Proxy servers have been in the information as of overdue, both as a outcome of the Iran putative poll and a existing legal case where Microsoft is suing purveyors of promoting bond deception. I information I could hold you by means of whatsoever proxies are, how they may well be second hand for both accepted and evil, and no matter what all the fuss is about.
primarily, here is a small atmosphere. When you move up your world wide web mozilla firefox browser, you are requested how you desire it to connect to the world wide web. Some of us that have domicile PCs don't deplete any proxy, and go out to the raw web without any fuss or nag. except companies that demanded to split behind on their bandwidth usage, maximize behavior and safeguard, and have dominate above anything their users visit use up them all the age.
Showing posts with label network. Show all posts
Showing posts with label network. Show all posts
Proxy List
extricated proxy sites, new agent 2011, placeholder move. You can reason a lot of loose agent on the activity, and servers too. Yet, the top character isn't the selfsame throughout, and there will oft be both which are far punter than the else folks. You hold to be selective regularise if they do not cost a convexity.
One among the items that you but moldiness do gift belike be to lie at the website. No entity whether it rattling is an travail or a server, you are exploit to bang to be careful the kinds of programs there are detailed; you don't compliments to download a group whose functions you might be not acquainted with. The far more info in regards to the freed procurator machine software around the parcel, the easier it is going to be to determine. In framing you are an front somebody the traducement with the applications faculty potential be recognisable.
Yet, new users do not cognize which ones would be the very someone, so it is obligatory that the information concerning it are elaborated. Patch various of them are filled with numerous functions, you should think the fact that you mightiness not use them all. Psychoanalyze your demands cautiously. Swing in too numerous of them simultaneously may actually ending in troubles wrong your laptop or machine.
In traffic to cost-free agent servers, you pauperism to ever see web sites that confirm and update their records oftentimes. Individual of the most favorite ones are updated apiece and every 20 transactions or so. Aver into statement that because they are totally inexact, a lot of individuals gain them, so it might bear a change though preceding to you judge 1 that you can infix with often.
If you are looking to try and remain anon. on the internet, then there's an superior hazard that you hold stumbled on sites which supplying totally released proxies of one sort or an more. You should use totally remove placeholder internet sites with care, as there could be author exploit on behind the scenes than you instrument be conscious of. If your concealment is really alpha to you, then be dilatory when employing any variety of totally loose placeholder on the web.
One among the items that you but moldiness do gift belike be to lie at the website. No entity whether it rattling is an travail or a server, you are exploit to bang to be careful the kinds of programs there are detailed; you don't compliments to download a group whose functions you might be not acquainted with. The far more info in regards to the freed procurator machine software around the parcel, the easier it is going to be to determine. In framing you are an front somebody the traducement with the applications faculty potential be recognisable.
Yet, new users do not cognize which ones would be the very someone, so it is obligatory that the information concerning it are elaborated. Patch various of them are filled with numerous functions, you should think the fact that you mightiness not use them all. Psychoanalyze your demands cautiously. Swing in too numerous of them simultaneously may actually ending in troubles wrong your laptop or machine.
In traffic to cost-free agent servers, you pauperism to ever see web sites that confirm and update their records oftentimes. Individual of the most favorite ones are updated apiece and every 20 transactions or so. Aver into statement that because they are totally inexact, a lot of individuals gain them, so it might bear a change though preceding to you judge 1 that you can infix with often.
If you are looking to try and remain anon. on the internet, then there's an superior hazard that you hold stumbled on sites which supplying totally released proxies of one sort or an more. You should use totally remove placeholder internet sites with care, as there could be author exploit on behind the scenes than you instrument be conscious of. If your concealment is really alpha to you, then be dilatory when employing any variety of totally loose placeholder on the web.
Squid Proxy ClarkConnect Community Edition 4
The following is the result oprek setting Squid Proxy Jiliid ClarkConnect Community Edition 2. Her results are better than the previous squid setting. Arguably this is a tweaking to optimize squid proxy proxy linux machine. Configuring squid proxy even this you can plug in your ClarkConnect which functioned as a gateway or router. Siilakan studied and adjusted to your Network IP configuration ... This tweaking can you apply to another linux distro, of course, by adjusting the squid you use.
Here's How to configure it the same as before:
1. Clarckconnect your remote ip using WinSCP, FileZilla, CuteFTP or the laen
2. entered into the directory / etc / squid / squid.conf open / edit delete smua contents, then paste existing configuration below. DO NOT FORGET backing up the old squid.conf configuration and IP NETWORK customize your new squid configuration first. If not, then an error occurs when you restart squid in it. Ojo numb .... Mbaaaahhh kekekkeee
3. Save the configuration, and remote Clarkconnect you with putty, restart Squid by typing # / etc / init.d / squid restart ... enter. If the squid stop and start as normal and you can browse ... congratulations .... You have successfully configured your Squid proxy with good and right and running well.
Here is his squid.conf configuration ...
http_port 192.168.1.254:3128 # LAN IPhttp_port 127.0.0.1:3128hierarchy_stoplist cgi-bin? localhostacl QUERY urlpath_regex cgi-bin \? localhostno_cache deny QUERYipcache_size 8192cache_mem 256 MBmaximum_object_size_in_memory 32 KBstore_dir_select_algorithm least-loadminimum_object_size 0 KBrange_offset_limit -1maximum_object_size 200 MBcache_swap_low 98cache_swap_high 99ipcache_low 98ipcache_high 99fqdncache_size 8192cache_dir ufs / var / spool / squid 20000 60 256redirect_program / usr / sbin / adzapperredirect_children 10auth_param ntlm children 15auth_param ntlm max_challenge_reuses 0max_challenge_lifetime 2 minutes auth_param ntlmauth_param ntlm use_ntlm_negotiate onauth_param basic program / usr / lib / squid / squid_ldap_auth-b "dc = host_anda, dc = net"-f "(& (objectclass = pcnProxyAccount) (uid =% s))"-h 127.0.0.1-D "cn = manager, cn = internal, dc = smkyapisbiak, dc = net "-W / etc / squid / ldap.conf-s one-v 3-U-d pcnProxyPasswordauth_param basic children 5auth_param basic realm ClarkConnect Community Edition - Web Proxy2 hours auth_param basic credentialsttlrefresh_pattern-i ^ http:// *. windowsupdate.com / .