Advertisement
ujiajah1

squid.conf /alex

Sep 3rd, 2016
319
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. ## SQUID.CONF ##
  2. cache_mgr proxy
  3. visible_hostname proxy
  4.  
  5. cache_mem 8 GB
  6. cache_swap_low 98
  7. cache_swap_high 99
  8.  
  9. minimum_object_size 0 KB
  10. maximum_object_size 5 GB
  11. maximum_object_size_in_memory 32 KB
  12.  
  13. ipcache_size 4096
  14. ipcache_low 98
  15. ipcache_high 99
  16.  
  17. dns_defnames on
  18. dns_v4_first on
  19.  
  20. memory_pools off
  21. reload_into_ims on
  22. vary_ignore_expire on
  23. max_filedescriptors 65536
  24.  
  25. cache_replacement_policy heap LFUDA
  26. memory_replacement_policy heap GDSF
  27.  
  28. cache_dir aufs /cache/cache 500000 58 256
  29.  
  30. access_log /var/log/squid/access.log
  31. cache_log /var/log/squid/cache.log
  32.  
  33. acl all src
  34.  
  35. always_direct allow all
  36. ssl_bump server-first all
  37. #http_access deny !Safe_ports
  38. #http_access deny CONNECT !SSL_ports
  39. http_access allow all
  40. icp_access allow all
  41.  
  42.  
  43. # LISTENING PORT SQUID
  44. https_port 3127 tproxy ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_cert/myCA.pem
  45. https_port 3126 tproxy ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_cert/myCA.pem
  46. http_port 3128
  47. http_port 3129 tproxy
  48. http_port 3130 tproxy
  49.  
  50. sslcrtd_program /usr/lib/squid/ssl_crtd -s /var/squid/ssl_db/certs/ -M 4MB
  51. sslcrtd_children 5
  52. # ========================================================================================================
  53.  
  54. max_stale 1 years
  55. acl 1 dstdomain .apple.com
  56. acl 1 dstdomain .facebook.com .fbcdn.net .akamaihd.net .fbsbx.com
  57. acl 2 url_regex -i ^https?:\/\/(.*\.facebook\.com)\/([0-9]+.*)
  58. acl 2 url_regex -i ^http.*\.(fbcdn|akamaihd)\.net\/h(profile|photos).*[\d\w].*\/([\w]\d+x\d+\/.*\.[\d\w]{3}).*
  59. acl 2 url_regex -i ^http(.*)static(.*)(akamaihd|fbcdn).net\/rsrc.php\/(.*\/.*\/(.*).(js|css|png|gif))(\?(.*)|$)
  60. acl 2 url_regex -i ^https?:\/\/[a-zA-Z0-9\-\_\.\%]*(fbcdn|akamaihd)[a-zA-Z0-9\-\_\.\%]*net\/rsrc\.php\/(.*)
  61. acl 2 url_regex -i ^https?\:\/\/.*(profile|photo|creative).*\.ak\.fbcdn\.net\/((h|)(profile|photos)-ak-)(snc|ash|prn)[0-9]?(.*)
  62. acl 2 url_regex -i ^https?:\/\/attachment\.fbsbx\.com\/.*\?(id=[0-9]*).*
  63. acl 2 url_regex -i ^https?:\/\/.*(fbcdn|akamaihd)\.net\/.*\/(.*\.mp4)(.*)
  64. acl 2 url_regex -i ^https?:\/\/.*(profile|photo|creative)*.akamaihd\.net\/((h|)(profile|photos|ads)-ak-)(snc|ash|prn|frc[0-9])[0-9]?(.*)
  65. acl 2 url_regex -i ^https?\:\/\/video\.(.*)\.fbcdn\.net\/(.*?)\/([0-9_]+\.(mp4|flv|avi|mkv|m4v|mov|wmv|3gp|mpg|mpeg)?)(.*)
  66. acl 2 url_regex -i \.fbsbx\.com\/.*\/(.*\.(unity3d|pak|zip|exe|dll|jpg|png|gif|swf)/)$
  67. acl 3 url_regex -i ^https?:\/\/(.*?)\/speedtest\/.*\.(jpg|txt|png|gif|swf)\?.*
  68. acl 3 url_regex -i speedtest\/.*\.(jpg|txt|png|gif|swf)\?.*
  69. acl 7 url_regex -i youtube.*(ptracking|stream_204|player_204|gen_204).*$
  70. acl 7 url_regex -i \.c\.(youtube|google)\.com\/(get_video|videoplayback|videoplay).*$
  71. acl 7 url_regex -i (youtube|google).*\/videoplayback\?.*
  72. acl 8 http_status 302
  73.  
  74. acl store_url url_regex -i (youtube|googlevideo|docs.google|video.google).*videoplayback\?.*
  75.  
  76. store_miss deny store_url 7 8
  77. send_hit deny store_url 7 8
  78.  
