[Udnet] Resumen de reporte de cambios propuestos para servicio de proxy

Andrés Abelardo Villarroel Acosta aavillarroela en udistrital.edu.co
Vie Ene 18 10:54:36 COT 2013


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Adjunto encontrarï¿¡n el reporte de los cambios propuestos para el
servicio de proxy. Por favor revisar el archivo adjunto
`reporte_cabios.txt' donde encontrarï¿¡n las diferencias entre la
configuraci￳n anterior y la nueva, mis comentarios est£n indicados
dentro del archivo con el prefijo "->" donde explico el porquï¿© de cada
cambio.

Esta nueva configuraci￳n est£ en este momento en entorno de pruebas
con la siguiente direcci￳n:

host  proxy: hp2.udistrital.edu.co
puert proxy: 3128

Por favor, validar y aprobar paso a producci￳n. Gracias.

Cordialmente.

- --av.-

- -- 
Andrï¿©s Abelardo Villarroel Acosta
Contratista Universidad Distrital Francisco Josï¿© de Caldas
ï¿rea de plataformas - Red UDNET
aavillarroela en udistrital.edu.co
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQEcBAEBAgAGBQJQ+XA1AAoJEMx52kKp9SgJpRAH/2nZ23Psvy9p/A+l1dk2n7Dc
OjvjCLn7+YEUCU4txTwWVg/+Uz3G2ZGLPMXkNbWl0KbwcKDwZWgkr2eTaIjOQJrd
FeGOPtm4BrrGyMGWEEl/Ys/N0DI/0o2DUjmFVtsD2M/Z//O/35s09ooAr3zH4LZJ
zwMHCu7UYyxT8Uoxud0uq601sxlXCN9jBsktITN4NcALDg3OgCemjPBmGxACHEuq
RE1xCU0+7+jfVx4EM5q1/kFEPFs6tXDx9tbEkUIUTxUnypbVyS+XHvzo716pf3Fn
XJFzbZHxuRxiLAQtlQ8wts4VraI8etEYFZAHIX6a7GwCIsnX8nOuJO+uPOdEzfc=
=l/DV
-----END PGP SIGNATURE-----
------------ próxima parte ------------

Index: squid.conf
===================================================================
--- squid.conf	(revision 517)
+++ squid.conf	(working copy)
@@ -51,6 +51,8 @@
 #Default:
 # http_port 3128
 
+http_port 3128
+
 #  TAG: https_port
 #        Usage:  [ip:]port cert=certificate.pem [key=key.pem] [options...]
 #
@@ -417,7 +419,7 @@
 #	to not query neighbor caches for certain objects.  You may
 #	list this option multiple times.
 #We recommend you to use at least the following line.
-hierarchy_stoplist cgi-bin ?
+#hierarchy_stoplist cgi-bin ?

-> Opcion no necesaria reemplazada por refresh_patterns
 
 #  TAG: no_cache
 #	A list of ACL elements which, if matched, cause the request to
@@ -428,7 +430,6 @@
 #	NOT be cached.
 #
 #We recommend you to use the following two lines.
-acl QUERY urlpath_regex cgi-bin \?
 
-> Opcion no necesaria reemplazada por refresh_patterns
 
 # OPTIONS WHICH AFFECT THE CACHE SIZE
@@ -466,8 +467,9 @@
 #	objects.
 #
 #Default:
-cache_mem 8 GB
 
+cache_mem 16 GB

-> Duplicación de la memoria del cache en base al monitoreo realizado (ver adjunto report1.png)

+
 #  TAG: cache_swap_low	(percent, 0-100)
 #  TAG: cache_swap_high	(percent, 0-100)
 #
@@ -520,7 +522,7 @@
 #Default:
 # maximum_object_size_in_memory 8 KB
 
-maximum_object_size_in_memory 41 KB
+maximum_object_size_in_memory 4096 KB

-> Aumentar en dos ordenes de magnitud el tamaño máximo de los objetos en cache de RAM.
 
 #  TAG: ipcache_size	(number of entries)
 #  TAG: ipcache_low	(percent)
@@ -668,9 +670,9 @@
 #	ones with no max-size specification last.
 #
 #Default:
-cache_dir ufs /var/spool/squid 24576 16 256 
-#cache deny all
 
+cache_dir aufs /var/spool/squid 51200 16 256 
+

-> Paso de ufs a aufs que es de escritura y lectura asincrona lo cuál diminuye le número de bloqueos en el sistema de archivos según documentacion de squid.

-> "aufs" uses the same storage format as "ufs", utilizing
-> POSIX-threads to avoid blocking the main Squid process on
-> disk-I/O. This was formerly known in Squid as async-io.

 #  TAG: cache_access_log
 #	Logs the client request activity.  Contains an entry for
 #	every HTTP and ICP queries received. To disable, enter "none".
@@ -678,6 +680,9 @@
 #Default:
 # cache_access_log /var/log/squid/access.log
 
+access_log /var/log/squid/access.log squid
+
+
 #  TAG: cache_log
 #	Cache logging file. This is where general information about
 #	your cache's behavior goes. You can increase the amount of data
@@ -696,6 +701,8 @@
 #Default:
 # cache_store_log /var/log/squid/store.log
 
+cache_store_log none
+

-> En la documentacion dice que no hay ninguna herramienta creada para analizar el log de almacenamiento se desactiva para disminuir accesos a disco

 #  TAG: cache_swap_log
 #	Location for the cache "swap.log."  This log file holds the
 #	metadata of objects saved on disk.  It is used to rebuild the
@@ -837,6 +844,7 @@
 #	(for example perl.com).
 #
 #Default:
+
 ftp_user proxy en udistrital.edu.co
 
 #  TAG: ftp_list_width
@@ -852,6 +860,7 @@
 #	connections, then turn off this option.
 #
 #Default:
+
 ftp_passive on
 
 #  TAG: ftp_sanitycheck
@@ -901,8 +910,9 @@
 #	is assumed to be unavailable.
 #
 #Default:
-dns_timeout 10 seconds
 
+dns_timeout 5 seconds
+

-> Las peticiones a DNS han reducido su tiempo de espera desde el cambio en la zona raíz "."

 #  TAG: dns_defnames	on|off
 # Note: This option is only available if Squid is rebuilt with the
 #       --disable-internal-dns option
@@ -1178,6 +1188,7 @@
 #auth_param ntlm max_challenge_reuses 0
 #auth_param ntlm max_challenge_lifetime 2 minutes
 #auth_param basic program <uncomment and complete this line>
+
 auth_param basic children 5
 auth_param basic realm Squid proxy-caching web server
 auth_param basic credentialsttl 2 hours
@@ -1361,10 +1372,12 @@
 #	used.
 #
 #Suggested default:
-refresh_pattern ^ftp:		1440	20%	10080
-refresh_pattern ^gopher:	1440	0%	1440
-refresh_pattern .		0	20%	4320
 
+refresh_pattern  ^ftp:     1440  20%  10080
+refresh_pattern  cgi-bin   0     0%   0 
+refresh_pattern  \?        0     0%   0 
+refresh_pattern  .         0     20%  4320
+
 #  TAG: quick_abort_min	(KB)
 #  TAG: quick_abort_max	(KB)
 #  TAG: quick_abort_pct	(percent)
@@ -1455,8 +1468,10 @@
 #	default is two minutes (120 seconds).
 #
 #Default:
-connect_timeout 2 minute
+# connect_timeout 2 minute
 
+connect_timeout 10 seconds
+

-> Disminuir el timeout de conexión de 2 minutos a 10 segundos termina antes conexiones de clientes que están ociosas ocupando espacio en la memoria de squid.

 #  TAG: peer_connect_timeout	time-units
 #	This parameter specifies how long to wait for a pending TCP
 #	connection to a peer cache.  The default is 30 seconds.   You
@@ -1464,8 +1479,10 @@
 #	with the 'connect-timeout' option on a 'cache_peer' line.
 #
 #Default:
-peer_connect_timeout 30 seconds
+# peer_connect_timeout 30 seconds
 
+peer_connect_timeout 10 seconds
+

-> Disminutcion del timeout de conexión con los peers (en cualquier caso no hay peers en esta configuracion de squid)

 #  TAG: read_timeout	time-units
 #	The read_timeout is applied on server-side connections.  After
 #	each successful read(), the timeout will be extended by this
@@ -1483,6 +1500,8 @@
 #Default:
 # request_timeout 5 minutes
 
+request_timeout 1 minute
+
 #  TAG: persistent_request_timeout
 #	How long to wait for the next HTTP request on a persistent
 #	connection after the previous request completes.
@@ -1636,7 +1655,6 @@
 #	  # A community string to limit access to your SNMP Agent
 #	  # Example:
 #	  #
-acl snmppublic snmp_community public

-> Se desactiva la comunidad snmp de squid para reducir el uso de recursos (se esta monitoreando por el object_cache con zabbix)

 #
 #	acl aclname maxconn number
 #	  # This will be matched when the client's IP address has
@@ -1679,116 +1697,50 @@
 #acl password proxy_auth REQUIRED
 #acl fileupload req_mime_type -i ^multipart/form-data$
 #acl javascript rep_mime_type -i ^application/x-javascript$
-#
-#Recommended minimum configuration:


-> Comienzan cambios en ACL's de usabilidad y de desempeño, según lo que se sugirió antes:

-> 
->     01  http_access allow manager localhost              - manager: proto cache_object
->                                                            localhost: src 127.0.0.1/32
->     02  http_access allow udistrital - udistrital: dstdomain .udistrital.edu.co
->     03  http_access allow udnet_permitidos               - udnet_permitidos: src 75 ip 4 rango de ip
->     04  http_access deny udnet Maximas_Conexiones        - udnet: src 10.20.0.0/16
->                                                            Maximas_Conexiones: maxconn 150
->     05  http_access allow permitidos                     - permitidos: url_regex -i "permitidos.acl" (234)
->     06  http_access allow emisora                        - emisora : src 1 ip 2 rango de ip
->     07  http_access allow CONNECT messengers msn         - CONNECT: method CONNECT
->         msnmsgr msn_messenger SkypeHabilitados             messengers: url_regex -i "messengers.acl" (73)
->                                                            msn: browser Messenger
->                                                            msnmsgr: rep_mime_type application/x-msn-messenger
->                                                            msn_messenger: url_regex -i gateway.dll
->                                                            SkypeHabilitados: src 28 ip
->     08  http_access deny messengers                      - ^
->     09  http_access deny msnmsgr !SkypeHabilitados       - ^
->     10  http_access deny msn_messenger !SkypeHabilitados - ^
->     11  http_access deny udnet_denegados                 - udnet_denegados: src 2 ip
->     12  http_access deny !Safe_ports                     - Safe_ports: port 8 tcpport 2 rango tcpport
->     13  http_access deny gtalk                           - gtalk: browser Google Talk (2 regex)
->     14  http_access deny CONNECT skype !SkypeHabilitados - ^
->                                                            skype: url_regex -i ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]
->                                                            ^
->     15  http_access deny msn                             - ^
->     16  http_access allow desbloqueados_por_solicitud    - desbloqueados_por_solicitud: url_regex -i
->                                                            "desbloqueados_por_solicitud.acl" (28)
->     17  http_access allow bibliotecas                    - bibliotecas: url_regex -i (32)
->     18  http_access deny manager                         - ^
->     19  http_access deny porno                           - porno: url_regex -i "porno.acl" (233)
->     20  http_access deny extensiones_prohibidas          - extensiones_prohibidas: urlpath_regex -i (12)
->     21  http_access allow restringidos restringidos_auth - restringidos: url_regex -i (2)
->                                                          - restringidos_auth: src 1 ip
->     22  http_access deny restringidos                    - ^
->     23  http_access deny prohibidos                      - prohibidos: url_regex -i "prohibidos.acl"
->     24  http_access allow udnet                          - ^
->     25  http_access allow localhost                      - ^
->     26  http_access deny all                             - all: src: 0.0.0.0/0
->  
-> De la documentación de squid:
->  
-> rep_mime_type: regular expression pattern matching on the reply (downloaded content) content-type header. This is only usable in the http_reply_access directive, not http_access.
->  
-> Desempeño:
->  
->  * 05: permitidos, cambiar por dstdomain donde se pueda
->  * 07: creo que esta regla no debe estar funcionando por la razón anterior
->  * 08: messengers, cambiar por dstdomain donde se pueda
->  * 09: msnmsgr, funciona solo en http_reply_access
->  * 10: msn_messenger, puede cambiarse por url_path
->  * 14: skype url_regex coincide con cualquier IP
->  * 16: desbloqueados_por_solicitud, cambiar por dstdomain donde se pueda
->  * 17: bibliotecas, cambiar por dstdomain donde se pueda
->  * 19: porno, cambiar por dstdomain donde se pueda
->  * 20: extensiones_prohibidas, cambiar . por \.
->  * 21: restringidos, cambiar por dstdomain donde se pueda
->  * 23: prohibidos, cambiar por dstdomain donde se pueda
->  
-> Usabilidad:
->  
->  * 19: Se bloquean cosas muy genéricas por ejemplo "adult" bloquea "adultos mayores".
->  
-> Seguridad:
->  
->  * 02: http_access allow udistrital, proxy está como relay abierto a toda la red aunque el firewall bloqueé, el proxy aún permite conexiones a todo el segmento de internet a cualquier puerto
->  
->  * 12, 24: Se permite connect a cualquier nombre 
->  
->  * Están las directivas:
->  
->    follow_x_forwarded_for allow udnet
->    acl_uses_indirect_client on
->  
->    Expandiendo las subredes hay 1653 direcciones IP mágicas (udnet_permitidos y emisora) de 65025 (2.5%)
->  
->  * Ext: https://addons.mozilla.org/en-us/firefox/addon/x-forwarded-for-header/
->  * Ext: http://code.google.com/p/foxreplace/
-> 

-acl all src 0.0.0.0/0.0.0.0
-acl manager proto cache_object
-acl localhost src 127.0.0.1/255.255.255.255
 
-#acl to_localhost dst 127.0.0.0/8
-
-#acl SSL_ports port 443 563
-
-acl Safe_ports port 80
-acl Safe_ports port 20 21
-acl Safe_ports port 443 563
-acl Safe_ports port 70
-acl Safe_ports port 210
-acl Safe_ports port 1025-65535
-acl Safe_ports port 280
-acl Safe_ports port 488
-acl Safe_ports port 591
-acl Safe_ports port 777
-acl CONNECT method CONNECT
-
-## ACL Personalizados
-
-acl udnet src 10.20.0.0/255.255.0.0
-acl udistrital dstdomain .udistrital.edu.co
-acl porno url_regex -i "/etc/squid/porno.acl"
-acl prohibidos url_regex -i "/etc/squid/prohibidos.acl"
-
-# acl permitidos url_regex -i "/etc/squid/permitidos.acl"
-
+acl to_localnet dst 127.0.0.0/8 200.69.103.2 192.168.1.2
+acl cualquier_ip dstdom_regex ^([0-9]{1,3}\.){3}[0-9]$
+acl adult_domains dstdomain "/etc/squid/adult.domains.acl"
+acl chat_domains dstdomain "/etc/squid/chat.domains.acl"
+acl malware_domains dstdomain "/etc/squid/malware.domains.acl"
+acl phishing_domains dstdomain "/etc/squid/phishing.domains.acl"
+acl publicite_domains dstdomain "/etc/squid/publicite.domains.acl"
+acl redirector_domains dstdomain "/etc/squid/redirector.domains.acl"
+acl marketingware_domains dstdomain "/etc/squid/marketingware.domains.acl"
+acl permitidos_dstdom_regex dstdomain "/etc/squid/permitidos_dstdom_regex.acl"
 acl permitidos_dstdomain_ip dstdomain "/etc/squid/permitidos_dstdomain_ip.acl"
 acl permitidos_dstdomain_name dstdomain "/etc/squid/permitidos_dstdomain_name.acl"
-acl permitidos_dstdom_regex dstdomain "/etc/squid/permitidos_dstdom_regex.acl"
-
 acl virus dstdomain "/etc/squid/virus.acl"
+acl apps.facebook.com dstdomain .apps.facebook.com
+acl udistrital dstdomain .udistrital.edu.co
+acl maximas_conexiones maxconn 150
+acl connect method CONNECT
+acl safe_ports port 1025-65535
+acl safe_ports port 20 21
+acl safe_ports port 210
+acl safe_ports port 280
+acl safe_ports port 443 563
+acl safe_ports port 488
+acl safe_ports port 591
+acl safe_ports port 70
+acl safe_ports port 777
+acl safe_ports port 80
+acl manager proto cache_object
+acl clientes_chat src "/etc/squid/clientes_chat.acl"
+acl clientes_denegados src "/etc/squid/clientes_denegados.acl"
+acl clientes_permitidos src "/etc/squid/clientes_permitidos.acl"
+acl all src 0.0.0.0/0.0.0.0
+acl udnet src 10.20.0.0/255.255.0.0
+acl permitir_apps.facebook.com src 10.20.100.1
+acl localhost src 127.0.0.1/255.255.255.255
+acl adult_urls url_regex "/etc/squid/adult.urls.acl"
+acl chat_urls url_regex "/etc/squid/chat.urls.acl"
+acl malware_urls url_regex "/etc/squid/malware.urls.acl"
+acl phishing_urls url_regex "/etc/squid/phishing.urls.acl"
+acl publicite_urls url_regex "/etc/squid/publicite.urls.acl"
+acl redirector_urls url_regex "/etc/squid/redirector.urls.acl"
+acl marketingware_urls url_regex "/etc/squid/marketingware.urls.acl"
 
-#acl extensiones_prohibidas urlpath_regex -i .asf$ .au$ .avi$ .divx$ .mid$ .mov$ .mp3$ .mpeg$ .mpg$ .wav$ .wma$ .wmv$
-
-acl extensiones_prohibidas urlpath_regex -i \.asf$ \.au$ \.avi$ \.divx$ \.mid$ \.mov$ \.mp3$ \.mpeg$ \.mpg$ \.wav$ \.wma$ \.wmv$
-
-acl udnet_denegados src 10.20.204.105 10.20.232.255
-acl udnet_permitidos src 10.20.0.53 10.20.100.12 10.20.100.127 10.20.100.13 10.20.100.180 10.20.100.192 10.20.100.31 10.20.100.55 10.20.111.10 10.20.111.18 10.20.121.248 10.20.161.222-10.20.161.224 10.20.180.56 10.20.200.52 10.20.204.33 10.20.205.29 10.20.205.38 10.20.205.42 10.20.205.49 10.20.208.34-10.20.208.35 10.20.208.45 10.20.210.36 10.20.230.0-10.20.230.255 10.20.231.44 10.20.232.30 10.20.233.57 10.20.24.105 10.20.24.113 10.20.24.52 10.20.25.30 10.20.30.100 10.20.32.120 10.20.32.181 10.20.32.99 10.20.33.85 10.20.40.145 10.20.40.159 10.20.40.160 10.20.40.170 10.20.40.173 10.20.40.230-10.20.40.234 10.20.40.30 10.20.40.34 10.20.40.41 10.20.40.43 10.20.40.86 10.20.40.92 10.20.44.100 10.20.44.101 10.20.44.28 10.20.44.52 10.20.44.53 10.20.44.54 10.20.44.56 10.20.44.58 10.20.44.61 10.20.44.62 10.20.44.66 10.20.44.75 10.20.44.78 10.20.44.81 10.20.44.83 10.20.44.93 10.20.44.95 10.20.44.96 10.20.44.98 10.20.48.24 10.20.48.29 10.20.48.47 10.20.52.131 10.20.52.162 10.20.52.66 10.20.72.25 10.20.76.40 10.20.8.200 10.20.8.36 10.20.8.40 10.20.82.0-10.20.82.255
-
-#acl portatil src 10.20.100.54
-
-#acl adservers url_regex -i "/etc/squid/adservers.acl"
-
-#acl tecnologica src 10.20.28.0/255.255.255.0
-
-#acl ieee src 10.20.140.25
-
-#acl asab src 10.20.52.0/255.255.255.0
-
-acl gtalk browser Google Talk
-
-#acl proxys_anonimos url_regex -i "/etc/squid/proxys_anonimos.acl"
-
-#acl mediodia time 12:00-14:00
-
-#acl messengers url_regex -i "/etc/squid/messengers.acl"
-
-acl messengers_dstdomain_ip dstdomain "/etc/squid/messengers_dstdomain_ip.acl"
-acl messengers_dstdomain_name dstdomain "/etc/squid/messengers_dstdomain_name.acl"
-acl messengers_dstdom_regex dstdom_regex "/etc/squid/messengers_dstdom_regex.acl"
-
-acl bibliotecas url_regex -i 165.193.106 165.193.107 askit.com c.ggimg.com callisto.ggimg.com callisto.ggsrv.com find.galegroup.com g.ggimg.com gale.com galegroup.com galenet.gale.com galenet.galegroup.com gbv.de ggimg.com ilrn.com infotrac-custom.com infotrac.galegroup.com litfinder.com pdfserve.galegroup.com petersons.com petersonstestprep.com psmedia.com rdsinc.com saur.de shakespeare.galegroup.com tlemea.com uia.org uslegalforms.com vantage.com webfeetguides.com webtrends.com 200.93.146.254
-acl desbloqueados_por_solicitud url_regex -i "/etc/squid/desbloqueados_por_solicitud.acl"
-acl msn browser Messenger
-
-#acl skype url_regex -i ^[0-9]+\.[0-9]+\.[0-9]+\.[0-9]
-
-acl skype dstdom_regex ^([0-9]{1,3}\.){3}[0-9]$
-
-acl emisora src 10.20.40.173 10.20.76.64/255.255.255.224 10.20.56.0/255.255.252.0
-
-#acl Asuntos_Disciplinarios src 10.20.207.25 10.20.209.24 10.20.209.27 10.20.209.28 10.20.209.30 10.20.209.35 10.20.209.39 10.20.209.40 10.20.209.43 10.20.209.45 10.20.209.50
-
-#acl msnmsgr rep_mime_type application/x-msn-messenger
-
-#acl msn_messenger url_regex -i gateway.dll
-
-acl msn_messenger urlpath_regex -i /gateway\.dll
-
-acl SkypeHabilitados src 10.20.111.31 10.20.171.114 10.20.177.36 10.20.180.36 10.20.180.42 10.20.203.81 10.20.204.36 10.20.209.34 10.20.210.250 10.20.232.191 10.20.232.33 10.20.232.70 10.20.24.66 10.20.24.92 10.20.28.156 10.20.28.216 10.20.29.105 10.20.29.119 10.20.29.156 10.20.40.173 10.20.44.107 10.20.44.24 10.20.44.50 10.20.44.69 10.20.44.74 10.20.44.78 10.20.44.79 10.20.48.24 10.20.141.26
-
-acl SkypeHabilitados src 10.20.0.31 # ticket 10927
-
-#acl restringidos url_regex -i apps.facebook.com chatenabled.mail.google.com
-
-acl restringidos dstdomain .apps.facebook.com
-
-acl restringidos_auth src 10.20.100.1
-
-acl Maximas_Conexiones maxconn 150
-
-no_cache deny QUERY
-
-##Adicionado por ARL el 23-11-2005 para arreglar problemas al ingresar a cuentas de hotmail
-
-#acl hotmail_domains dstdomain .hotmail.msn.com .passport.com .passport.net
-#header_access Accept-Encoding deny hotmail_domains
-#header_access Accept-Encoding deny all
-#anonymize_headers deny Accept-Encoding
-
-##Fin Adicion
-
-
-
-
 #  TAG: http_access
 #	Allowing or Denying access based on defined access lists
 #
@@ -1813,68 +1765,71 @@
 #Recommended minimum configuration:
 #
 # Only allow cachemgr access from localhost
-http_access allow manager localhost
-http_access allow udistrital
-#http_access deny tecnologica !udistrital
 
-http_access deny virus
+# infos
 
-# Deny requests to unknown ports
-http_access allow udnet_permitidos
-http_access deny udnet Maximas_Conexiones
-# Deny CONNECT to other than SSL ports
 
+http_access deny  clientes_denegados
+http_access deny  maximas_conexiones
+http_access allow manager localhost
+http_access deny  manager
+http_access deny  to_localnet
+http_access deny  virus
+http_access allow udistrital
+http_access allow clientes_permitidos
 http_access allow permitidos_dstdomain_ip
 http_access allow permitidos_dstdomain_name
 http_access allow permitidos_dstdom_regex
-
-# http_access allow permitidos
-
-#
-# We strongly recommend to uncomment the following to protect innocent
-# web applications running on the proxy server who think that the only
-# one who can access services on "localhost" is a local user
-#http_access deny to_localhost
-#
-# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
-http_access allow emisora
-
-#http_access allow CONNECT messengers msn msnmsgr msn_messenger SkypeHabilitados
-#http_access deny messengers
-
-http_access deny messengers_dstdomain_ip
-http_access deny messengers_dstdomain_name
-http_access deny messengers_dstdom_regex
-
-#http_access deny msnmsgr !SkypeHabilitados
-
-http_access deny msn_messenger !SkypeHabilitados
-http_access deny udnet_denegados
-
-
-# Exampe rule allowing access from your local networks. Adapt
-# to list your (internal) IP networks from where browsing should
-# be allowed
-#acl our_networks src 192.168.1.0/24 192.168.2.0/24
-#http_access allow our_networks
-
-# And finally deny all other access to this proxy
-http_access deny !Safe_ports
-http_access deny gtalk
-http_access deny CONNECT skype !SkypeHabilitados
-http_access deny msn
-http_access allow desbloqueados_por_solicitud
-http_access allow bibliotecas
-http_access deny manager
-http_access deny porno
-http_access deny extensiones_prohibidas
-http_access allow restringidos restringidos_auth
-http_access deny restringidos
-http_access deny prohibidos
+http_access deny  !safe_ports
+http_access allow connect cualquier_ip clientes_chat
+http_access allow chat_domains clientes_chat
+http_access allow chat_urls clientes_chat
+http_access allow apps.facebook.com permitir_apps.facebook.com
+http_access deny  connect cualquier_ip
+http_access deny  apps.facebook.com
+http_access deny  chat_domains
+http_access deny  chat_urls
+http_access deny  adult_domains
+http_access deny  adult_urls
+http_access deny  malware_domains
+http_access deny  malware_urls
+http_access deny  phishing_domains
+http_access deny  phishing_urls
+http_access deny  publicite_domains
+http_access deny  publicite_urls
+http_access deny  redirector_domains
+http_access deny  redirector_urls
+http_access deny  marketingware_domains
+http_access deny  marketingware_urls
 http_access allow udnet
 http_access allow localhost
-http_access deny all
+http_access deny  all

-> Hasta aqui son los cambios en reglas de control de acceso. 

-> Se agregan páginas personalizadas para cada tipo de error y se define una codificación de errores de la siguiente manera:

-> COD_ERROR    PAGINA_QUE_CARGA                 DESCRIPCION_DE_ERROR
-> 222600	ERR_ACCESS_DENIED                Denegación genérica, no especificada
-> 222694	ERR_ACCESS_DENIED_ADULT          Denegación de páginas para adultos
-> 222657	ERR_ACCESS_DENIED_CHAT           Denegación de páginas de chat
-> 222677	ERR_ACCESS_DENIED_MALWARE        Denegación de páginas de malware
-> 222646	ERR_ACCESS_DENIED_PHISHING       Denegación de páginas de phishing
-> 222676	ERR_ACCESS_DENIED_PUBLICITE      Denegacion de páginas de publicidad
-> 222665	ERR_ACCESS_DENIED_REDIRECTOR     Denegacion de páginas que permiten saltar las reglas del proxy
-> 222633	ERR_ACCESS_DENIED_MARKETINGWARE  Denegación de páginas de adware
-> 222656	ERR_ACCESS_DENIED_MAXCONN        Denegación por alcance de máximas conexiones (TCP_RESET)
-> 222655	ERR_ACCESS_DENIED_MANAGER        Denegación por intento de acceso a interfaz administrativa del proxy
-> 222615	ERR_ACCESS_DENIED_LOCALNET       Denegación por intento de acceso a red interna
-> 222670	ERR_ACCESS_DENIED_VIRUS          Denegación de páginas conocidas como vectores de virus
-> 222680	ERR_ACCESS_DENIED_CONN           Denegación por uso de método CONNECT a un destino no permitido
-> 222622	ERR_ACCESS_DENIED_PORT           Denegación por uso de puerto no permitido
-> 222613	ERR_ACCESS_DENIED_FB             Denegación de la página app.facebook.com
-> 222610	ERR_ACCESS_DENIED_CLIENT         Denegación explicíta de cliente por dirección IP

+# infos
+
+deny_info   TCP_RESET                       maximas_conexiones
+deny_info   ERR_ACCESS_DENIED_CLIENT        clientes_denegados
+deny_info   ERR_ACCESS_DENIED_MANAGER       manager
+deny_info   ERR_ACCESS_DENIED_LOCALNET      to_localnet
+deny_info   ERR_ACCESS_DENIED_VIRUS         virus
+deny_info   ERR_ACCESS_DENIED_PORT          !safe_ports
+deny_info   ERR_ACCESS_DENIED_CONN          connect cualquier_ip
+deny_info   ERR_ACCESS_DENIED_CHAT          chat_domains
+deny_info   ERR_ACCESS_DENIED_CHAT          chat_urls
+deny_info   ERR_ACCESS_DENIED_FB            apps.facebook.com
+deny_info   ERR_ACCESS_DENIED_ADULT         adult_domains
+deny_info   ERR_ACCESS_DENIED_ADULT         adult_urls
+deny_info   ERR_ACCESS_DENIED_MALWARE       malware_domains
+deny_info   ERR_ACCESS_DENIED_MALWARE       malware_urls
+deny_info   ERR_ACCESS_DENIED_PHISHING      phishing_domains
+deny_info   ERR_ACCESS_DENIED_PHISHING      phishing_urls
+deny_info   ERR_ACCESS_DENIED_PUBLICITE     publicite_domains
+deny_info   ERR_ACCESS_DENIED_PUBLICITE     publicite_urls
+deny_info   ERR_ACCESS_DENIED_REDIRECTOR    redirector_domains
+deny_info   ERR_ACCESS_DENIED_REDIRECTOR    redirector_urls
+deny_info   ERR_ACCESS_DENIED_MARKETINGWARE marketingware_domains
+deny_info   ERR_ACCESS_DENIED_MARKETINGWARE marketingware_urls
+
 #  TAG: http_reply_access
 #        Allow replies to client requests. This is complementary to http_access.
 #
@@ -1896,6 +1851,7 @@
 #
 #
 # and finally allow by default
+
 http_reply_access allow all
 
 #  TAG: icp_access
@@ -2044,7 +2000,6 @@
 #Default:
 # reply_body_max_size 0 allow all
 
-
 # ADMINISTRATIVE PARAMETERS
 # -----------------------------------------------------------------------------
 
@@ -2056,6 +2011,8 @@
 #Default:
 # cache_mgr root
 
+cache_mgr proxy en udistrital.edu.co
+

-> Uso de buzón para alimentar una cola de RT

 #  TAG: cache_effective_user
 #  TAG: cache_effective_group
 #
@@ -2086,6 +2043,8 @@
 #Default:
 # none
 
+visible_hostname proxy.udistrital.edu.co
+
 #  TAG: unique_hostname
 #	If you want to have multiple machines with the same
 #	'visible_hostname' then you must give each machine a different
@@ -2117,9 +2076,6 @@
 #	following information from this configuration file:
 #
 #		http_port
-http_port 3128
-#http_port 3129 transparent
-#https_port 3131 transparent cert=/etc/squid/my.cert key=/etc/squid/my.key
 #		icp_port
 #		cache_mgr
 #
@@ -2270,7 +2226,9 @@
 #	cause some Internet sites to become unavailable.
 #
 #Example:
+
 append_domain .udistrital.edu.co
+
 #
 #Default:
 # none
@@ -2467,11 +2425,6 @@
 #  TAG: store_avg_object_size	(kbytes)
 #	Average object size, used to estimate number of objects your
 #	cache can hold.  See doc/Release-Notes-1.1.txt.  The default is
-
-#cache deny extensiones_prohibidas adservers
-
-cache deny extensiones_prohibidas
-

-> Por usabilidad se dejan de prohibir ciertas extensiones de archivo

 #	13 KB.
 #
 #Default:
@@ -2589,6 +2542,7 @@
 #
 #Default:
 #none
+
 always_direct allow udistrital
 always_direct deny all
 
@@ -2762,8 +2716,9 @@
 #	set this to "3401" to use the normal SNMP support.
 #
 #Default:
-snmp_port 3401
 
+snmp_port 0
+

-> Se desactiva snmp

 #  TAG: snmp_access
 #	Allowing or denying access to the SNMP port.
 #
@@ -2773,8 +2728,9 @@
 #	snmp_access allow|deny [!]aclname ...
 #
 #Example:
-snmp_access allow snmppublic localhost
+
 snmp_access deny all
+

-> snmp desactivado

 #
 #Default:
 # snmp_access deny all
@@ -2911,7 +2867,6 @@
 # delay_access 1 deny all
 # delay_access 2 allow lotsa_little_clients
 # delay_access 2 deny all
-
 #
 #Default:
 # none
@@ -2982,9 +2937,8 @@
 #	"seen" by squid).
 #
 #Default:
-# delay_initial_bucket_level 50
+#delay_initial_bucket_level 50
 #delay_initial_bucket_level 30
-delay_initial_bucket_level 20
 
-> Los pools de administración de ancho de banda no se estaban utilizando así que se desactivan por completo.

 #  TAG: incoming_icp_average
 #  TAG: incoming_http_average
@@ -3156,6 +3110,7 @@
 # coredump_dir none
 #
 # Leave coredumps in the first cache dir
+
 coredump_dir /var/spool/squid
 
 #  TAG: redirector_bypass
@@ -3382,36 +3337,5 @@
 #Default:
 # sleep_after_fork 0
 
-cache_mgr adminud en udistrital.edu.co
-visible_hostname proxy.udistrital.edu.co
-
-#deny_info ERR_ADS_DENIED adservers
-
-#deny_info ERR_ADS_DENIED adservers
-
-#delay_pools 2
-delay_pools 1
-#delay_class 1 2
-#delay_class 2 3
-delay_class 1 3
-#delay_parameters 1 -1/-1 -1/-1
-#delay_parameters 2 -1/-1 -1/-1 375000/375000
-delay_parameters 1 -1/-1 -1/-1 -1/-1
-
-#delay_access 1 allow Asuntos_Disciplinarios
-#delay_access 1 deny all
-#delay_access 2 allow udnet
-#delay_access 2 deny all
-delay_access 1 allow udnet
-
-
-#follow_x_forwarded_for allow localhost
-#follow_x_forwarded_for allow udnet
-#acl_uses_indirect_client on
-#delay_pool_uses_indirect_client on
-#log_uses_indirect_client on
-
-access_log /var/log/squid/access.log squid
-
 max_filedesc 20480
 
------------ próxima parte ------------
Se ha borrado un mensaje que no está en formato texto plano...
Nombre     : report1.jpg
Tipo       : image/jpeg
Tamaño     : 114173 bytes
Descripción: no disponible
Url        : http://listas.udistrital.edu.co/mailman/private/udnet/attachments/20130118/ce63b453/report1-0001.jpg
------------ próxima parte ------------
Se ha borrado un mensaje que no está en formato texto plano...
Nombre     : 10895.jpg
Tipo       : image/jpeg
Tamaño     : 239662 bytes
Descripción: no disponible
Url        : http://listas.udistrital.edu.co/mailman/private/udnet/attachments/20130118/ce63b453/10895-0001.jpg
------------ próxima parte ------------
Se ha borrado un mensaje que no está en formato texto plano...
Nombre     : reporte_cambios.txt.sig
Tipo       : application/pgp-signature
Tamaño     : 287 bytes
Descripción: no disponible
Url        : http://listas.udistrital.edu.co/mailman/private/udnet/attachments/20130118/ce63b453/reporte_cambios.txt-0001.bin
------------ próxima parte ------------
Se ha borrado un mensaje que no está en formato texto plano...
Nombre     : report1.jpg.sig
Tipo       : application/pgp-signature
Tamaño     : 287 bytes
Descripción: no disponible
Url        : http://listas.udistrital.edu.co/mailman/private/udnet/attachments/20130118/ce63b453/report1.jpg-0001.bin
------------ próxima parte ------------
Se ha borrado un mensaje que no está en formato texto plano...
Nombre     : 10895.jpg.sig
Tipo       : application/pgp-signature
Tamaño     : 287 bytes
Descripción: no disponible
Url        : http://listas.udistrital.edu.co/mailman/private/udnet/attachments/20130118/ce63b453/10895.jpg-0001.bin


Más información sobre la lista de distribución Udnet