* 518 400 99% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (tiff | mov | avi | qt | mpeg | wmv | ra | rm | avi | divx) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (class | css | js | gif | jpg | ps) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (JPE | jpeg | png | bmp | tif) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (mpg | mpe | wav | au | mid | mp3 | mp4 | ac4 | swf) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | gz | arj | lha | LZH | 7z) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | tgz | tar | exe | bin | rpm | iso) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (hqx | pdf | rtf | doc | swf | xls | ppt | doc | docx | xlsx) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (inc | cab | ad | txt | etc. | dat) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. zynga.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. friendster.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. kompas.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. detik.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. facebook.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern-i ^ http:// *. bhinneka.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. fbcdn.net / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern. 720 50% 432 000 reload-into-ims override-lastmodrefresh_pattern ^ ftp:1440 20% 10 080refresh_pattern ^ gopher: 1440 0% 1440refresh_pattern. 0 20% 4320quick_abort_min 0 KBquick_abort_max 0 KBquick_abort_pct 95half_closed_clients offshutdown_lifetime 10 secondsacl all src 0.0.0.0/0.0.0.0acl manager proto cache_objectacl localhost src 127.0.0.0 / 8webconfig_lan acl src 192.168.1.0/24 # IP Network Localwebconfig_to_lan 192.168.1.0/24 # acl dst IP Local Networkto_localhost acl dst 127.0.0.0 / 8proxy_auth REQUIRED acl passwordacl Privoxy dstdomain config.privoxy.orgSSL_ports port 443 563 aclSSL_ports port 81 10000 aclacl Safe_ports port 80acl Safe_ports port 21acl Safe_ports port 443 563acl Safe_ports port 70acl Safe_ports port 210acl Safe_ports port 1025-65535acl Safe_ports port 280acl Safe_ports port 488acl Safe_ports port 591acl Safe_ports port 777acl Safe_ports port 81 82 83 10000 # Web-based administration toolsacl CONNECT method CONNECThttp_access allow manager localhosthttp_access deny managerhttp_access deny! Safe_portshttp_access deny CONNECT! SSL_portsurl_regex sex acl-i "/ etc / squid / sex"deny_info ERR_ACCESS_DENIED sexhttp_access deny sexour_networks acl src 192.168.1.0/24 # IP Network Localhttp_access allow our_networkshttp_access deny Privoxyhttp_access allow localhosthttp_access allow webconfig_to_lanhttp_access allow webconfig_lanhttp_access deny allhttp_reply_access allow alldns_testnames 5icp_access allow all52428800 reply_body_max_size allow allcache_effective_user squidcache_effective_group squidvirtual httpd_accel_hosthttpd_accel_port 80httpd_accel_with_proxy onhttpd_accel_uses_host_header onmemory_pools offmemory_pools_limit 2048 MBforwarded_for offstore_avg_object_size 50 KBreload_into_ims onerror_directory / etc / squid / errorsmaximum_single_addr_tries 3coredump_dir / usr / local / squid / var / cachebalance_on_multiple_ip onpipeline_prefetch ondelay_pools 0positive_dns_ttl 1 yearconnect_timeout 1 minute# Delay_pools 1# Delay_class 1 2# Delay_parameters a -1/-1 16000/64000coredump_dir / var / spool / squidclient_persistent_connections onserver_persistent_connections offpersistent_connection_after_error onie_refresh onvary_ignore_expire onfollow_x_forwarded_for allow localhost
Here's How to configure it the same as before:
1. Clarckconnect your remote ip using WinSCP, FileZilla, CuteFTP or the laen
2. entered into the directory / etc / squid / squid.conf open / edit delete smua contents, then paste existing configuration below. DO NOT FORGET backing up the old squid.conf configuration and IP NETWORK customize your new squid configuration first. If not, then an error occurs when you restart squid in it. Ojo numb .... Mbaaaahhh kekekkeee
3. Save the configuration, and remote Clarkconnect you with putty, restart Squid by typing # / etc / init.d / squid restart ... enter. If the squid stop and start as normal and you can browse ... congratulations .... You have successfully configured your Squid proxy with good and right and running well.
4. Done ... coffee ... sedotz's cigarette ... .. while enjoying browsing the Mak Nyoooooooozzzzzzzzzzzzzz ... ... ... ..
Here is his squid.conf configuration ...
http_port 192.168.1.254:3128 # LAN IPhttp_port 127.0.0.1:3128hierarchy_stoplist cgi-bin? localhostacl QUERY urlpath_regex cgi-bin \? localhostno_cache deny QUERYipcache_size 8192cache_mem 256 MBmaximum_object_size_in_memory 32 KBstore_dir_select_algorithm least-loadminimum_object_size 0 KBrange_offset_limit -1maximum_object_size 200 MBcache_swap_low 98cache_swap_high 99ipcache_low 98ipcache_high 99fqdncache_size 8192cache_dir ufs / var / spool / squid 20000 60 256redirect_program / usr / sbin / adzapperredirect_children 10auth_param ntlm children 15auth_param ntlm max_challenge_reuses 0max_challenge_lifetime 2 minutes auth_param ntlmauth_param ntlm use_ntlm_negotiate onauth_param basic program / usr / lib / squid / squid_ldap_auth-b "dc = host_anda, dc = net"-f "(& (objectclass = pcnProxyAccount) (uid =% s))"-h 127.0.0.1-D "cn = manager, cn = internal, dc = smkyapisbiak, dc = net "-W / etc / squid / ldap.conf-s one-v 3-U-d pcnProxyPasswordauth_param basic children 5auth_param basic realm ClarkConnect Community Edition - Web Proxy2 hours auth_param basic credentialsttlrefresh_pattern-i ^ http:// *. windowsupdate.com / .* 518 400 99% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (tiff | mov | avi | qt | mpeg | wmv | ra | rm | avi | divx) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (class | css | js | gif | jpg | ps) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (JPE | jpeg | png | bmp | tif) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (mpg | mpe | wav | au | mid | mp3 | mp4 | ac4 | swf) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | gz | arj | lha | LZH | 7z) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | tgz | tar | exe | bin | rpm | iso) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (hqx | pdf | rtf | doc | swf | xls | ppt | doc | docx | xlsx) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (inc | cab | ad | txt | etc. | dat) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. zynga.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. friendster.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. kompas.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. detik.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. facebook.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern-i ^ http:// *. bhinneka.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. fbcdn.net / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern. 720 50% 432 000 reload-into-ims override-lastmodrefresh_pattern ^ ftp:1440 20% 10 080refresh_pattern ^ gopher: 1440 0% 1440refresh_pattern. 0 20% 4320quick_abort_min 0 KBquick_abort_max 0 KBquick_abort_pct 95half_closed_clients offshutdown_lifetime 10 secondsacl all src 0.0.0.0/0.0.0.0acl manager proto cache_objectacl localhost src 127.0.0.0 / 8webconfig_lan acl src 192.168.1.0/24 # IP Network Localwebconfig_to_lan 192.168.1.0/24 # acl dst IP Local Networkto_localhost acl dst 127.0.0.0 / 8proxy_auth REQUIRED acl passwordacl Privoxy dstdomain config.privoxy.orgSSL_ports port 443 563 aclSSL_ports port 81 10000 aclacl Safe_ports port 80acl Safe_ports port 21acl Safe_ports port 443 563acl Safe_ports port 70acl Safe_ports port 210acl Safe_ports port 1025-65535acl Safe_ports port 280acl Safe_ports port 488acl Safe_ports port 591acl Safe_ports port 777acl Safe_ports port 81 82 83 10000 # Web-based administration toolsacl CONNECT method CONNECThttp_access allow manager localhosthttp_access deny managerhttp_access deny! Safe_portshttp_access deny CONNECT! SSL_portsurl_regex sex acl-i "/ etc / squid / sex"deny_info ERR_ACCESS_DENIED sexhttp_access deny sexour_networks acl src 192.168.1.0/24 # IP Network Localhttp_access allow our_networkshttp_access deny Privoxyhttp_access allow localhosthttp_access allow webconfig_to_lanhttp_access allow webconfig_lanhttp_access deny allhttp_reply_access allow alldns_testnames 5icp_access allow all52428800 reply_body_max_size allow allcache_effective_user squidcache_effective_group squidvirtual httpd_accel_hosthttpd_accel_port 80httpd_accel_with_proxy onhttpd_accel_uses_host_header onmemory_pools offmemory_pools_limit 2048 MBforwarded_for offstore_avg_object_size 50 KBreload_into_ims onerror_directory / etc / squid / errorsmaximum_single_addr_tries 3coredump_dir / usr / local / squid / var / cachebalance_on_multiple_ip onpipeline_prefetch ondelay_pools 0positive_dns_ttl 1 yearconnect_timeout 1 minute# Delay_pools 1# Delay_class 1 2# Delay_parameters a -1/-1 16000/64000coredump_dir / var / spool / squidclient_persistent_connections onserver_persistent_connections offpersistent_connection_after_error onie_refresh onvary_ignore_expire onfollow_x_forwarded_for allow localhost
Here's How to configure it the same as before:
1. Clarckconnect your remote ip using WinSCP, FileZilla, CuteFTP or the laen
2. entered into the directory / etc / squid / squid.conf open / edit delete smua contents, then paste existing configuration below. DO NOT FORGET backing up the old squid.conf configuration and IP NETWORK customize your new squid configuration first. If not, then an error occurs when you restart squid in it. Ojo numb .... Mbaaaahhh kekekkeee
3. Save the configuration, and remote Clarkconnect you with putty, restart Squid by typing # / etc / init.d / squid restart ... enter. If the squid stop and start as normal and you can browse ... congratulations .... You have successfully configured your Squid proxy with good and right and running well.
Here is his squid.conf configuration ...
http_port 192.168.1.254:3128 # LAN IPhttp_port 127.0.0.1:3128hierarchy_stoplist cgi-bin? localhostacl QUERY urlpath_regex cgi-bin \? localhostno_cache deny QUERYipcache_size 8192cache_mem 256 MBmaximum_object_size_in_memory 32 KBstore_dir_select_algorithm least-loadminimum_object_size 0 KBrange_offset_limit -1maximum_object_size 200 MBcache_swap_low 98cache_swap_high 99ipcache_low 98ipcache_high 99fqdncache_size 8192cache_dir ufs / var / spool / squid 20000 60 256redirect_program / usr / sbin / adzapperredirect_children 10auth_param ntlm children 15auth_param ntlm max_challenge_reuses 0max_challenge_lifetime 2 minutes auth_param ntlmauth_param ntlm use_ntlm_negotiate onauth_param basic program / usr / lib / squid / squid_ldap_auth-b "dc = host_anda, dc = net"-f "(& (objectclass = pcnProxyAccount) (uid =% s))"-h 127.0.0.1-D "cn = manager, cn = internal, dc = smkyapisbiak, dc = net "-W / etc / squid / ldap.conf-s one-v 3-U-d pcnProxyPasswordauth_param basic children 5auth_param basic realm ClarkConnect Community Edition - Web Proxy2 hours auth_param basic credentialsttlrefresh_pattern-i ^ http:// *. windowsupdate.com / .* 518 400 99% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (tiff | mov | avi | qt | mpeg | wmv | ra | rm | avi | divx) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (class | css | js | gif | jpg | ps) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (JPE | jpeg | png | bmp | tif) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (mpg | mpe | wav | au | mid | mp3 | mp4 | ac4 | swf) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | gz | arj | lha | LZH | 7z) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | tgz | tar | exe | bin | rpm | iso) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (hqx | pdf | rtf | doc | swf | xls | ppt | doc | docx | xlsx) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (inc | cab | ad | txt | etc. | dat) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. zynga.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. friendster.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. kompas.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. detik.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. facebook.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern-i ^ http:// *. bhinneka.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. fbcdn.net / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern. 720 50% 432 000 reload-into-ims override-lastmodrefresh_pattern ^ ftp:1440 20% 10 080refresh_pattern ^ gopher: 1440 0% 1440refresh_pattern. 0 20% 4320quick_abort_min 0 KBquick_abort_max 0 KBquick_abort_pct 95half_closed_clients offshutdown_lifetime 10 secondsacl all src 0.0.0.0/0.0.0.0acl manager proto cache_objectacl localhost src 127.0.0.0 / 8webconfig_lan acl src 192.168.1.0/24 # IP Network Localwebconfig_to_lan 192.168.1.0/24 # acl dst IP Local Networkto_localhost acl dst 127.0.0.0 / 8proxy_auth REQUIRED acl passwordacl Privoxy dstdomain config.privoxy.orgSSL_ports port 443 563 aclSSL_ports port 81 10000 aclacl Safe_ports port 80acl Safe_ports port 21acl Safe_ports port 443 563acl Safe_ports port 70acl Safe_ports port 210acl Safe_ports port 1025-65535acl Safe_ports port 280acl Safe_ports port 488acl Safe_ports port 591acl Safe_ports port 777acl Safe_ports port 81 82 83 10000 # Web-based administration toolsacl CONNECT method CONNECThttp_access allow manager localhosthttp_access deny managerhttp_access deny! Safe_portshttp_access deny CONNECT! SSL_portsurl_regex sex acl-i "/ etc / squid / sex"deny_info ERR_ACCESS_DENIED sexhttp_access deny sexour_networks acl src 192.168.1.0/24 # IP Network Localhttp_access allow our_networkshttp_access deny Privoxyhttp_access allow localhosthttp_access allow webconfig_to_lanhttp_access allow webconfig_lanhttp_access deny allhttp_reply_access allow alldns_testnames 5icp_access allow all52428800 reply_body_max_size allow allcache_effective_user squidcache_effective_group squidvirtual httpd_accel_hosthttpd_accel_port 80httpd_accel_with_proxy onhttpd_accel_uses_host_header onmemory_pools offmemory_pools_limit 2048 MBforwarded_for offstore_avg_object_size 50 KBreload_into_ims onerror_directory / etc / squid / errorsmaximum_single_addr_tries 3coredump_dir / usr / local / squid / var / cachebalance_on_multiple_ip onpipeline_prefetch ondelay_pools 0positive_dns_ttl 1 yearconnect_timeout 1 minute# Delay_pools 1# Delay_class 1 2# Delay_parameters a -1/-1 16000/64000coredump_dir / var / spool / squidclient_persistent_connections onserver_persistent_connections offpersistent_connection_after_error onie_refresh onvary_ignore_expire onfollow_x_forwarded_for allow localhost
Here's How to configure it the same as before:
1. Clarckconnect your remote ip using WinSCP, FileZilla, CuteFTP or the laen
2. entered into the directory / etc / squid / squid.conf open / edit delete smua contents, then paste existing configuration below. DO NOT FORGET backing up the old squid.conf configuration and IP NETWORK customize your new squid configuration first. If not, then an error occurs when you restart squid in it. Ojo numb .... Mbaaaahhh kekekkeee
3. Save the configuration, and remote Clarkconnect you with putty, restart Squid by typing # / etc / init.d / squid restart ... enter. If the squid stop and start as normal and you can browse ... congratulations .... You have successfully configured your Squid proxy with good and right and running well.
4. Done ... coffee ... sedotz's cigarette ... .. while enjoying browsing the Mak Nyoooooooozzzzzzzzzzzzzz ... ... ... ..
Here is his squid.conf configuration ...
http_port 192.168.1.254:3128 # LAN IPhttp_port 127.0.0.1:3128hierarchy_stoplist cgi-bin? localhostacl QUERY urlpath_regex cgi-bin \? localhostno_cache deny QUERYipcache_size 8192cache_mem 256 MBmaximum_object_size_in_memory 32 KBstore_dir_select_algorithm least-loadminimum_object_size 0 KBrange_offset_limit -1maximum_object_size 200 MBcache_swap_low 98cache_swap_high 99ipcache_low 98ipcache_high 99fqdncache_size 8192cache_dir ufs / var / spool / squid 20000 60 256redirect_program / usr / sbin / adzapperredirect_children 10auth_param ntlm children 15auth_param ntlm max_challenge_reuses 0max_challenge_lifetime 2 minutes auth_param ntlmauth_param ntlm use_ntlm_negotiate onauth_param basic program / usr / lib / squid / squid_ldap_auth-b "dc = host_anda, dc = net"-f "(& (objectclass = pcnProxyAccount) (uid =% s))"-h 127.0.0.1-D "cn = manager, cn = internal, dc = smkyapisbiak, dc = net "-W / etc / squid / ldap.conf-s one-v 3-U-d pcnProxyPasswordauth_param basic children 5auth_param basic realm ClarkConnect Community Edition - Web Proxy2 hours auth_param basic credentialsttlrefresh_pattern-i ^ http:// *. windowsupdate.com / .* 518 400 99% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (tiff | mov | avi | qt | mpeg | wmv | ra | rm | avi | divx) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (class | css | js | gif | jpg | ps) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (JPE | jpeg | png | bmp | tif) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (mpg | mpe | wav | au | mid | mp3 | mp4 | ac4 | swf) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | gz | arj | lha | LZH | 7z) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (zip | tgz | tar | exe | bin | rpm | iso) $ 1,440 90% 432 000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (hqx | pdf | rtf | doc | swf | xls | ppt | doc | docx | xlsx) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i \. (inc | cab | ad | txt | etc. | dat) $ 1440 90% 432000 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. zynga.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. friendster.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. kompas.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. detik.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. facebook.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern-i ^ http:// *. bhinneka.com / .* 432 000 90% 1440 override-expire override-lastmod reload-into-ims ignore-reloadrefresh_pattern-i ^ http:// *. fbcdn.net / .* 432 000 90% 1440 override-expire override-lastmod reload-into-imsrefresh_pattern. 720 50% 432 000 reload-into-ims override-lastmodrefresh_pattern ^ ftp:1440 20% 10 080refresh_pattern ^ gopher: 1440 0% 1440refresh_pattern. 0 20% 4320quick_abort_min 0 KBquick_abort_max 0 KBquick_abort_pct 95half_closed_clients offshutdown_lifetime 10 secondsacl all src 0.0.0.0/0.0.0.0acl manager proto cache_objectacl localhost src 127.0.0.0 / 8webconfig_lan acl src 192.168.1.0/24 # IP Network Localwebconfig_to_lan 192.168.1.0/24 # acl dst IP Local Networkto_localhost acl dst 127.0.0.0 / 8proxy_auth REQUIRED acl passwordacl Privoxy dstdomain config.privoxy.orgSSL_ports port 443 563 aclSSL_ports port 81 10000 aclacl Safe_ports port 80acl Safe_ports port 21acl Safe_ports port 443 563acl Safe_ports port 70acl Safe_ports port 210acl Safe_ports port 1025-65535acl Safe_ports port 280acl Safe_ports port 488acl Safe_ports port 591acl Safe_ports port 777acl Safe_ports port 81 82 83 10000 # Web-based administration toolsacl CONNECT method CONNECThttp_access allow manager localhosthttp_access deny managerhttp_access deny! Safe_portshttp_access deny CONNECT! SSL_portsurl_regex sex acl-i "/ etc / squid / sex"deny_info ERR_ACCESS_DENIED sexhttp_access deny sexour_networks acl src 192.168.1.0/24 # IP Network Localhttp_access allow our_networkshttp_access deny Privoxyhttp_access allow localhosthttp_access allow webconfig_to_lanhttp_access allow webconfig_lanhttp_access deny allhttp_reply_access allow alldns_testnames 5icp_access allow all52428800 reply_body_max_size allow allcache_effective_user squidcache_effective_group squidvirtual httpd_accel_hosthttpd_accel_port 80httpd_accel_with_proxy onhttpd_accel_uses_host_header onmemory_pools offmemory_pools_limit 2048 MBforwarded_for offstore_avg_object_size 50 KBreload_into_ims onerror_directory / etc / squid / errorsmaximum_single_addr_tries 3coredump_dir / usr / local / squid / var / cachebalance_on_multiple_ip onpipeline_prefetch ondelay_pools 0positive_dns_ttl 1 yearconnect_timeout 1 minute# Delay_pools 1# Delay_class 1 2# Delay_parameters a -1/-1 16000/64000coredump_dir / var / spool / squidclient_persistent_connections onserver_persistent_connections offpersistent_connection_after_error onie_refresh onvary_ignore_expire onfollow_x_forwarded_for allow localhost
Building Of A Proxy Server + Ubuntu Mikrotik 10:10 - Part 1
| Previously, I say thank you so much for your permission and support of Rizzal Bang Bang menbagi Bastian for science in the blog inil After finally battered oprek Mikrotik Proxy + Ubuntu Server 10.10 (32/64bit) is finished results are incredible as well dah .. . Ok with no strings attached .. trigger cigarettes run out, the following preparations: IP topology above is not written by authors only, therefore you are free to change the IP and customize to your IP !!!!! If you are not thinking about the Ubuntu CD Ubuntu Server 10:10 please download below: 64 Bit 32 Bit Download Download and burn to CD 1. Prepare the Ubuntu Server CD 10.10 (32 Bit or 64 Bit) - Advice for Beginners 32 Bit 2. 1 CPU Intel Pentium 4 / AMD, 2 GB of RAM minimum, 160GB HD-minimal, 1 NIC, CDROM 3. Cable Cross 4 MikroTik which can already internet Next follow the step by step installation of ubuntu (Caution, caution in the installation, incorrect installation FAILED proxy !!!!) 10:10 UBUNTU 64 bit Btrfs Step by step (CPU Proxy jgn in relation to the Internet first when installing, so that the process is faster) 1. INSERT INTO UBUNTU CD AND CDROM boot choose to cdroom, 2. Choose the language bahasa (enter) 3. Select install ubuntu server (enter) 4. Press enter to choose langguage bahasa 5. Select the united states 6. Click no to detect the keyboard layout? 7. USA Click on the Ubuntu installer main menu 8. USA Click on the keyboard layout 9. Click continue to configure the network 10. Select the network manually configure the contents of the ip address 192.168.11.11 dg enter select continue 11. Netmask 255.255.255.0 enter select continue 12. Gateway 192.168.11.1 continue click continue 13. Name server addresses 192.168.11.1 enter select continue 14. Hotsnama: dg contents proxyku continue continue select enter 15. Domain name: the blank only, select continue enter 16. On the Configure the clok choose select from the list continues to search worldwide jakarta (adjust your location) continues to enter 17. On the menu select manually partition the disk 18. We delete the old partition first: 19. Select the partition continues to enter his select delete the partion (repeat this command for all partitions reply left) 20. When you have finished select Guided partitioning, then select manually navigate to the FREE SPACE (enter), 21. Select Create new partition (enter) 22. New partition size content of 256 mb (select continue and enter), select Primary (enter), select the Beginning (enter), to use as select EXT4 (enter) at the Mount Point select / boot (enter), pd mount option select [*] noatime (select continue and enter), the fox becomes a bootable flag on TDK IF HIS STATUS CHANGED JUST IGNORE then select done setting up the partition 23. New partition size of 20 gb (select continue and enter), select Primary (enter), select the Beginning (enter), to use as select EXT4 (enter) at the Mount Point select / (enter), pd mount option select [*] noatime (select continue and enter), then select done setting up the partition 24. Navigate to the FREE SPACE (enter), select Create new partition (enter) the contents of the new partition size 4 gb (2x size of RAM) select continue and enter, select Primary (enter), select the Beginning (enter), to use as select the swap area ( enter), then Select done setting up the partition 25. Navigate to the FREE SPACE (enter), select Create new partition (enter) the new partition size of all the remaining contents of the hard drive (select continue and enter), select Primary (enter), select the Beginning (enter), to use as select Btrfs or Reinsfers (enter ) NOTE: Btrfs to 64bit Reinfers for 32bit manually enter the Moun point for the / cache, pd mount option select [*] noatime and realtime then Select continue and done setting up the partition 26. Then select finish partitioning and write changes to disk, write the changes to disk select yes 27. the full name for the new user content dg proxyku, continue to continue & enter 28. Username for your account on the content of dg proxyku, continue to continue & enter 29. on a user's password for the new content dg proxyku, continue to continue & enter 30. to re-enter password to verify the contents of dg proxyku, continue to continue & enter 31. to use weak passwords select yes 32. to encrypt your home directory select no 33. the HTTP proxy information blank ONLY 34. 43% on apt config press enter, also in 81% press enter select no automatic updates 35.pada choose software to install select the OpenSSH server select continus pd finish the installation and reboot, grab the Ubuntu CD, 1st Boot returned to the HDD further # Login dg proxyku # Password proxyku # Sudo su - # Content proxyku if you want to login as root every reboot ubuntu follow these steps: # Type passwd Enter new UNIX password # dg proxyku contents # Retype new UNIX password proxyku contents The following step was remote Mikrotik Winbox, new terminals, fill his ip in the usual way: ip address add address 192.168.11.1/24 interface = ether3 CROSS connect the cable to the CPU and connect to mikrotik port 3 check the ping of each cpu and mikrotik ping 192.168.11.11 and ping 192.168.11.1 if they reply and ping from DNS, if the reply is ready to install the proxy If not reply and ubuntu reboot mikrotik, jik not reply also check the IP is wrong If not reply CABLE One kaleeeeeeeee (pake CROSS bozzz) Install Package antecedent need: # Sudo apt-get update # Sudo apt-get install squid squid-cgi squidclient # Sudo apt-get install gcc # Sudo apt-get install build-essential # Sudo apt-get install sharutils # Sudo apt-get install ccze # Sudo apt-get install-dev libzip # Sudo apt-get install automake1.9 Download Squid 7 Stable 9 on the menu this blog or you download squid-2.7.STABLE9 then you copied to the folder / root using WinSCP in ubuntu and continue: # Tar xvf squid-2.7.STABLE9 + patch.tar.gz # Cd squid-2.7.STABLE9 -> Then you compile the proxy by using the compiler script in the tutorial section to 2. OK until here first ... next First Stage is compiling the kernel and setting the SQUID, sysctl.conf in the Proxy, as well as NAT, mangle, simple queue, queue tree, queue TYPE in Mikrotik. But First patient ... heehehhe sure the steps above you make it through his Success ... If you let me wish deh .. |
Squid 2.7 Patch Update Stable9 overcome parse_refreshpattern
Previous authors have praised the visitors who managed proxy server ubuntu mengoprek 10.10 and managed to add a new disk partition to store the cache. From the comments of the visitors are asked to have a problem parse_refreshpattern: Unknown option when running the command / etc / init.d / squid restart. The authors understand that despite the lack of squid works well and can keep the cache as well. However, there is sempura if there is a small problem. Therefore, the authors of the following messages is a solution to ubuntu squid proxy fully and optimally. Ok just follow these steps ... ...
Please download first squid2.7STABLE9PATCH.tar.gz download menu in this blog, you must rename the copy squid2.7STABLE9.tar.gz in / root Ubuntu Server
2. Remote Ubuntu with putty, stop squid # / etc / init.d / squid stop
3. Retrieved squid2.7STABLE9.tar.gz
# Tar xvf squid-2.7.STABLE9.tar.gz
# Squid 2.7.STABLE9-Cd
4. to translate the heart of the proxy machine
You can get here ->: kernel compilation
Open to select all, copy and paste Ubuntu, right click and enter ... wait for it to finish
follows:
# Make a
# Make install
After a successful compile, download squid.conf menu updated this blog, open WinSCP, the file / etc / squid / squid.conf to edit, and delete all the contents and replace it with, UPDATE, and re-adjust the cache directory ACLs according to the above settings.
Then open and edit squid.conf.pl add the following script:
================================================== =====
http_access deny dontrewrite
http_access deny! GetMethod
http_access allow store_rewrite_list_domain_CDN
http_access allow store_rewrite_list
http_access allow store_rewrite_list_domain
http_access allow store_rewrite_list_path
localhost http_access allow manager
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny! Security doors
Connect http_access deny! sslports
http_access deny all
================================================== =============
srcript you delete and inflicted the above script and then save the file squid.conf and continue squid.conf.pl
# Sudo chmod + x / etc / init.d / squid
# / Etc / init.d / squid stop
customize the cache folder
# Chown proxyku: proxyku / cache1
# Chown proxyku: proxyku / cache2
# Chmod 777 / cache1
# Chmod 777 / cache2
# Chown proxy: proxy / etc / squid / storeurl.pl
# Chmod 777 / etc / squid / storeurl.pl
# Squid-f / etc / squid / squid.conf-z
# / Etc / init.d / squid restart
if you can not parse_refreshpattern: Unknown option .... Congratulations, you've got the squid patch 2.7Stable9 success.
You can view the client log HIT type the command:
tail-f / var / log / squid / access.log | ccze
tail-f / var / log / squid / access.log | grep HIT
NOTE: This update squid.conf configuration is the setting for the dinamyc content. The experience of the author, at the time of complete customer access, 1 (one) day and can afford to store more than 2 GB of hard disk cache to the proxy server, then install the hard drive to a large cache .
Please download first squid2.7STABLE9PATCH.tar.gz download menu in this blog, you must rename the copy squid2.7STABLE9.tar.gz in / root Ubuntu Server
2. Remote Ubuntu with putty, stop squid # / etc / init.d / squid stop
3. Retrieved squid2.7STABLE9.tar.gz
# Tar xvf squid-2.7.STABLE9.tar.gz
# Squid 2.7.STABLE9-Cd
4. to translate the heart of the proxy machine
You can get here ->: kernel compilation
Open to select all, copy and paste Ubuntu, right click and enter ... wait for it to finish
follows:
# Make a
# Make install
After a successful compile, download squid.conf menu updated this blog, open WinSCP, the file / etc / squid / squid.conf to edit, and delete all the contents and replace it with, UPDATE, and re-adjust the cache directory ACLs according to the above settings.
Then open and edit squid.conf.pl add the following script:
================================================== =====
http_access deny dontrewrite
http_access deny! GetMethod
http_access allow store_rewrite_list_domain_CDN
http_access allow store_rewrite_list
http_access allow store_rewrite_list_domain
http_access allow store_rewrite_list_path
localhost http_access allow manager
http_access deny manager
http_access allow purge localhost
http_access deny purge
http_access deny! Security doors
Connect http_access deny! sslports
http_access deny all
================================================== =============
srcript you delete and inflicted the above script and then save the file squid.conf and continue squid.conf.pl
# Sudo chmod + x / etc / init.d / squid
# / Etc / init.d / squid stop
customize the cache folder
# Chown proxyku: proxyku / cache1
# Chown proxyku: proxyku / cache2
# Chmod 777 / cache1
# Chmod 777 / cache2
# Chown proxy: proxy / etc / squid / storeurl.pl
# Chmod 777 / etc / squid / storeurl.pl
# Squid-f / etc / squid / squid.conf-z
# / Etc / init.d / squid restart
if you can not parse_refreshpattern: Unknown option .... Congratulations, you've got the squid patch 2.7Stable9 success.
You can view the client log HIT type the command:
tail-f / var / log / squid / access.log | ccze
tail-f / var / log / squid / access.log | grep HIT
NOTE: This update squid.conf configuration is the setting for the dinamyc content. The experience of the author, at the time of complete customer access, 1 (one) day and can afford to store more than 2 GB of hard disk cache to the proxy server, then install the hard drive to a large cache .
Update Of High-performance Squid Configuration
At the request of visitors to this blog, gives the following configuration squid.conf authors and squid.conf.pl accordance with job title is most capable of storing the cache configuration with its high performance. Mengoprek please the visitors, taking into account LETTERS deliberately included to fit the author's intellectual property and network configuration of your LAN. This configuration is updated and tested on September 2, 2011. By editing this configuration, the cache is already stored on your hard drive, same increase is not lost ..
Things to note:
1. Backup and squid.conf.pl your squid.conf
Second Proxy Remote with WinSCP, copy the squid.conf squid.conf.pl and updates to the file / etc / squid /
3. Edit and change the IP network and LAN with network settings, and save
4. Stop the squid # / etc / init.d / squid stop
5th rebuild the cache # squid-f / etc / squid / squid.conf-z
6. Start squid / etc / init.d / squid start
7. Check with navigation etc www.mivo.tv www.youtube.com
8th Notice if there are any significant changes to your octopus.
HIT 9.Cek representative with the command:
to view the access log customers
# Tail-f / var / log / squid / access.log | ccze
to view the access log has arrived
# Tail-f / var / log / squid / access.log | grep HIT
10. If not, restart the proxy server .. and check your HIT
Things to note:
1. Backup and squid.conf.pl your squid.conf
Second Proxy Remote with WinSCP, copy the squid.conf squid.conf.pl and updates to the file / etc / squid /
3. Edit and change the IP network and LAN with network settings, and save
4. Stop the squid # / etc / init.d / squid stop
5th rebuild the cache # squid-f / etc / squid / squid.conf-z
6. Start squid / etc / init.d / squid start
7. Check with navigation etc www.mivo.tv www.youtube.com
8th Notice if there are any significant changes to your octopus.
HIT 9.Cek representative with the command:
to view the access log customers
# Tail-f / var / log / squid / access.log | ccze
to view the access log has arrived
# Tail-f / var / log / squid / access.log | grep HIT
10. If not, restart the proxy server .. and check your HIT
Building Of A Proxy Server + Ubuntu Mikrotik 10:10 - Part 2
In Part 2 will discuss Mikrotik setup and Ubuntu. First, you must install
1.Putty: For Ubuntu remotely with SSH
2. WinSCP: If you want to edit the scripts and the remote control
3. Winbox: remote Mikrotik.
When the 3-install the software, these remote follow the instructions as follows:
Mikrotik your remote control and configuration of:
IP Firewall Mangle:
0,,, a proxy-HIT
PREROUTING chain = action = mark-packet new package passthrough mark = proxy = no hit DSCP = 12
1,,, http-conn
PREROUTING chain action = mark-connection new connection = passthrough = no http_conn registered TCP = src-address = 192.168.1.0/24 interface = ether2 in
2 = action = mark-Chain PREROUTING-package brand new package http_conn = = no pass-through connection-mark = http_conn
3,,, https-conn
PREROUTING chain = action = mark-connection new-connection-mark = https passthrough = yes conn = new connection status
protocol = tcp dst-port = 443
4-PREROUTING chain = action = mark-routing new-routing-mark = https passthrough = no connection-mark = https conn
5,,, DNS
Action = PREROUTING chain outside the brand new connection connection = DNS passthrough = yes protocol = udp dst-port = 53
6 = action = PREROUTING chain brand-new connection connection = mark DNS passthrough = yes protocol = UDP dst-port = 53
7 = PREROUTING chain the new action = change DSCP DSCP = 12 = registered DNS connection
8,,, DNS packets
PREROUTING chain = action = mark-packet new package brand DNS_PACKET = passthrough = no connection-mark = DNS
9 PREROUTING chain = action = mark-packet new-packet-mark = DNS_PACKET passthrough = yes
10,,, YM-Conn
chain = forward action = mark-connection marks a new connection = ym passthrough = no protocol = tcp dst-port = 5050,5100,5051
11 chain = PREROUTING action = mark-connection new connection = ym passthrough = yes connection trademark brand = YM
12;;; Winbox
chain = input action = mark-connection new connection marks winbox passthrough = no protocol = TCP = dst-port = 8291
13,,, MMS CHANGE
String = new action = change mss MSS = 1440 tcp-flags SYN = TCP protocol interface = ether1 gateway
tcp-MSS = 1441 to 65535
FIREWALL IP address-list:
0,,, localnet
Localnet 192.168.1.0/24 -> LAN IP to change the local IP address
1,,, PROXY
192.168.11.0/24 proxy - IP Network> Proxy
Cola Type:
0 = the name of "default" type = pfifo pfifo-limit = 50
Type name = "ethernet-default" = pfifo pfifo-limit = 50
2 name = "Wireless by default" sfq sfq disturbing type = = = 5 SFQ-Devote 1514
3 name = "synchronous failure" type = red-limit = 60 red-min-threshold = 10
red-max-limit = 50 red-burst = 20 red-avg-packet = 1000
4 name = "hotspot-default" sfq-perturb type = SFQ SFQ-= 5 = 1514 Allot
5 name = "downstream-DMP" type = PCQ PCQ PCQ = 0 the speed limit = 50
PCQ PCQ-classifier = address DST-total-limit = 20000
6 name = "top-DMP" type = PCQ PCQ PCQ = 0 the speed limit = 50
PCQ-classifier = src-address PCQ total-limit = 20000
7 name = "PING" type = pfifo pfifo-limit = 64
8 Name = "game_up" type = PCQ PCQ PCQ = 0 rate-limit = 20
PCQ-classifier = dst address, dst-port PCQ-total-limit = 500
9 Name = "game_dw" type = PCQ PCQ PCQ = 0 rate-limit = 20
Tail Shaft:
0 = name of the parents' Turbo-proxy "= global-out packet-mark = proxy-hit-limit = 0
Down team PCQ queue = priority = 5 max-limit = 0 burst = 0 limit
burst-threshold = 0 burst-time = 0s
Parent name = "DNS-Up" = global-in-package label = DNS_PACKET limit-at = 0
queue = PCQ upstream priority = 5 max-limit = 0 burst = 0 limit
burst-threshold = 0 burst-time = 0s
A simple string:
0 name = "TRAFFICT shapping" DST-address = 0.0.0.0 / 0 interface = all parent = none
packet = packet-mark = intl feel both priority = 1
upstream-pcq/downsteam-pcq queue = limit = 0 / 0 max-limit = 0 / 0
Burst Limit-threshold = 0 / 0 burst = 0 / 0 burst-time = 5s/5s
-Total default file = Ethernet-time = 0s-1d, Sunday, Monday, Tuesday, Wednesday, Thursday, Friday, Saturday
Name = "BW-management address' target = local dst Your IP-address = 0.0.0.0 / 0
interface = all parent = packet = DNS_PACKET SHAPPING TRAFFICT direction = Both
= 1 priority = queue-limit to upstream-pcq/downsteam-pcq = 0 / 0
5M/5M max-limit = burst-limit = burst threshold = 5M/5M 5M/5M
burst-time = total queue = default 5s/5s
NOTE: When you set the parameters for allocating bandwidth per client / per client IP address with the parent, BW management
Your IP FIREWALL NAT
0;;; HIT PROXY
string = action = dst dstnat-NAT for addresses = 192.168.11.11 to-ports = 3128 protocol = tcp src = address! 192.168.11.11
src-address-list = localnet DST-address-list =! ProxyNet dst-port = 80,8080,3128
Connection conn = http brand
1,,, Posted by webbox
string = action = srcnat masquerade out-interface = ether1 gateway
2,,, Out Proxy (Can you also turn off)
srcnat chain = action = src-NAT IP address = Internet / IP for example, PUBLIC 125 124 123 122
src = local IP address of your ex 192.168.1.254 (IP NO NETWORK)
4 = string dstnat action = DST-NAT two-port = 53 protocol = UDP dst-port = 53
5,,, SSH
dstnat chain = action = addresses = 192.168.11.11 DST NAT-to-ports = 22
protocol = tcp = IP internet address DST / PUBLIC IP dst-port = 22.10000
Introduction by Mikrotik is over, but the client can not surf, the next step is the distance ubuntu with putty and WinSCP:
OK, in the first part, you Suda modules update. The author discusses not come back because you've managed mengisntallasi considered. In addition, remote Ubuntu with putty, putty open, enter the IP address of the host name / IP address 192.168.11.11 (Ubuntu IP) or public, you can log in as root and enter the password, then compiles the Ubuntu kernel. Copy the following script block srcript smua, then right-click on the console of Ubuntu, it will be executed automatically.
You can take it from here -> to turn the core
you open it and copy and paste it by right-clicking on the Ubuntu and press Enter, wait a moment in the process of preparation is complete.,
The next step
# Make
# Make install Sudo
Then on the remote Ubuntu with WinSCP, the / etc / squid
You must first download the settings for squid in the download menu this blog or click the download button to learn to read and the location of files and squid.conf konfiugrasi
Edit squid.conf
First stop squid
# Sudo / etc / init.d / squid stop
copy the configuration file you downloaded from the menu downlod this blog, he puts in his library. Do not mistake the site:
drag files from squid / etc / init.d /
drag and drop files sysctl.conf in / etc /
drag and drop files squid.conf, and storeurl.pl squid.conf.pl in / etc / squid
Next:
# Sudo chmod + x / etc / init.d / squid
# Give the folder permissions of the cache
chown proxy: proxy / cache
chmod 777 / cache
chown proxy: proxy / etc / squid / storeurl.pl
chmod 777 / etc / squid / storeurl.pl
• Creating folders # swap / cache in the cache folder specified dg command:
squid-f / etc / squid / squid.conf-z
• Start the squid.
/ Etc / init.d / squid restart
then try browsing customer.
control the right way: # tail-f / var / log / squid / access.log entry
If customers see aksess Ubuntu means that the proxy is already well underway.
1.Putty: For Ubuntu remotely with SSH
2. WinSCP: If you want to edit the scripts and the remote control
3. Winbox: remote Mikrotik.
When the 3-install the software, these remote follow the instructions as follows:
Mikrotik your remote control and configuration of:
IP Firewall Mangle:
0,,, a proxy-HIT
PREROUTING chain = action = mark-packet new package passthrough mark = proxy = no hit DSCP = 12
1,,, http-conn
PREROUTING chain action = mark-connection new connection = passthrough = no http_conn registered TCP = src-address = 192.168.1.0/24 interface = ether2 in
2 = action = mark-Chain PREROUTING-package brand new package http_conn = = no pass-through connection-mark = http_conn
3,,, https-conn
PREROUTING chain = action = mark-connection new-connection-mark = https passthrough = yes conn = new connection status
protocol = tcp dst-port = 443
4-PREROUTING chain = action = mark-routing new-routing-mark = https passthrough = no connection-mark = https conn
5,,, DNS
Action = PREROUTING chain outside the brand new connection connection = DNS passthrough = yes protocol = udp dst-port = 53
6 = action = PREROUTING chain brand-new connection connection = mark DNS passthrough = yes protocol = UDP dst-port = 53
7 = PREROUTING chain the new action = change DSCP DSCP = 12 = registered DNS connection
8,,, DNS packets
PREROUTING chain = action = mark-packet new package brand DNS_PACKET = passthrough = no connection-mark = DNS
9 PREROUTING chain = action = mark-packet new-packet-mark = DNS_PACKET passthrough = yes
10,,, YM-Conn
chain = forward action = mark-connection marks a new connection = ym passthrough = no protocol = tcp dst-port = 5050,5100,5051
11 chain = PREROUTING action = mark-connection new connection = ym passthrough = yes connection trademark brand = YM
12;;; Winbox
chain = input action = mark-connection new connection marks winbox passthrough = no protocol = TCP = dst-port = 8291
13,,, MMS CHANGE
String = new action = change mss MSS = 1440 tcp-flags SYN = TCP protocol interface = ether1 gateway
tcp-MSS = 1441 to 65535
FIREWALL IP address-list:
0,,, localnet
Localnet 192.168.1.0/24 -> LAN IP to change the local IP address
1,,, PROXY
192.168.11.0/24 proxy - IP Network> Proxy
Cola Type:
0 = the name of "default" type = pfifo pfifo-limit = 50
Type name = "ethernet-default" = pfifo pfifo-limit = 50
2 name = "Wireless by default" sfq sfq disturbing type = = = 5 SFQ-Devote 1514
3 name = "synchronous failure" type = red-limit = 60 red-min-threshold = 10
red-max-limit = 50 red-burst = 20 red-avg-packet = 1000
4 name = "hotspot-default" sfq-perturb type = SFQ SFQ-= 5 = 1514 Allot
5 name = "downstream-DMP" type = PCQ PCQ PCQ = 0 the speed limit = 50
PCQ PCQ-classifier = address DST-total-limit = 20000
6 name = "top-DMP" type = PCQ PCQ PCQ = 0 the speed limit = 50
PCQ-classifier = src-address PCQ total-limit = 20000
7 name = "PING" type = pfifo pfifo-limit = 64
8 Name = "game_up" type = PCQ PCQ PCQ = 0 rate-limit = 20
PCQ-classifier = dst address, dst-port PCQ-total-limit = 500
9 Name = "game_dw" type = PCQ PCQ PCQ = 0 rate-limit = 20
Tail Shaft:
0 = name of the parents' Turbo-proxy "= global-out packet-mark = proxy-hit-limit = 0
Down team PCQ queue = priority = 5 max-limit = 0 burst = 0 limit
burst-threshold = 0 burst-time = 0s
Parent name = "DNS-Up" = global-in-package label = DNS_PACKET limit-at = 0
queue = PCQ upstream priority = 5 max-limit = 0 burst = 0 limit
burst-threshold = 0 burst-time = 0s
A simple string:
0 name = "TRAFFICT shapping" DST-address = 0.0.0.0 / 0 interface = all parent = none
packet = packet-mark = intl feel both priority = 1
upstream-pcq/downsteam-pcq queue = limit = 0 / 0 max-limit = 0 / 0
Burst Limit-threshold = 0 / 0 burst = 0 / 0 burst-time = 5s/5s
-Total default file = Ethernet-time = 0s-1d, Sunday, Monday, Tuesday, Wednesday, Thursday, Friday, Saturday
Name = "BW-management address' target = local dst Your IP-address = 0.0.0.0 / 0
interface = all parent = packet = DNS_PACKET SHAPPING TRAFFICT direction = Both
= 1 priority = queue-limit to upstream-pcq/downsteam-pcq = 0 / 0
5M/5M max-limit = burst-limit = burst threshold = 5M/5M 5M/5M
burst-time = total queue = default 5s/5s
NOTE: When you set the parameters for allocating bandwidth per client / per client IP address with the parent, BW management
Your IP FIREWALL NAT
0;;; HIT PROXY
string = action = dst dstnat-NAT for addresses = 192.168.11.11 to-ports = 3128 protocol = tcp src = address! 192.168.11.11
src-address-list = localnet DST-address-list =! ProxyNet dst-port = 80,8080,3128
Connection conn = http brand
1,,, Posted by webbox
string = action = srcnat masquerade out-interface = ether1 gateway
2,,, Out Proxy (Can you also turn off)
srcnat chain = action = src-NAT IP address = Internet / IP for example, PUBLIC 125 124 123 122
src = local IP address of your ex 192.168.1.254 (IP NO NETWORK)
4 = string dstnat action = DST-NAT two-port = 53 protocol = UDP dst-port = 53
5,,, SSH
dstnat chain = action = addresses = 192.168.11.11 DST NAT-to-ports = 22
protocol = tcp = IP internet address DST / PUBLIC IP dst-port = 22.10000
Introduction by Mikrotik is over, but the client can not surf, the next step is the distance ubuntu with putty and WinSCP:
OK, in the first part, you Suda modules update. The author discusses not come back because you've managed mengisntallasi considered. In addition, remote Ubuntu with putty, putty open, enter the IP address of the host name / IP address 192.168.11.11 (Ubuntu IP) or public, you can log in as root and enter the password, then compiles the Ubuntu kernel. Copy the following script block srcript smua, then right-click on the console of Ubuntu, it will be executed automatically.
You can take it from here -> to turn the core
you open it and copy and paste it by right-clicking on the Ubuntu and press Enter, wait a moment in the process of preparation is complete.,
The next step
# Make
# Make install Sudo
Then on the remote Ubuntu with WinSCP, the / etc / squid
You must first download the settings for squid in the download menu this blog or click the download button to learn to read and the location of files and squid.conf konfiugrasi
Edit squid.conf
First stop squid
# Sudo / etc / init.d / squid stop
copy the configuration file you downloaded from the menu downlod this blog, he puts in his library. Do not mistake the site:
drag files from squid / etc / init.d /
drag and drop files sysctl.conf in / etc /
drag and drop files squid.conf, and storeurl.pl squid.conf.pl in / etc / squid
Next:
# Sudo chmod + x / etc / init.d / squid
# Give the folder permissions of the cache
chown proxy: proxy / cache
chmod 777 / cache
chown proxy: proxy / etc / squid / storeurl.pl
chmod 777 / etc / squid / storeurl.pl
• Creating folders # swap / cache in the cache folder specified dg command:
squid-f / etc / squid / squid.conf-z
• Start the squid.
/ Etc / init.d / squid restart
then try browsing customer.
control the right way: # tail-f / var / log / squid / access.log entry
If customers see aksess Ubuntu means that the proxy is already well underway.
Subscribe to:
Posts (Atom)


