Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- acl all src
- acl SSL_ports port 443
- acl Safe_ports port 80
- acl Safe_ports port 21
- acl Safe_ports port 443
- acl Safe_ports port 70
- acl Safe_ports port 210
- acl Safe_ports port 1025-65535
- acl Safe_ports port 280
- acl Safe_ports port 488
- acl Safe_ports port 591
- acl Safe_ports port 777
- acl CONNECT method CONNECT
- acl getmethod method GET
- # Rules to block few Advertising sites
- acl ads url_regex -i .youtube\.com\/ad_frame?
- acl ads url_regex -i .(s|s[0-90-9])\.youtube\.com
- acl ads url_regex -i .googlesyndication\.com
- acl ads url_regex -i .doubleclick\.net
- acl ads url_regex -i ^http:\/\/googleads\.*
- acl ads url_regex -i ^http:\/\/(ad|ads|ads[0-90-9]|ads\d|kad|a[b|d]|ad\d|adserver|adsbox)\.[a-z0-9]*\.[a-z][a-z]*
- acl ads url_regex -i ^http:\/\/openx\.[a-z0-9]*\.[a-z][a-z]*
- acl ads url_regex -i ^http:\/\/[a-z0-9]*\.openx\.net\/
- acl ads url_regex -i ^http:\/\/[a-z0-9]*\.u-ad\.info\/
- acl ads url_regex -i ^http:\/\/adserver\.bs\/
- acl ads url_regex -i !^http:\/\/adf\.ly
- http_access deny ads
- http_reply_access deny ads
- #deny_info http://yoursite/yourad,htm ads
- #==== End Rules: Advertising ====
- acl reverbnation url_regex -i reverbnation.*(audio_player|ec_stream_song).*$
- acl reverbnation url_regex -i \.c\.(reverbnation|c2lo)\.com\/(get_audio|audioplayback|audioplay).*$
- acl youtube url_regex -i youtube.*(ptracking|stream_204|player_204|gen_204).*$
- acl youtube url_regex -i (youtube|google).*\/videoplayback\?.*
- acl speedtest url_regex -i ^https?:\/\/(.*?)\/speedtest\/(.*\.(jpg|txt))\??.*$
- acl deny_domain dstdomain .windowsupdate.com
- http_access deny deny_domain
- acl deny_url url_regex -i ^https?:\/\/.*cdn\.mozilla\.(net|org)\/pub\/firefox\/(releases|candidates)\/.*\/update\/win32\/.*
- acl deny_url url_regex -i ^https?:\/\/.*\.pack.google.com\/edgedl\/chrome\/win\/.*
- acl deny_url url_regex -i ^https?:\/\/cache.pack.google.com\/edgedl\/.*
- acl deny_url url_regex -i ^https?:\/\/www.google.com\/dl\/chrome\/win\/.*
- http_access deny deny_url
- cache_mgr Internet-Kaltersia
- visible_hostname albspirit@info.al
- cache_mem 5000 MB
- cache_swap_low 98
- cache_swap_high 99
- ipcache_size 2048
- ipcache_low 98
- ipcache_high 99
- ################################
- maximum_object_size 1024 MB
- maximum_object_size_in_memory 512 KB
- minimum_object_size 1 KB
- cache_replacement_policy heap LFUDA
- memory_replacement_policy heap GDSF
- cache_dir ufs /mnt/128gb/cache-1 112500 264 256
- cache_dir ufs /mnt/128gb/cache-2 112500 264 256
- cache_dir ufs /mnt/gb128/cache-1 112500 264 256
- cache_dir ufs /mnt/gb128/cache-2 112500 264 256
- access_log stdio:/var/log/squid/access.log
- #cache_log /var/log/squid/cache.log
- cache_store_log none
- logfile_rotate 1
- always_direct allow all
- ssl_bump server-first all
- http_access deny !Safe_ports
- http_access deny CONNECT !SSL_ports
- http_access allow all
- http_reply_access allow all
- icp_access allow all
- http_port 3128
- http_port 3129 tproxy
- https_port 3127 tproxy ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl_cert/myCA.pem
- sslcrtd_program /usr/lib/squid/ssl_crtd -s /var/squid/ssl_db/certs/ -M 4MB
- sslcrtd_children 20
- always_direct allow all
- ssl_bump client-first all
- sslproxy_cert_error allow all
- sslproxy_flags DONT_VERIFY_PEER
- sslproxy_cert_error deny all
- ssl_unclean_shutdown on
- sslproxy_version 1
- always_direct allow all
- ssl_bump none localhost
