Squid Proxy: ACLs, Authentication and Caching - 夜莺博客

Squid Proxy: ACLs, Authentication and Caching

Squid has been the reference caching forward proxy for decades, and it is still the pragmatic choice when you need egress control, content filtering and a cache in front of a slow uplink. Two things decide whether the deployment is pleasant or painful: the order of http_access rules, and whether you actually need authenticated users. This guide covers both, plus the cache settings that reduce bandwidth instead of wasting disk.

Baseline configuration

http_port 3128

# who may use the proxy
acl localnet src 192.0.2.0/24
acl localnet src 2001:db8:1::/64

acl SSL_ports port 443
acl Safe_ports port 80
acl Safe_ports port 443
acl Safe_ports port 21
acl CONNECT method CONNECT

# order matters: deny first, allow afterwards
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localnet
http_access deny all

visible_hostname proxy.corp.local

Delete any acl localnet line that does not describe your environment, and keep the terminal http_access deny all. Squid evaluates rules top-down and stops at the first match; an allow placed above a deny silently makes the deny unreachable.

Filtering with the right ACL type

  • dstdomain - the correct way to block or allow sites: acl blocked dstdomain .example.com. Domain names, not IPs, because CDNs share addresses.
  • urlpath_regex - file extensions: acl files urlpath_regex -i \.(exe|iso|mkv)$.
  • time - business-hours rules: acl office_hours time MTWHF 09:00-17:00.
  • src - network or host based policy, including reading long lists from a file with acl trusted src "/etc/squid/trusted_ips.txt".

Requiring authentication

sudo apt-get install apache2-utils
sudo touch /etc/squid/passwords && sudo chown proxy:proxy /etc/squid/passwords
sudo chmod 640 /etc/squid/passwords
sudo htpasswd /etc/squid/passwords alice

auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/passwords
auth_param basic realm Proxy Authentication Required
auth_param basic credentialsttl 2 hours
acl authenticated proxy_auth REQUIRED
http_access allow authenticated
http_access deny all

For directory-backed auth, swap the helper for basic_ldap_auth with -b (search base), -D (bind DN), -W (password file instead of -w on the command line, which would expose the secret in the process list) and -f (filter). If you enable authentication, remove http_access allow localnet or clients will bypass it by simply living on a trusted subnet.

Caching that does not waste disk on dynamic pages

cache_dir ufs /var/spool/squid 20000 16 256
cache_mem 512 MB
maximum_object_size 100 MB
maximum_object_size_in_memory 2 MB

refresh_pattern -i \.(jpg|jpeg|png|gif|ico|webp)$ 10080 90% 43200
refresh_pattern -i \.(css|js|woff2?)$                10080 90% 43200
refresh_pattern -i (/cgi-bin/|\?)                     0     0%     0
refresh_pattern .                                     0    20%  4320

Initialise the cache after any cache_dir change with sudo squid -z, and keep both cache_swap_high/cache_swap_low at sensible values (90/80) so Squid trims the cache gradually instead of stalling on a full disk.

Verification and troubleshooting

  • squid -k parse before every reload; it validates the configuration without restarting the service.
  • squidclient -h localhost -p 3128 mgr:info shows hit ratios and memory usage; a near-zero hit ratio on static content means your refresh_pattern order is wrong.
  • Permission errors on startup are almost always /var/spool/squid ownership - it must belong to the proxy user.
  • If the proxy fronts origin servers, evaluate a reverse proxy for that role instead, as described in nginx Reverse Proxy Setup: proxy_pass, Headers and Buffers; Squid's forward-proxy ACL model is a poor fit for TLS termination.

Related reading on this site: nginx Reverse Proxy Setup: proxy_pass, Headers and Buffers and nftables from Scratch: Tables, Chains and NAT Examples.

原文链接:https://docs.redhat.com/en/documentation/Red_Hat_Enterprise_Linux/9/html/deploying_web_servers_and_reverse_proxies/configuring-the-squid-caching-proxy-server_deploying-web-servers-and-reverse-proxies