.0/26
#}
DESTINATION CLASSES:
dest adult {
domainlist adult/domains
urllist adult/urls
expressionlist adult/expressions
}
acl {
admin {
pass any
}
foo-clients within workhours {
pass good !in-addr !adult any
} else {
pass any
}
bar-clients {
pass local none
}
default {
pass pass !adult all
redirect www.google.fr
}
}[/code]
Donc si qulqu’un pouvais me donner une solution ou une piste je le suis en serais super reconnaissant Merci d’avance