- ssl_bump server-first all
- sslproxy_cert_error allow all
- sslproxy_flags DONT_VERIFY_PEER
- acl QUERY urlpath_regex -i (begin|start)\=
- acl QUERY urlpath_regex -i cgi-bin \? .php$ .asp$ .shtml$ .cfm$ .cfml$ .phtml$ .php3$ localhost
- acl dontrewrite url_regex -i c\.youtube\.com\/.*(begin|start)\=.*
- acl dontrewrite url_regex redbot\.org
- acl getmethod method GET
- acl redir urlpath_regex -i &redirect_counter=1&cms_redirect=yes
- acl redir urlpath_regex -i &ir=1&rr=12
- acl yutube url_regex -i youtube\.com\/(generate_204|ptracking|stream_204|player_204|s|(.*(playback|watchtime|delayplay)))\?.*$
- acl yutube url_regex -i gstatic\.com\/csi\?.*$
- acl rewritedoms url_regex -i dl\.sourceforge\.net.*
- acl rewritedoms url_regex -i i[0-9]*\.ytimg\.com.*
- acl rewritedoms url_regex -i ak\.fbcdn\.net.*
- acl rewritedoms url_regex -i (youtube|google).*\/videoplayback\?.*
- store_id_program /etc/squid/store-id.pl
- store_id_children 20 startup=10 idle=5 concurrency=30
- store_id_access deny !getmethod
- store_id_access deny redir
- store_id_access deny dontrewrite
- store_id_access allow rewritedoms
- store_id_access allow youtube
- store_id_access allow speedtest
- store_id_access allow reverbnation
- store_id_access deny all
- strip_query_terms off
- max_stale 1 year
- refresh_pattern -i akamaihd.net.* 43830 99% 43830 override-expire override-lastmod ignore-reload
- refresh_pattern -i https:\/\/.*\.xx\.fbcdn\.net\/.* 43830 99% 43830 override-expire override-lastmod ignore-reload
- refresh_pattern ^.*safebrowsing.*google 43830 99% 43830 override-expire ignore-reload ignore-no-store ignore-private ignore-auth ignore-must-revalidate store-stale
- refresh_pattern -i \.wikimapia\.org\/? 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-private
- refresh_pattern -i \.(gif|png|pnp|img|jpg|jpeg|jpe?g|jpeg2|ico|mod|bmp|eps|tif|tiff?|pcx|pic|tga|iff|sct|pxr|raw|dcs|rle|lzw|ccit|f3d|woff)$ 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i \.(pps|ppsx|ps|rtx|wpl|doc|docx|pdf|xls|xlsx|latex|ppt|pptx|mbd|conf|txt|asm|pl|log|dll|bat|psd)$ 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i \.(mp4|3ivx|asf|avi|m2ts|divx|mjpeg|ogv|webm|mpg|mpeg|ogg|wmv|mkv|3gp|swf|flv|x-flv|3g2|vob|swf|swz|mov)$ 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i \.(ogg|mp2|ac3|mpc|m4a|flac|aiff|aif|aifc|raw|au|mid|wav|wv|mp3|gsm|dct|aac|mmf|wma|atrac|ra|ram|dss|msv|dvf|m4p|amr|awb|ape|apl)$ 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i \.(exe|dfg|crx|7z|mds|mod|mdl|arj|bz2|ms-dos|ccd|sub|deb|cab|pak|bin|cue|nrg|isz|mdf|qt|zip|tar|jar|jxr|jad|tar.gz|tar|msi|inc|lha|ms(i|p|u)|rpm|tgz|rtp|rpz|nui|kom|stg|pak|sup|nzp|npz|tgz|reg|vpx|idx|gz|avc|ref|msp|iso|info.gz|vdf.gz|rar|mar|dat|rp)$ 110080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i \.(css|js)$ 10080 99% 10080 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth store-stale
- refresh_pattern -i (hackshield|nprotect|webnProtect) 0 0% 0
- refresh_pattern -i \.(php|html|xml|aspx)$\? 0 0% 0
- ################################
- refresh_pattern ^http.*(youtube|googlevideo)\.* 43200 99% 242020 ignore-reload override-expire override-lastmod ignore-must-revalidate ignore-private ignore-no-store ignore-auth store-stale
- #FB
- refresh_pattern \.facebook\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private
- refresh_pattern \.facebook\.com.* 240 50% 480
- refresh_pattern \.fbcdn\.net.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private store-stale
- refresh_pattern \.gstatic\.com/images\? 1440 99% 14400 override-expire override-lastmod ignore-reload ignore-private ignore-must-revalidate
- refresh_pattern \.(akamaihd|edgecastcdn|spilcdn|zgncdn|(tw|y|yt)img)\.com.*\.(jp(e?g|e|2)|gif|png|swf|mp(3|4)) 1440 99% 14400 override-expire override-lastmod ignore-reload ignore-private
- refresh_pattern (gstatic|diggstatic)\.com/.* 1440 99% 14400 override-expire ignore-reload ignore-private
- refresh_pattern (photobucket|pbsrc|flickr|yimg|ytimg|twimg|gravatar)\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private
- refresh_pattern (zynga|ninjasaga|mafiawars|cityville|farmville|crowdstar|spilcdn|agame|popcap)\.com/.* 1440 99% 14400 override-expire ignore-reload ignore-private
- refresh_pattern ^http:\/\/images|image|img|pics|openx|thumbs[0-9]\. 1440 99% 14400 override-expire ignore-reload ignore-private
- refresh_pattern ^.*safebrowsing.*google 1440 99% 14400 override-expire ignore-reload ignore-private ignore-auth ignore-must-revalidate
- refresh_pattern ^http://.*\.squid\.internal\/.* 10080 100% 79900 override-expire override-lastmod ignore-reload ignore-no-store ignore-must-revalidate ignore-private ignore-auth max-stale=10000 store-stale
- refresh_pattern -i reverbnation.com 1440 99% 14400 override-expire override-lastmod ignore-no-cache ignore-private ignore-must-revalidate ignore-reload store-stale
- refresh_pattern (get_video\?|videoplayback\?|videodownload\?|\.flv\?|\.fid\?) 43200 99% 43200 override-expire ignore-reload ignore-must-revalidate ignore-private
- #
- #PATTERN REFRESH
- refresh_pattern -i \.(html|htm|css|js|png|jsp|asx|asp|aspx)$ 240 100% 420
- refresh_pattern -i \/speedtest\/.*\.(txt|jpg|png|swf) 0 99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
- refresh_pattern .pixieimage\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
- refresh_pattern .blogspot\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
- refresh_pattern .multiply\.com.*\.(jp(e?g|e|2)|gif|png|tiff?|bmp|swf|mp(4|3)) 1440 99% 14400 override-expire ignore-reload ignore-private ignore-reload override-lastmod reload-into-ims
- refresh_pattern .((pikawarnet\.com)|(blogspot\.com)|(pixieimage\.com)|(multiply\.com)).* 60 30% 240
- # Add any of your own refresh_pattern entries above these.
- #
- refresh_pattern ^ftp: 1440 20% 10080
- refresh_pattern ^gopher: 1440 0% 1440
- refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
- refresh_pattern . 0 20% 4320
- ########################################################
- range_offset_limit 1 KB
- quick_abort_min 0 KB
- quick_abort_max 0 KB
- quick_abort_pct 100
- ##############################################
- forwarded_for off
- request_header_access X-Forwarded-For deny all
- request_header_access From deny all
- request_header_access Server deny all
- request_header_access Link deny all
- request_header_access Via deny all
- request_header_access WWW-Authenticate deny all
- request_header_access Cache-Control deny all
- request_header_access Proxy-Connection deny all
- request_header_access X-Cache deny all
- request_header_access X-Cache-Lookup deny all
- request_header_access Forwarded-For deny all
- request_header_access Pragma deny all
- request_header_access Keep-Alive deny all
- dns_nameservers 8.8.8.8 8.8.4.4
- offline_mode off
- memory_pools off
- client_db off
- cache_effective_user proxy
- cache_effective_group proxy
- reload_into_ims on
- vary_ignore_expire on
- qos_flows local-hit=0x30
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement