ess allow A B
¸Ã¹æÔòÓÀ²»ÕýÈ·£¬ÒòΪij¸öÔ´IP µØÖ·²»¿ÉÄÜͬʱµÈͬÓÚ1.2.3.4 ºÍ5.6.7.8¡£ÕâÌõ¹æÔòµÄÕæÕýÒâͼÊÇ£º
acl A src 1.2.3.4 5.6.7.8
http_access allow A
¶Ôij¸öACL ÖµµÄÆ¥ÅäËã·¨ÊÇ£¬squid ÔÚ·ÃÎÊÁбíÀïÕÒµ½Æ¥Å乿Ôòʱ£¬ËÑË÷ÖÕÖ¹¡£¼ÙÈçûÓзÃÎʹæÔòµ¼ÖÂÆ¥Å䣬ĬÈ϶¯×÷ÊÇÁбíÀï×îºóÒ»Ìõ¹æÔòµÄÈ¡·´¡£ÀýÈ磬¿¼ÂÇÈçϼòµ¥·ÃÎÊÅäÖãº
acl Bob ident bob
http_access allow Bob
¼ÙÈçÓû§Mary ·¢ÆðÇëÇó£¬Ëý»á±»¾Ü¾ø¡£ÁбíÀï×îºóµÄ£¨Î¨Ò»µÄ£©¹æÔòÊÇallow ¹æÔò£¬Ëü²»Æ¥ÅäÓû§Ãûmary¡£ÕâÑù£¬Ä¬Èϵ͝×÷ÊÇallow µÄÈ¡·´£¬¹ÊÇëÇ󱻾ܾø¡£ÀàËÆµÄ£¬¼ÙÈç×îºóµÄ¹æÔòÊÇdeny ¹æÔò£¬Ä¬È϶¯×÷ÊÇÔÊÐíÇëÇó¡£ÔÚ·ÃÎÊÁбíµÄ×îºó¼ÓÉÏÒ»Ìõ£¬Ã÷È·ÔÊÐí»ò¾Ü¾øËùÓÐÇëÇó£¬ÊǺõÄʵ¼Ê×ö·¨¡£ÎªÇå³þÆð¼û£¬ÒÔǰµÄʾÀýÓ¦¸ÃÈç´Ëд£º
acl All src 0/0
acl Bob ident bob
http_access allow Bob
http_access deny All
src 0/0 ACL ±íʾƥÅäÿһ¸öºÍÈÎÒâÀàÐ͵ÄÇëÇó¡£
6.2.3 ·ÃÎÊÁбí·ç¸ñ
squid µÄ·ÃÎÊ¿ØÖÆÓï·¨·Ç³£Ç¿´ó¡£´ó¶àÊýÇé¿öÏ£¬Äã¿ÉÒÔʹÓÃÁ½ÖÖ»ò¶àÖÖ·½·¨À´Íê³ÉͬÑùµÄÊ¡£Í¨³££¬Äã¸Ã½«¸ü¾ßÌåµÄºÍÊÜÏÞÖÆµÄ·ÃÎÊÁбí·ÅÔÚÊ×λ¡£ÀýÈ磬ÈçÏÂÓï¾ä²¢·ÇºÜºÃ£º
acl All src 0/0
acl Net1 src 1.2.3.0/24
acl Net2 src 1.2.4.0/24
acl Net3 src 1.2.5.0/24
acl Net4 src 1.2.6.0/24
acl WorkingHours time 08:00-17:00
http_access allow Net1 WorkingHours
http_access allow Net2 WorkingHours
http_access allow Net3 WorkingHours
http_access allow Net4
http_access deny All
¼ÙÈçÄãÕâÑùд£¬·ÃÎÊ¿ØÖÆÁбí»á¸üÈÝÒ×ά»¤ºÍÀí½â£º
http_access allow Net4
http_access deny !WorkingHours
http_access allow Net1
http_access allow Net2
http_access allow Net3
http_access deny All
ÎÞÂÛºÎʱ£¬Äã±àдÁËÒ»¸ö´øÁ½¸ö»ò¸ü¶àACL ÔªËØµÄ¹æÔò£¬½¨ÒéÄãÔÚÆäºó½ô¸úÒ»ÌõÏà·´µÄ£¬¸ü¹ã·ºµÄ¹æÔò¡£ÀýÈ磬ĬÈϵÄsquid ÅäÖþܾø·ÇÀ´×Ô±¾»úIP µØÖ·µÄcache ¹ÜÀíÇëÇó£¬ÄãÒ²ÐíÊÔͼÕâÑùд£º
acl CacheManager proto cache_object
acl Localhost src 127.0.0.1
http_access deny CacheManager !Localhost
È»¶ø£¬ÕâÀïµÄÎÊÌâÊÇ£¬ÄãûÓÐÔÊÐíȷʵÀ´×Ô±¾»úµÄcache ¹ÜÀíÇëÇó¡£ËæºóµÄ¹æÔò¿ÉÄܵ¼ÖÂÇëÇ󱻾ܾø¡£ÈçϹæÔò¾Í²úÉúÁËÎÊÌ⣺
acl CacheManager proto cache_object
acl Localhost src 127.0.0.1
acl MyNet 10.0.0.0/24
acl All src 0/0
http_access deny CacheManager !Localhost
http_access allow MyNet
http_access deny All
¼ÈÈ»À´×Ô±¾»úµÄÇëÇ󲻯¥ÅäMyNet£¬Ëü±»¾Ü¾ø¡£±àд±¾¹æÔòµÄ¸üºÃ·½·¨ÊÇ£º
http_access allow CacheManager localhost
http_access deny CacheManager
http_access allow MyNet
http_access deny All
6.2.4 ÑÓʱ¼ì²é
ijЩACL ²»ÄÜÔÚÒ»¸ö¹ý³ÌÀï±»¼ì²é£¬ÒòΪ±ØÒªµÄÐÅÏ¢²»¿ÉÓá£ident,dst,srcdomain ºÍproxy_auth ÀàÐÍÊôÓڸ÷¶³ë¡£µ±squid Óöµ½Ä³¸öACL ²»Äܱ»¼ì²éʱ£¬ËüÑÓ³Ù¾ö¶¨²¢ÇÒ·¢²¼¶Ô±ØÒªÐÅÏ¢µÄ²éѯ£¨IP µØÖ·£¬ÓòÃû£¬Óû§ÃûµÈ£©¡£µ±ÐÅÏ¢¿ÉÓÃʱ£¬squid ÔÙ´ÎÔÚÁбíµÄ¿ªÍ·Î»Öüì²éÕâЩ¹æÔò¡£Ëü²»»á´Óǰ´Î¼ì²éʣϵÄλÖüÌÐø¡£¼ÙÈç¿ÉÄÜ£¬ÄãÓ¦¸Ã½«ÕâЩ×î¿ÉÄܱ»ÑÓʱµÄACL ·ÅÔÚ¹æÔòµÄ¶¥²¿£¬ÒÔ±ÜÃâ²»±ØÒªµÄ£¬Öظ´µÄ¼ì²é¡£
ÒòΪÑÓʱµÄ´ú¼ÛÌ«´ó£¬squid »á¾¡¿ÉÄÜ»º´æ²éѯ»ñÈ¡µÄÐÅÏ¢¡£ident ²éѯÔÚÿ¸öÁ¬½ÓÀï·¢Éú£¬¶ø²»ÊÇÔÚÿ¸öÇëÇóÀï¡£ÕâÒâζ×Å£¬µ±ÄãʹÓÃident ²éѯʱ£¬³ÖÐøHTTP Á¬½ÓÇÐʵ¶ÔÄãÓÐÀû¡£DNS ÏìÓ¦µÄÖ÷»úÃûºÍIP µØÖ·Ò²±»»º´æ£¬³ý·ÇÄãʹÓÃÔçÆÚµÄÍⲿdnsserver ½ø³Ì¡£´úÀíÑé
Ö¤ÐÅÏ¢±»»º´æ£¬Çë¼û6.1.2.12 Õ½ڵÄÃèÊö¡£
6.2.5 ¼õ»ººÍ¼ÓËÙ¹æÔò¼ì²é
Squid ÄÚ²¿¿¼ÂÇijЩ·ÃÎʹæÔò±»¿ìËÙ¼ì²é£¬ÆäËûµÄ±»¼õ»º¼ì²é¡£Çø±ðÊÇsquid ÊÇ·ñÑÓ³ÙËüµÄ¾ö¶¨£¬ÒԵȴý¸½¼ÓÐÅÏ¢¡£»»¾ä»°Ëµ£¬ÔÚsquid ²éѯ¸½¼ÓÐÅϢʱ£¬Ä³¸ö¼õ»º¼ì²é»á±»ÑÓʱ£¬ÀýÈ磺
+ ·´ÏòDNS ²éѯ£º¿Í»§IP µØÖ·µÄÖ÷»úÃû
+ RFC 1413 ident ²éѯ£º¿Í»§TCP Á¬½ÓµÄÓû§Ãû
+ ÑéÖ¤Æ÷£ºÑéÖ¤Óû§ÐÅÓÃ
+ DNS ת·¢²éѯ£ºÔʼ·þÎñÆ÷µÄIP µØÖ·
+ Óû§¶¨ÒåµÄÍⲿACL