  79. store_id_program /usr/bin/perl /etc/squid/store-id.pl
  80. store_id_children 10 startup=5 idle=2 concurrency=10
  81. store_id_access allow 1
  82. store_id_access allow 2
  83. store_id_access allow 3
  84. store_id_access allow 7
  85. store_id_access deny all
  86.  
  87. #YouTube
  88. refresh_pattern (audio|video)\/(webm|mp4) 129600 99% 129600 ignore-reload override-expire override-lastmod ignore-must-revalidate  ignore-private ignore-no-store ignore-auth store-stale
  89. refresh_pattern -i (get_video\?|videoplayback\?|videodownload\?|\.mp4|\.webm|\.flv|((audio|video)\/(webm|mp4))) 241920 100% 241920 override-expire ignore-reload ignore-private ignore-no-store ignore-must-revalidate reload-into-ims ignore-auth store-stale
  90. refresh_pattern -i ^https?\:\/\/.*\.googlevideo\.com\/videoplayback.*   10080 99% 43200 override-lastmod override-expire ignore-reload reload-into-ims ignore-private reload-into-ims ignore-auth store-stale
  91. refresh_pattern -i \/speedtest\/.*\.(txt|jpg|png|swf)  0  99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
  92.  
  93. refresh_pattern static\.(xx|ak)\.fbcdn\.net*\.(jpg|gif|png) 241920 99% 241920 ignore-reload override-expire ignore-no-store
  94. refresh_pattern ^https?\:\/\/profile\.ak\.fbcdn.net*\.(jpg|gif|png) 241920 99% 241920 ignore-reload override-expire ignore-no-store
  95. refresh_pattern (akamaihd|fbcdn)\.net 14400 99% 518400  ignore-no-store ignore-private ignore-reload ignore-must-revalidate store-stale
  96. refresh_pattern -i https?:\/\/.*\.xx\.fbcdn\.net\/.*\.(jpg|png) 43830 99% 259200 override-expire override-lastmod ignore-reload
  97. refresh_pattern -i ^https?\:\/\/video\.(.*)\.fbcdn\.net\/(.*?)\/([0-9_]+\.(mp4|flv|avi|mkv|m4v|mov|wmv|3gp|mpg|mpeg)?)(.*) 241920 99% 241920 ignore-no-store ignore-reload override-expire
  98.  
  99. refresh_pattern -i \.(3gp|7z|ace|asx|bin|deb|divx|dvr-ms|ram|rpm|exe|inc|cab|qt) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  100. refresh_pattern -i \.(rar|jar|gz|tgz|bz2|iso|m1v|m2(v|p)|mo(d|v)|arj|lha|lzh|zip|tar|iop|nzp|pak|mar|msp) 10080 80% 10080 override-expire override-lastmod reload-into-ims ignore-reload
  101. refresh_pattern -i \.(jp(e?g|e|2)|gif|pn[pg]|bm?|tiff?|ico|swf|dat|ad|txt|dll) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  102. refresh_pattern -i \.(avi|ac4|mp(e?g|a|e|1|2|3|4)|mk(a|v)|ms(i|u|p)|og(x|v|a|g)|rm|r(a|p)m|snd|vob|webm) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  103. refresh_pattern -i \.(pp(t?x)|s|t)|pdf|rtf|wax|wm(a|v)|wmx|wpl|cb(r|z|t)|xl(s?x)|do(c?x)|flv|x-flv) 10080 80% 10080 override-expire override-lastmod reload-into-ims
  104. refresh_pattern -i \.(3gp|7z|ace|asx|bin|deb|cup|dvr-ms|ram|rpm|exe|inc|cab|qt) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  105. refresh_pattern -i \.(rar|jar|gz|tgz|bz2|iso|m1v|m2(v|p)|mo(d|v)|arj|lha|lzh|zip|tar|pak|cup) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  106. refresh_pattern -i \.(avi|ac4|mp(e?g|a|e|1|2|3|4)|mk(a|v)|ms(i|u|p)|og(x|v|a|g)|rm|r(a|p)m|snd|vob) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  107. refresh_pattern -i \.(pp(t?x)|s|t)|pdf|rtf|wax|wm(a|v)|wmx|wpl|cb(r|z|t)|xl(s?x)|do(c?x)|flv|x-flv) 10080 100% 43800 override-expire override-lastmod ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
  108. refresh_pattern -i .(html|htm|css|js|xml)$ 1440 75% 40320
  109. refresh_pattern -i .index.(html|htm)$ 0 75% 43800
  110. refresh_pattern -i ^http.*squid\.internal.* 43200 100% 799000 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth
  111.  
  112. #KEEP THESE LINES AT BOTTOM OF CONFIGURATION
  113. refresh_pattern ^ftp:  1440 20% 10080
  114. refresh_pattern ^gopher: 1440 0% 1440
  115. refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
  116. refresh_pattern .  0 0% 4320
  117.  
  118. # local
  119. qos_flows local-hit=0x30
  120. #collapsed_forwarding on
  121. ## END SQUID.CONF ##
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement