Обсуждение настройки и работы сервисов, резервирования, сетевых настроек и вопросов безопасности ОС.
Модераторы: SLEDopit , Модераторы разделов
Art666
Сообщения: 49
ОС: Mandriva 2008
Сообщение
Art666 » 09.05.2008 15:36
всем привет. имееться компютер з убунтой 8,04, squid 3 с таким конфигом
Код: Выделить всё
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_port 172.16.28.16:1234
ftp_user anonymous@
ftp_list_width 32
ftp_passive on
ftp_sanitycheck on
acl art src 172.16.28.16/255.255.255.255 # Мой сервер
acl serg src 172.16.28.28/255.255.255.255 # пользователь Serg
http_access allow art
http_access allow serg
http_access deny !Safe_ports
http_access deny all
почему я могу пользаваться прокси, а serg нет (у него просто ничего не загружаеться)?
заранее спасибо
Alexxx
Сообщения: 892
Статус: --==XXX==--
ОС: Archlinux current
Сообщение
Alexxx » 09.05.2008 15:56
Art666 писал(а): ↑ 09.05.2008 15:36
почему я могу пользаваться прокси, а serg нет (у него просто ничего не загружаеться)?
заранее спасибо
Ну, например, файервол рубит запросы.
А вот ещё в строчке
а самого правила
all нету:
Art666
Сообщения: 49
ОС: Mandriva 2008
Сообщение
Art666 » 09.05.2008 16:14
а что нада ввести в терминале чтоб файрвол вобще отцыпился от 1234 порта?
а когда дописую в файл строку
то в терминале вижу такое
Код: Выделить всё
art@art-desktop:/etc/squid3$ sudo /etc/init.d/squid3 restart
* Restarting Squid HTTP Proxy 3.0 squid3 * Waiting... * ... * ... * ... * ... * ... * ... [ OK ]
2008/05/09 15:21:23| WARNING: '0.0.0.0/0.0.0.0' is a subnetwork of '0.0.0.0/0.0.0.0'
2008/05/09 15:21:23| WARNING: because of this '0.0.0.0/0.0.0.0' is ignored to keep splay tree searching predictable
2008/05/09 15:21:23| WARNING: You should probably remove '0.0.0.0/0.0.0.0' from the ACL named 'all'
[ OK ]
art@art-desktop:/etc/squid3$
Igor Yakimchuk
Сообщения: 110
ОС: FreeBSD
Сообщение
Igor Yakimchuk » 09.05.2008 17:06
а в логах пишет что пользовател пытается ломиться через прокси?
Есть ли фаервол и разрешается ли цепляться на порт прокси сервера?
Art666
Сообщения: 49
ОС: Mandriva 2008
Сообщение
Art666 » 10.05.2008 14:50
в логе написано что ломился
Код: Выделить всё
1210321709.739 109 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210321808.747 34 172.16.28.16 TCP_DENIED/403 2579 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210321814.879 0 172.16.28.16 TCP_DENIED/403 2586 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210321988.588 2 172.16.28.16 TCP_DENIED/403 2645 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210321990.427 0 172.16.28.16 TCP_DENIED/403 2645 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210321991.083 0 172.16.28.16 TCP_DENIED/403 2645 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210321991.689 0 172.16.28.16 TCP_DENIED/403 2645 GET http://gimper.ru/forum/viewforum.php? - NONE/- text/html
1210322003.109 0 172.16.28.16 TCP_DENIED/403 2644 GET http://www.google.com/search? - NONE/- text/html
1210322086.194 0 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210322184.776 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210323570.174 123 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210323645.101 1530 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210326348.832 66 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210326657.262 110 172.16.28.16 TCP_DENIED/403 2660 GET http://linuxforum.ru/index.php? - NONE/- text/html
1210326657.311 48 172.16.28.16 TCP_DENIED/403 2585 GET http://sitecheck2.opera.com/? - NONE/- text/html
1210326693.936 14 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210327818.110 58 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210327831.642 6 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210328850.662 15 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328851.910 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328852.947 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328874.216 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328875.085 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328875.505 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328875.849 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328876.274 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328876.557 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328876.797 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328877.040 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328877.230 0 172.16.28.28 TCP_DENIED/403 2845 GET http://cihar.com/gammu/phonedb/benq/1182/ - NONE/- text/html
1210328886.464 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210328892.008 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210328905.708 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210329117.578 35 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210329409.363 67 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210329632.491 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210329658.627 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210329907.671 16 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210330139.661 48 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210330146.853 11 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210330154.688 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210330162.766 0 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210330184.362 0 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210330226.069 1 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
1210330652.063 37 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210331127.464 151 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210331506.823 139 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210332001.599 15 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210332496.587 5 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210332991.596 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210333486.616 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210333981.628 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210334476.773 83 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210334808.904 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210335468.183 656 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210335961.797 42 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210336456.715 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210336951.753 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210337446.765 0 172.16.28.28 NONE/400 1790 GET / - NONE/- text/html
1210411878.419 108 172.16.28.16 NONE/400 1790 GET / - NONE/- text/html
Alexxx
Сообщения: 892
Статус: --==XXX==--
ОС: Archlinux current
Сообщение
Alexxx » 10.05.2008 15:49
может /etc/hosts.allow ещё глянуть??...
Art666
Сообщения: 49
ОС: Mandriva 2008
Сообщение
Art666 » 10.05.2008 22:11
сщдержимое /etc/hosts.allow
Код: Выделить всё
# /etc/hosts.allow: list of hosts that are allowed to access the system.
# See the manual pages hosts_access(5) and hosts_options(5).
#
# Example: ALL: LOCAL @some_netgroup
# ALL: .foobar.edu EXCEPT terminalserver.foobar.edu
#
# If you're going to protect the portmapper use the name "portmap" for the
# daemon name. Remember that you can only use the keyword "ALL" and IP
# addresses (NOT host or domain names) for the portmapper, as well as for
# rpc.mountd (the NFS mount daemon). See portmap(8) and rpc.mountd(8)
# for further information.
#
Voler
Сообщения: 498
ОС: Fedora
Сообщение
Voler » 11.05.2008 12:47