<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://ca.wiki.guifi.net/w/skins/common/feed.css?303"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="ca">
		<id>http://ca.wiki.guifi.net/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bellera</id>
		<title>Guifi.net - Wiki Català - Contribucions de l'usuari [ca]</title>
		<link rel="self" type="application/atom+xml" href="http://ca.wiki.guifi.net/w/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bellera"/>
		<link rel="alternate" type="text/html" href="http://ca.wiki.guifi.net/wiki/Especial:Contribucions/Bellera"/>
		<updated>2026-07-29T04:20:49Z</updated>
		<subtitle>Contribucions de l'usuari</subtitle>
		<generator>MediaWiki 1.22.0</generator>

	<entry>
		<id>http://ca.wiki.guifi.net/wiki/Squid</id>
		<title>Squid</title>
		<link rel="alternate" type="text/html" href="http://ca.wiki.guifi.net/wiki/Squid"/>
				<updated>2014-03-14T06:40:09Z</updated>
		
		<summary type="html">&lt;p&gt;Bellera: /* pfsense */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{PlantillaCurs&lt;br /&gt;
| fitxers                = {{FitxerIOriginalODT|url=http://anonymous@svn.projectes.lafarga.cat/svn/iceupc/DissenyXarxaLocalLinux/moodle/sessio7/Squid/transparencies|nom=ProxySquid}}&lt;br /&gt;
| repositori             = http://anonymous@svn.projectes.lafarga.cat/svn/iceupc/DissenyXarxaLocalLinux&lt;br /&gt;
| autors                 = [[Especial:Contribucions/Sergi|Sergi Tur Badenas]]&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidLogo.png|thumb|right|Squid]]&lt;br /&gt;
&lt;br /&gt;
Squid (calamar en angles) és segurament el servidor proxy i cache web open source més famós i utilitzat.&lt;br /&gt;
&lt;br /&gt;
'''Característiques''':&lt;br /&gt;
*Llicència GNU General Public License.&lt;br /&gt;
*Suporta diferents protocols però s'utilitza principalment per HTTP i FTP. Té suport parcial per SSL i TLS.&lt;br /&gt;
*S'utilitza principalment per emmagatzemar pàgines web en cache i millorar la connexió a Internet&lt;br /&gt;
*No proveïx de sistemes de filtratge (és pot fer amb afegitons també coneguts com add-ons) &lt;br /&gt;
*Se li poden incorporar afegitons (SquidGuard, Calamaris, ufdbGuard)&lt;br /&gt;
&lt;br /&gt;
=Introducció=&lt;br /&gt;
&lt;br /&gt;
Squid és una aplicació que bàsicament s'utilitza per a:&lt;br /&gt;
&lt;br /&gt;
'''Web caching''':&lt;br /&gt;
*“Cachejar” és  guardar la informació en una memòria que estigui més propera a l'usuari final.&lt;br /&gt;
*Proxy HTTP. Els clients s'han de configurar per tal d'utilitzar el proxy com a medi de connexió a Internet.&lt;br /&gt;
*Proxy transparent. No cal configuració dels clients (totes les comunicacions pel port 80 són interceptades). Cal tenir en compte que no es pot utilitzar amb HTTPS.&lt;br /&gt;
&lt;br /&gt;
'''Reverse proxy | web server acceleration''':&lt;br /&gt;
*Permet utilitzar un servidor proxy com a suport d'un servidor web. La filosofia és inversa al web caching i permet alliberar carrega en un servidor web compartin st part de la carrega amb el proxy.&lt;br /&gt;
*[[Apache]] permet implementar aquesta funcionalitat amb un mòdul.&lt;br /&gt;
&lt;br /&gt;
==Proxies (passarel·les) vs firewalls (tallafocs)==&lt;br /&gt;
&lt;br /&gt;
Quina diferència hi ha entre els tallafocs i els proxies? Tots dos són eines de control d'ús dels recursos d'una xarxa però que apliquen els seus mecanismes de control en nivells diferents del protocol [[OSI]] o [[TCP/IP]]. La següent taula relaciona els nivells OSI amb l'eina corresponent:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Nivell OSI&lt;br /&gt;
! Tallafocs&lt;br /&gt;
! Proxy&lt;br /&gt;
|-&lt;br /&gt;
| Nivell 1. Nivell físic&lt;br /&gt;
| No s'aplica&lt;br /&gt;
| No s'aplica&lt;br /&gt;
|-&lt;br /&gt;
| Nivell 2. Nivell d'enllaç&lt;br /&gt;
| Sí&lt;br /&gt;
| No&lt;br /&gt;
|-&lt;br /&gt;
| Nivell 3. Nivell de xarxa (IP)&lt;br /&gt;
| Sí&lt;br /&gt;
| No&lt;br /&gt;
|-&lt;br /&gt;
| Nivell 4. Nivell de transport (TCP)&lt;br /&gt;
| Sí&lt;br /&gt;
| No&lt;br /&gt;
|-&lt;br /&gt;
| Nivells d'aplicació 5, 6 i 7. &lt;br /&gt;
| No&lt;br /&gt;
| Sí&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{{nota| Cal tenir en compte però que aquesta classificació de les tasques que realitzen els tallafocs i els proxies no és completament rígida. Per exemple, proxies com Squid també fan tasques de control d'accés per IP (nivell 3) o per MAC (nivell 2) o per port (nivell 4)}}&lt;br /&gt;
&lt;br /&gt;
En resum, els tallafocs estan pensats per a treballar als nivells de xarxa i transport de la informació i els proxies estan pensats per treballar a nivell d'aplicació, és a dir amb les dades que es transporten.&lt;br /&gt;
&lt;br /&gt;
En xarxes modernes el protocols més utilitzats a nivell de xarxa i transport són Ethernet i TCP/IP. Un tallafocs com [[iptables]] suporta aquests protocols i pot cobrir qualsevol requeriment de control en aquest nivells. &lt;br /&gt;
&lt;br /&gt;
En canvi, a nivell d'aplicació tenim gairebé tants protocols com aplicacions que utilitzen la xarxa; per navegar per la xarxa utilitzem [[HTTP]], per al correu electrònic utilitzem [[POP3]], [[IMAP]] i [[SMTP]], per a xarxes Windows utilitzem [[SMB/CFIS]], per a xarxes Linux [[NFS]], per a transferència de fitxers [[FTP]]... la llista és molt llarga.&lt;br /&gt;
&lt;br /&gt;
Cal tenir en compte doncs que a nivell d'aplicació necessitem un proxy que suport el protocol que volem controlar. Squid és capaç de treballar amb [[HTTP]], [[HTTPS]], [[FTP]] i [[Gopher]] que són alguns dels protocols més utilitzats en xarxes. Per a filtrar altres protocols hauríeu d'utilitzar altres proxies.&lt;br /&gt;
&lt;br /&gt;
{{nota|Cal tenir en compte que un tallafocs com p. ex. [[iptables]] pot perfectament crear normes de control d'accés basades en informació del nivell d'aplicació (per exemple filtrar les pàgines que continguin la paraula sexe). El problema és que no està dissenyat per aquesta tasca i per tant és molt millor utilitzar un proxy de nivell d'aplicació.}}&lt;br /&gt;
&lt;br /&gt;
==Avantatges i inconvenients==&lt;br /&gt;
&lt;br /&gt;
'''Avantatges''':&lt;br /&gt;
*Millor velocitat.&lt;br /&gt;
*Millor control de l'accés a recursos. &lt;br /&gt;
*Llistes ACL per controlar l'accés a Internet.&lt;br /&gt;
*Permet filtrar a nivell d'aplicació (urls, continguts, horaris d'accés, etc.)&lt;br /&gt;
'''Inconvenients''':&lt;br /&gt;
*S'envaeix la privacitat dels clients del proxy (molta informació personal és registrada )&lt;br /&gt;
*La cache pot ser un greu problema per a pàgines dinàmiques.&lt;br /&gt;
*Squid, si s'utilitza directament és força laboriós i complicat de configurar. Tenim aplicacions (front-ends) que ens faciliten l'ús d'Squid.&lt;br /&gt;
&lt;br /&gt;
== Web caching ==&lt;br /&gt;
&lt;br /&gt;
Com sap la cache quins objectes ha de guardar en memòria i quins no? Això depèn de com s'hagi desenvolupat la pàgina web i de com es configuri la memòria cau en el client.&lt;br /&gt;
Un objecte pot ser marcat per tal que no sigui mai guardat en memòria cau (P. ex. pàgines dinàmiques) i la cache ignorarà aquest objecte. &lt;br /&gt;
&lt;br /&gt;
{{nota|Tingueu en compte que parlem d'objectes i no de pàgines web. La majoria de pàgines web modernes són realment un conjunt d'objectes: fitxers HTML, imatges, codi de servidor com PHP, múltimedia, etc... Cadascun d'aquest objectes s'obté amb una petició HTTP especifica i per tant podem especificar diferents configuracions de cache per a cada objecte}}.&lt;br /&gt;
&lt;br /&gt;
També es pot marcar un objecte amb una '''edat màxima''' (max age, indica un temps) o un camp expires (indica una data concreta) que indica a la cache quin serà el màxim de temps abans de que es vegi obligada a tornar a demanar l'objecte.&lt;br /&gt;
&lt;br /&gt;
L'objecte també pot tenir un camp amb la '''data de l'última modificació''' (last modified). Si la data de modificació és més nova que la data de l'objecte guardat aleshores cal tornar a demanar l'objecte. &lt;br /&gt;
&lt;br /&gt;
[[Fitxer:webcaching.png|center]]&lt;br /&gt;
&lt;br /&gt;
Quan un objecte de la cache encara és correcte és diu que és un objecte fresc (FRESH) i si no és correcte es diu que està caducat (STALE). El protocol [[HTTP]] defineix 3 modes de controlar la memòria cau:&lt;br /&gt;
&lt;br /&gt;
*'''Freshness''': permet indicar la &amp;quot;frescura&amp;quot; de les respostes HTTP de forma que la cache les pugui reutilitzar sense tornar-les a demanar. Aquesta informació normalment s'indica a les capçaleres de les respostes HTTP (HTTP response headers). Les capçaleres més utilitzades:&lt;br /&gt;
&lt;br /&gt;
 '''Expires''': indica una data a partir de la qual l'objecte es considerarà caducat.&lt;br /&gt;
 '''Cache-Control''': indica durant quants segons l'objecte es considerarà fresc.&lt;br /&gt;
&lt;br /&gt;
*'''Validation''': es pot utilitzar per comprovar si una resposta en memòria cau encara és vàlida. La capçalera utilitzada és:&lt;br /&gt;
&lt;br /&gt;
 '''Last-Modified''': Si la data de modificació de l'objecte és posterior a la data de l'objecte en memòria cau aleshores està caducat.&lt;br /&gt;
&lt;br /&gt;
*'''Invalidation''': Alguns request com POST, PUT O DELETE poden invalidar un objecte de la memòria cau.&lt;br /&gt;
&lt;br /&gt;
Podeu utilitzar el plugin de firefox [https://addons.mozilla.org/es-ES/firefox/addon/60 Web Developer] que entre d'altres coses us permet consultar els response headers (al menú Information &amp;gt; View Response Headers) de qualsevol pàgina. També són molt interessants les eines com [[webscarab]]. &lt;br /&gt;
&lt;br /&gt;
Per exemple els response headers d'aquesta pàgina són:&lt;br /&gt;
&lt;br /&gt;
 '''Date''': Sun, 24 Jan 2010 15:53:35 GMT&lt;br /&gt;
 '''Server''': Apache/2.2.11 (Ubuntu) PHP/5.2.6-3ubuntu4 with Suhosin-Patch mod_ssl/2.2.11 OpenSSL/0.9.8g&lt;br /&gt;
 '''X-Powered-By''': PHP/5.2.6-3ubuntu4&lt;br /&gt;
 '''Content-Language''': ca&lt;br /&gt;
 '''Vary''': Accept-Encoding,Cookie&lt;br /&gt;
 '''X-Vary-Options''': Accept-Encoding;list-contains=gzip,Cookie;string-contains=wikidb_mediawiki_Token;string-contains=wikidb_mediawiki_LoggedOut;string- &lt;br /&gt;
 contains=wikidb_mediawiki__session&lt;br /&gt;
 '''Expires''': Thu, 01 Jan 1970 00:00:00 GMT&lt;br /&gt;
 '''Cache-Control''': private, must-revalidate, max-age=0&lt;br /&gt;
 '''Last-Modified''': Sun, 24 Jan 2010 15:53:28 GMT&lt;br /&gt;
 '''Content-Encoding''': gzip&lt;br /&gt;
 '''Content-Type''': text/html; charset=utf-8&lt;br /&gt;
 &lt;br /&gt;
 200 OK&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://en.wikipedia.org/wiki/Web_cache&lt;br /&gt;
&lt;br /&gt;
===Memòria cau de Firefox===&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
&lt;br /&gt;
 [[Firefox#Cache]]&lt;br /&gt;
&lt;br /&gt;
==Com funciona Squid?==&lt;br /&gt;
&lt;br /&gt;
[[Imatge:DiagramaDeFluxSquid.png]]&lt;br /&gt;
&lt;br /&gt;
=Instal·lació=&lt;br /&gt;
&lt;br /&gt;
En sistemes de la família [[Debian]] com p. ex. [[Ubuntu]], podem instal·lar Squid des dels [[repositoris]]:&lt;br /&gt;
&lt;br /&gt;
{{nota| Als repositoris també hi ha la versió 2.x amb el nom de paquet squid!}}&lt;br /&gt;
&lt;br /&gt;
 '''$ [[sudo]] [[apt-get]] install squid3'''&lt;br /&gt;
 S'està llegint la llista de paquets... Fet &lt;br /&gt;
 S'està construint l'arbre de dependències       &lt;br /&gt;
 Reading state information... Fet           &lt;br /&gt;
 S'instal·laran els següents paquets extres:&lt;br /&gt;
   squid3-common&lt;br /&gt;
 Paquets suggerits:&lt;br /&gt;
   '''squid3-client squid3-cgi resolvconf'''&lt;br /&gt;
 S'instal·laran els següents paquets NOUS:&lt;br /&gt;
   '''squid3 squid3-common'''&lt;br /&gt;
 0 actualitzats, 2 nous a instal·lar, 0 a eliminar i 44 no actualitzats.&lt;br /&gt;
 Es necessita obtenir 966kB d'arxius.&lt;br /&gt;
 Després de desempaquetar s'usaran 6312kB d'espai en disc addicional.&lt;br /&gt;
 Voleu continuar [S/n]? s&lt;br /&gt;
 Des:1 http://ch.archive.ubuntu.com feisty/universe squid3-common 3.0.PRE5-5 [245kB]&lt;br /&gt;
 Des:2 http://ch.archive.ubuntu.com feisty/universe squid3 3.0.PRE5-5 [721kB]&lt;br /&gt;
 966kB descarregats en 5s (165kB/s)    &lt;br /&gt;
 S'està seleccionant el paquet squid3-common prèviament no seleccionat.&lt;br /&gt;
 (S'està llegint la base de dades ... hi ha 322742 fitxers i directoris instal·lats actualment.)&lt;br /&gt;
 S'està desempaquetant squid3-common (de .../squid3-common_3.0.PRE5-5_all.deb) ...&lt;br /&gt;
 S'està seleccionant el paquet squid3 prèviament no seleccionat.&lt;br /&gt;
 S'està desempaquetant squid3 (de .../squid3_3.0.PRE5-5_i386.deb) ...&lt;br /&gt;
 S'està configurant squid3-common (3.0.PRE5-5) ...&lt;br /&gt;
 S'està configurant squid3 (3.0.PRE5-5) ...&lt;br /&gt;
 [: 68: ==: unexpected operator&lt;br /&gt;
 Creating Squid HTTP proxy 3.0 spool directory structure&lt;br /&gt;
 2007/07/03 17:53:13| Creating Swap Directories&lt;br /&gt;
 2007/07/03 17:53:13| /var/spool/squid3 exists &lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/00&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/01&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/02&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/03&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/04&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/05&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/06&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/07&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/08&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/09&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0A&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0B&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0C&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0D&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0E&lt;br /&gt;
 2007/07/03 17:53:13| Making directories in /var/spool/squid3/0F&lt;br /&gt;
 * Restarting Squid HTTP Proxy 3.0 squid3                     &lt;br /&gt;
&lt;br /&gt;
Observeu com és crea la memòria cau per emmagatzemar fitxers a:&lt;br /&gt;
&lt;br /&gt;
 /var/spool/squid3&lt;br /&gt;
&lt;br /&gt;
I el servidor Squid es arrencat automàticament i s'executarà sempre a l'inici del sistema. &lt;br /&gt;
&lt;br /&gt;
L'executable és el fitxer '''/usr/sbin/squid3''':&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L squid3 | grep sbin&lt;br /&gt;
 /usr/sbin&lt;br /&gt;
 /usr/sbin/squid3&lt;br /&gt;
&lt;br /&gt;
I els fitxers de configuració:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L squid3 | grep etc&lt;br /&gt;
 /etc&lt;br /&gt;
 /etc/logrotate.d&lt;br /&gt;
 /etc/logrotate.d/squid3&lt;br /&gt;
 /etc/squid3&lt;br /&gt;
 /etc/squid3/squid.conf&lt;br /&gt;
 /etc/squid3/msntauth.conf&lt;br /&gt;
 /etc/resolvconf.d&lt;br /&gt;
 /etc/resolvconf.d/update-libc.d&lt;br /&gt;
 /etc/resolvconf.d/update-libc.d/squid3&lt;br /&gt;
 /etc/init.d&lt;br /&gt;
 /etc/init.d/squid3&lt;br /&gt;
&lt;br /&gt;
Cal també que tingueu en compte el paquet:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L squid3-common&lt;br /&gt;
 /.&lt;br /&gt;
 /usr&lt;br /&gt;
 /usr/share&lt;br /&gt;
 /usr/share/doc&lt;br /&gt;
 /usr/share/doc/squid3-common&lt;br /&gt;
 /usr/share/doc/squid3-common/README&lt;br /&gt;
 /usr/share/doc/squid3-common/CREDITS.gz&lt;br /&gt;
 /usr/share/doc/squid3-common/changelog.Debian.gz&lt;br /&gt;
 /usr/share/doc/squid3-common/QUICKSTART&lt;br /&gt;
 /usr/share/doc/squid3-common/RELEASENOTES.html&lt;br /&gt;
 /usr/share/doc/squid3-common/SPONSORS&lt;br /&gt;
 /usr/share/doc/squid3-common/copyright&lt;br /&gt;
 /usr/share/doc/squid3-common/TODO.gz&lt;br /&gt;
 /usr/share/doc/squid3-common/CONTRIBUTORS.gz&lt;br /&gt;
 /usr/share/squid3&lt;br /&gt;
 /usr/share/squid3/icons&lt;br /&gt;
 /usr/share/squid3/icons/anthony-binhex.gif&lt;br /&gt;
 /usr/share/squid3/icons/anthony-bomb.gif&lt;br /&gt;
 /usr/share/squid3/icons/anthony-box.gif&lt;br /&gt;
 /usr/share/squid3/icons/anthony-box2.gif&lt;br /&gt;
 /usr/share/squid3/icons/anthony-c.gif&lt;br /&gt;
 /usr/share/squid3/icons/anthony-compressed.gif&lt;br /&gt;
 ...&lt;br /&gt;
 /usr/share/squid3/mib.txt&lt;br /&gt;
 /usr/share/squid3/mime.conf&lt;br /&gt;
 /usr/share/squid3/errors&lt;br /&gt;
 &lt;br /&gt;
==Control del servei Apache. Execució, parada i reconfiguració d'Apache==&lt;br /&gt;
&lt;br /&gt;
Seguint els estàndards de Debian GNU/Linux (basat en el sistema d'scripts d'inicialització SystemV (http://en.wikipedia.org/wiki/System_V)) l'script de control del dimoni bind és:&lt;br /&gt;
&lt;br /&gt;
 /etc/init.d/squid3&lt;br /&gt;
&lt;br /&gt;
Les accions que podem fer amb el servei són start|stop|restart|reload|force-reload.&lt;br /&gt;
&lt;br /&gt;
Cada cop que fem un canvi a la configuració d'Apache2 hem de fer un restart o, millor encara, un reload del servei:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/init.d/squid3 reload&lt;br /&gt;
&lt;br /&gt;
Tal com podem veure executant:&lt;br /&gt;
&lt;br /&gt;
 $ sudo updatedb&lt;br /&gt;
 $ locate squid | grep rc&lt;br /&gt;
 /etc/rc0.d/K30squid3&lt;br /&gt;
 /etc/rc1.d/K30squid3&lt;br /&gt;
 /etc/rc2.d/S30squid3&lt;br /&gt;
 /etc/rc3.d/S30squid3&lt;br /&gt;
 /etc/rc4.d/S30squid3&lt;br /&gt;
 /etc/rc5.d/S30squid3&lt;br /&gt;
 /etc/rc6.d/K30squid3  &lt;br /&gt;
&lt;br /&gt;
El servei squid s'executa a partir del nivell 3.&lt;br /&gt;
&lt;br /&gt;
Podeu trobar més informació a l'article [[Configuraci%C3%B3_de_serveis_en_Linux._Daemons | Configuració de serveis en Linux]].&lt;br /&gt;
&lt;br /&gt;
==Ports per defecte del servei==&lt;br /&gt;
&lt;br /&gt;
Possiblement squid és un dels pocs serveis que no apareix al fitxer [[/etc/services]]:&lt;br /&gt;
&lt;br /&gt;
 $ cat /etc/services | grep 3128&lt;br /&gt;
&lt;br /&gt;
Però sapigueu que el port per defecte és:&lt;br /&gt;
&lt;br /&gt;
 3128&lt;br /&gt;
&lt;br /&gt;
I podeu utilitzar [[nmap]] per comprovar el correcte funcionament del servidor:&lt;br /&gt;
&lt;br /&gt;
 $ nmap localhost&lt;br /&gt;
 PORT     STATE SERVICE&lt;br /&gt;
 22/tcp   open  ssh&lt;br /&gt;
 53/tcp   open  domain&lt;br /&gt;
 80/tcp   open  http&lt;br /&gt;
 139/tcp  open  netbios-ssn&lt;br /&gt;
 445/tcp  open  microsoft-ds&lt;br /&gt;
 631/tcp  open  ipp&lt;br /&gt;
 '''3128/tcp open  squid-http'''&lt;br /&gt;
 3306/tcp open  mysql&lt;br /&gt;
 5900/tcp open  vnc&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
==Versió d'Squid==&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -l squid3&lt;br /&gt;
 Desired=Unknown/Install/Remove/Purge/Hold&lt;br /&gt;
 | Status=Not/Inst/Cfg-files/Unpacked/Failed-cfg/Half-inst/trig-aWait/Trig-pend&lt;br /&gt;
 |/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)&lt;br /&gt;
 ||/ Nom                                    Versió                                Descripció&lt;br /&gt;
 +++-======================================-======================================-============================================================================================&lt;br /&gt;
 ii  squid3                                 '''3.0.STABLE18-1'''                         A full featured Web Proxy cache (HTTP proxy)&lt;br /&gt;
&lt;br /&gt;
==Conèixer la versió que tenim d'Squid i les opcions de compilació==&lt;br /&gt;
&lt;br /&gt;
 $ squid3 -v&lt;br /&gt;
 Squid Cache: Version 3.0.STABLE18&lt;br /&gt;
 configure options:  '--build=i486-linux-gnu' '--prefix=/usr' '--includedir=${prefix}/include' '--mandir=${prefix}/share/man' '--infodir=${prefix}/share/info'  &lt;br /&gt;
 '--sysconfdir=/etc' '--localstatedir=/var' '--libexecdir=${prefix}/lib/squid3' '--disable-maintainer-mode' '--disable-dependency-tracking' '--srcdir=.' '--datadir=/usr/share&lt;br /&gt;
 /squid3' '--sysconfdir=/etc/squid3' '--mandir=/usr/share/man' '--with-cppunit-basedir=/usr' '--enable-inline' '--enable-async-io=8' '--enable-storeio=ufs,aufs,diskd,null' &lt;br /&gt;
 '--enable-removal-policies=lru,heap' '--enable-delay-pools' '--enable-cache-digests' '--enable-underscores' '--enable-icap-client' '--enable-follow-x-forwarded-for' '--enable-&lt;br /&gt;
 auth=basic,digest,ntlm,negotiate' '--enable-basic-auth-helpers=LDAP,MSNT,NCSA,PAM,SASL,SMB,YP,getpwnam,multi-domain-NTLM' '--enable-ntlm-auth-helpers=SMB' '--enable-digest-&lt;br /&gt;
 auth-helpers=ldap,password' '--enable-negotiate-auth-helpers=squid_kerb_auth' '--enable-external-acl-helpers=ip_user,ldap_group,session,unix_group,wbinfo_group' '--enable-&lt;br /&gt;
 arp-acl' '--enable-snmp' '--with-filedescriptors=65536' '--with-large-files' '--with-default-user=proxy' '--enable-epoll' '--enable-linux-netfilter' 'build_alias=i486-&lt;br /&gt;
 linux-gnu' 'CC=cc' 'CFLAGS=-g -O2 -g -Wall -O2' 'LDFLAGS=-Wl,-Bsymbolic-functions' 'CPPFLAGS=' 'CXX=g++' 'CXXFLAGS=-g -O2 -g -Wall -O2' 'FFLAGS=-g -O2'&lt;br /&gt;
&lt;br /&gt;
==Recompilar el paquet Debian==&lt;br /&gt;
&lt;br /&gt;
Amb [[apt-get]] es molt senzill instal·lar una aplicació compilant-la:&lt;br /&gt;
&lt;br /&gt;
 $ cd [[/usr/src]]&lt;br /&gt;
 $ [[sudo]] apt-get build-dep squid3&lt;br /&gt;
 $ sudo apt-get -b source squid3&lt;br /&gt;
 $ sudo apt-get install squid-langpack&lt;br /&gt;
 $ sudo [[dpkg]] -i squid*.deb&lt;br /&gt;
&lt;br /&gt;
Fixeu-vos que ha creat varios paquets Debian:&lt;br /&gt;
&lt;br /&gt;
 $ [[ls]] *deb&lt;br /&gt;
 squid3_3.0.STABLE18-1_i386.deb      squid3-common_3.0.STABLE18-1_all.deb  squidclient_3.0.STABLE18-1_i386.deb&lt;br /&gt;
 squid3-cgi_3.0.STABLE18-1_i386.deb  squid3-dbg_3.0.STABLE18-1_i386.deb&lt;br /&gt;
&lt;br /&gt;
Per a més detalls consulteu [[Apt-get#opci.C3.B3_source|apt-get opció source]]&lt;br /&gt;
&lt;br /&gt;
Podeu controlar el procés de creació del [[Paquet Debian]] editant un fitxer:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[joe]] squid3-3.0.STABLE18/debian/rules&lt;br /&gt;
&lt;br /&gt;
I per exemple afegir el suport per a fer log del user agent (navegadors). Afegiu:&lt;br /&gt;
&lt;br /&gt;
 [[--enable-useragent-log]] \&lt;br /&gt;
&lt;br /&gt;
Per exemple, ha de quedar:&lt;br /&gt;
&lt;br /&gt;
 DEB_CONFIGURE_EXTRA_FLAGS := --datadir=/usr/share/squid3 \&lt;br /&gt;
                --sysconfdir=/etc/squid3 \&lt;br /&gt;
                --mandir=/usr/share/man \&lt;br /&gt;
                --with-cppunit-basedir=/usr \&lt;br /&gt;
                --enable-inline \&lt;br /&gt;
                --enable-async-io=8 \&lt;br /&gt;
                --enable-storeio=&amp;quot;ufs,aufs,diskd,null&amp;quot; \&lt;br /&gt;
                --enable-removal-policies=&amp;quot;lru,heap&amp;quot; \&lt;br /&gt;
                --enable-delay-pools \&lt;br /&gt;
                --enable-cache-digests \&lt;br /&gt;
                --enable-underscores \&lt;br /&gt;
                --enable-icap-client \&lt;br /&gt;
                --enable-follow-x-forwarded-for \&lt;br /&gt;
                --enable-auth=&amp;quot;basic,digest,ntlm,negotiate&amp;quot; \&lt;br /&gt;
                --enable-basic-auth-helpers=&amp;quot;LDAP,MSNT,NCSA,PAM,SASL,SMB,YP,getpwnam,multi-domain-NTLM&amp;quot; \&lt;br /&gt;
                --enable-ntlm-auth-helpers=&amp;quot;SMB&amp;quot; \&lt;br /&gt;
                --enable-digest-auth-helpers=&amp;quot;ldap,password&amp;quot; \&lt;br /&gt;
                --enable-negotiate-auth-helpers=&amp;quot;squid_kerb_auth&amp;quot; \  &lt;br /&gt;
                --enable-external-acl-helpers=&amp;quot;ip_user,ldap_group,session,unix_group,wbinfo_group&amp;quot; \&lt;br /&gt;
                --enable-arp-acl \&lt;br /&gt;
                --enable-snmp \&lt;br /&gt;
                '''--enable-useragent-log \'''&lt;br /&gt;
                --with-filedescriptors=65536 \&lt;br /&gt;
                --with-large-files \&lt;br /&gt;
                --with-default-user=proxy&lt;br /&gt;
&lt;br /&gt;
{{nota| Si es vol activar --enable-ssl \ aleshores cal instal·lar abans:&lt;br /&gt;
 $ sudo apt-get install libssl-dev}}&lt;br /&gt;
&lt;br /&gt;
Si instal·leu el paquet nou ara veure:&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install squid-langpack&lt;br /&gt;
 $ sudo dpkg -i squid*.deb&lt;br /&gt;
&lt;br /&gt;
Ara podeu comprovar que té activat useragent&lt;br /&gt;
&lt;br /&gt;
 $ squid3 -v | grep agent&lt;br /&gt;
 ...&lt;br /&gt;
 acl-helpers=ip_user,ldap_group,session,unix_group,wbinfo_group' '--enable-arp-acl' '--enable-snmp' ''''--enable-useragent-log'''' '--with-filedescriptors=65536' &lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
:*http://www.howtoforge.com/how-to-rebuild-the-squid-2.6-debian-package-with-support-for-x-forwarded-for-headers&lt;br /&gt;
&lt;br /&gt;
=Configuració=&lt;br /&gt;
&lt;br /&gt;
==Manual==&lt;br /&gt;
&lt;br /&gt;
Segons la versió hi ha diferents manuals que podeu trobar a:&lt;br /&gt;
&lt;br /&gt;
 http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#Do_you_have_a_squid.conf_example.3F&lt;br /&gt;
&lt;br /&gt;
Per a 3.0 el trobareu a:&lt;br /&gt;
&lt;br /&gt;
 http://www.squid-cache.org/Versions/v3/3.0/cfgman/&lt;br /&gt;
&lt;br /&gt;
==Configuració del client del proxy (Proxy no transparent). Navegador web Firefox==&lt;br /&gt;
&lt;br /&gt;
 Consulteu [[Configuració_de_clients_proxy]].&lt;br /&gt;
&lt;br /&gt;
Anem al menú '''Edita/Preferències''':&lt;br /&gt;
&lt;br /&gt;
Seleccionem la pestanya '''Avançat''' i després la pestanya '''Xarxa''':&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidNavegador.png]]&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidNavegador2.png]]&lt;br /&gt;
&lt;br /&gt;
'''NOTA''': El port normalment és el '''3186''':&lt;br /&gt;
&lt;br /&gt;
 $ sudo nmap localhost&lt;br /&gt;
 Starting Nmap 4.20 ( http://insecure.org ) at 2007-11-18 20:19 CET&lt;br /&gt;
 Interesting ports on localhost (127.0.0.1):&lt;br /&gt;
 Not shown: 1687 closed ports&lt;br /&gt;
 PORT      STATE SERVICE&lt;br /&gt;
 22/tcp    open  ssh&lt;br /&gt;
 23/tcp    open  telnet&lt;br /&gt;
 80/tcp    open  http&lt;br /&gt;
 139/tcp   open  netbios-ssn&lt;br /&gt;
 445/tcp   open  microsoft-ds&lt;br /&gt;
 631/tcp   open  ipp&lt;br /&gt;
 '''3128/tcp  open  squid-http'''&lt;br /&gt;
 3306/tcp  open  mysql&lt;br /&gt;
 4662/tcp  open  edonkey&lt;br /&gt;
 10000/tcp open  snet-sensor-mgmt&lt;br /&gt;
&lt;br /&gt;
Si no em configurat les ACL molt possiblement rebrem un error com el següent a l'intentar navegar:&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidNoPermetAccedir.png]]&lt;br /&gt;
&lt;br /&gt;
El següent apartat explica com configurar les ACL.&lt;br /&gt;
&lt;br /&gt;
====Autoconfiguració de proxys amb DHCP====&lt;br /&gt;
&lt;br /&gt;
 Consulteu http://wiki.squid-cache.org/SquidFaq/ConfiguringBrowsers#head-5aa28de5e8308087a925cb7ef54ca070a16564d4&lt;br /&gt;
&lt;br /&gt;
Fitxer '''proxy.cat''':&lt;br /&gt;
&lt;br /&gt;
 function FindProxyForURL(url, host)&lt;br /&gt;
 {&lt;br /&gt;
    if (isPlainHostName(host) ||&lt;br /&gt;
        dnsDomainIs(host, &amp;quot;.foobar&amp;quot;))&lt;br /&gt;
        return &amp;quot;DIRECT&amp;quot;;&lt;br /&gt;
     else&lt;br /&gt;
         if (isInNet(myIpAddress(), &amp;quot;192.168.1.3&amp;quot;, &amp;quot;255.255.0.0&amp;quot;))&lt;br /&gt;
             return &amp;quot;PROXY 192.168.1.3:3128; DIRECT&amp;quot;;&lt;br /&gt;
         else&lt;br /&gt;
             return &amp;quot;DIRECT&amp;quot;;&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
Un altre...&lt;br /&gt;
&lt;br /&gt;
 function FindProxyForURL (url,host)&lt;br /&gt;
 	{ if ((url.substring(0,5) != &amp;quot;http:&amp;quot;) &amp;amp;&amp;amp; &lt;br /&gt;
 	      (url.substring(0,6) != &amp;quot;https:&amp;quot;) &amp;amp;&amp;amp;&lt;br /&gt;
 	      (url.substring(0,4) != &amp;quot;ftp:&amp;quot;) &amp;amp;&amp;amp;&lt;br /&gt;
 	      (url.substring(0,7) != &amp;quot;gopher:&amp;quot;)) {&lt;br /&gt;
 	      return &amp;quot;DIRECT&amp;quot;; &lt;br /&gt;
 	      }&lt;br /&gt;
 	  if (isPlainHostName(host) || shExpMatch(host,&amp;quot;192.168.*&amp;quot;) || shExpMatch(host,&amp;quot;127.*&amp;quot;) || dnsDomainIs(host,&amp;quot;correu.edu365.com&amp;quot;) || &lt;br /&gt;
 dnsDomainIs  (host,&amp;quot;.intranet&amp;quot;) || (url.substring(11,23) == &amp;quot;xtec.es:8800&amp;quot;) || dnsDomainIs (host,&amp;quot;xat.edu365.com&amp;quot;) || dnsDomainIs &lt;br /&gt;
 (host,&amp;quot;.gencat.net&amp;quot;)  || dnsDomainIs (host,&amp;quot;.gencat.es&amp;quot;)) {&lt;br /&gt;
 	      	 return &amp;quot;DIRECT&amp;quot;;&lt;br /&gt;
               } &lt;br /&gt;
 	  else&lt;br /&gt;
 	  	return &amp;quot;PROXY 192.168.0.2:8080; PROXY proxy.xtec.es:8080; DIRECT&amp;quot;; &lt;br /&gt;
 	}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Aquest fitxer es penja a Internet, i permet configurar els proxys automàticament.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://www.xtec.cat/~mcguri/index_proxy.html&lt;br /&gt;
*http://www.xtec.cat/~mcguri/proxypac.txt&lt;br /&gt;
*http://squidproxy.wordpress.com/category/proxypac/&lt;br /&gt;
*http://homepages.tesco.net/J.deBoynePollard/FGA/web-browser-auto-proxy-configuration.html&lt;br /&gt;
*http://en.wikipedia.org/wiki/Proxy_auto-config&lt;br /&gt;
*http://www.hostsfile.org/pac.html&lt;br /&gt;
*http://en.wikipedia.org/wiki/Proxy_auto-config&lt;br /&gt;
**http://www.davidpashley.com/articles/automatic-proxy.html&lt;br /&gt;
&lt;br /&gt;
====Configuració del proxy amb DHCP. Segona part====&lt;br /&gt;
&lt;br /&gt;
 TODO&lt;br /&gt;
&lt;br /&gt;
Exemple IES Nicolau Copèrnic:&lt;br /&gt;
&lt;br /&gt;
  function FindProxyForURL(url, host)&lt;br /&gt;
   {&lt;br /&gt;
      if (isInNet(host, &amp;quot;192.168.0.0&amp;quot;, &amp;quot;255.255.0.0&amp;quot;)) {&lt;br /&gt;
        return &amp;quot;DIRECT&amp;quot;;&lt;br /&gt;
    } else {&lt;br /&gt;
       if (shExpMatch(url, &amp;quot;http:*&amp;quot;))&lt;br /&gt;
          return &amp;quot;PROXY 192.168.11.1:800&amp;quot; ;&lt;br /&gt;
       if (shExpMatch(url, &amp;quot;https:*&amp;quot;))&lt;br /&gt;
          return &amp;quot;PROXY 192.168.11.1:800&amp;quot; ;&lt;br /&gt;
       if (shExpMatch(url, &amp;quot;ftp:*&amp;quot;))&lt;br /&gt;
          return &amp;quot;PROXY 192.168.11.1:800&amp;quot; ;&lt;br /&gt;
       return &amp;quot;DIRECT&amp;quot;;&lt;br /&gt;
    }&lt;br /&gt;
 }&lt;br /&gt;
&lt;br /&gt;
El col·loques a:&lt;br /&gt;
&lt;br /&gt;
 http://www.iescopernic.com/proxy.pac&lt;br /&gt;
&lt;br /&gt;
Servidor de DHCP:&lt;br /&gt;
&lt;br /&gt;
 option local-pac-server code 252 = text;&lt;br /&gt;
 option local-pac-server &amp;quot;http://www.iescopernic.com/wpad.dat&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
O (recurs ecualug):&lt;br /&gt;
&lt;br /&gt;
 # Configuracion automatica de proxy&lt;br /&gt;
 option wpad-url code 252 = text;&lt;br /&gt;
 option wpad-url &amp;quot;http://wpad.midominio.com:81/proxy.pac\n&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Recursos'''&lt;br /&gt;
*http://www.davidpashley.com/articles/automatic-proxy.html&lt;br /&gt;
*http://wp.netscape.com/eng/mozilla/2.0/relnotes/demo/proxy-live.html&lt;br /&gt;
*http://www.ecualug.org/?q=2008/07/02/comos/parte_3_el_servidor_dhcp_y_dns_dinamico&lt;br /&gt;
&lt;br /&gt;
==Configuració del servidor==&lt;br /&gt;
&lt;br /&gt;
===Fitxer de configuració. /etc/squid/squid3.conf===&lt;br /&gt;
&lt;br /&gt;
Els fitxers de configuració són:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L squid3 | grep etc&lt;br /&gt;
 /etc&lt;br /&gt;
 /etc/[[logrotate]].d&lt;br /&gt;
 /etc/logrotate.d/squid3&lt;br /&gt;
 /etc/squid3&lt;br /&gt;
 [[/etc/squid3/squid.conf]]&lt;br /&gt;
 /etc/squid3/msntauth.conf&lt;br /&gt;
 /etc/resolvconf.d&lt;br /&gt;
 /etc/resolvconf.d/update-libc.d&lt;br /&gt;
 [[/etc/resolvconf.d/update-libc.d/squid3]]&lt;br /&gt;
 /etc/init.d&lt;br /&gt;
 [[/etc/init.d/squid3]]&lt;br /&gt;
&lt;br /&gt;
El fitxer important de configuració és:&lt;br /&gt;
&lt;br /&gt;
 [[/etc/squid3/squid.conf]]&lt;br /&gt;
&lt;br /&gt;
Per defecte el fitxer conté molts camps de comentari que podeu eliminar amb l'ordre [[grep]]:&lt;br /&gt;
&lt;br /&gt;
 $ cat squid.conf | grep -v '^#\|^$\|^;'&lt;br /&gt;
&lt;br /&gt;
El fitxer per defecte de configuració conté el següent:&lt;br /&gt;
&lt;br /&gt;
 $ cat squid.conf | grep -v '^#\|^$\|^;'&lt;br /&gt;
 acl manager proto cache_object&lt;br /&gt;
 acl localhost src 127.0.0.1/32&lt;br /&gt;
 acl to_localhost dst 127.0.0.0/8&lt;br /&gt;
 acl SSL_ports port 443&lt;br /&gt;
 acl Safe_ports port 80		# http&lt;br /&gt;
 acl Safe_ports port 21		# ftp&lt;br /&gt;
 acl Safe_ports port 443		# https&lt;br /&gt;
 acl Safe_ports port 70		# gopher&lt;br /&gt;
 acl Safe_ports port 210		# wais&lt;br /&gt;
 acl Safe_ports port 1025-65535	# unregistered ports&lt;br /&gt;
 acl Safe_ports port 280		# http-mgmt&lt;br /&gt;
 acl Safe_ports port 488		# gss-http&lt;br /&gt;
 acl Safe_ports port 591		# filemaker&lt;br /&gt;
 acl Safe_ports port 777		# multiling http&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 http_access allow manager localhost&lt;br /&gt;
 http_access deny manager&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access deny all&lt;br /&gt;
 icp_access deny all&lt;br /&gt;
 htcp_access deny all&lt;br /&gt;
 http_port 3128&lt;br /&gt;
 hierarchy_stoplist cgi-bin ?&lt;br /&gt;
 access_log /var/log/squid3/access.log squid&lt;br /&gt;
 refresh_pattern ^ftp:		1440	20%	10080&lt;br /&gt;
 refresh_pattern ^gopher:	1440	0%	1440&lt;br /&gt;
 refresh_pattern (cgi-bin|\?)	0	0%	0&lt;br /&gt;
 refresh_pattern .		0	20%	4320&lt;br /&gt;
 icp_port 3130&lt;br /&gt;
 coredump_dir /var/spool/squid3&lt;br /&gt;
&lt;br /&gt;
Podeu consultar la referència dels paràmetres d'Squid al manual:&lt;br /&gt;
&lt;br /&gt;
*http://www.squid-cache.org/Versions/v3/3.0/cfgman/&lt;br /&gt;
*http://wiki.squid-cache.org/Features&lt;br /&gt;
&lt;br /&gt;
Comentem línia a línia el fitxer per defecte. Les línies '''acl''':&lt;br /&gt;
&lt;br /&gt;
 [http://www.squid-cache.org/Versions/v3/3.0/cfgman/acl.html acl] manager proto cache_object&lt;br /&gt;
 acl localhost src 127.0.0.1/32&lt;br /&gt;
 acl to_localhost dst 127.0.0.0/8&lt;br /&gt;
 acl SSL_ports port 443&lt;br /&gt;
 acl Safe_ports port 80		# http&lt;br /&gt;
 acl Safe_ports port 21		# ftp&lt;br /&gt;
 acl Safe_ports port 443		# https&lt;br /&gt;
 acl Safe_ports port 70		# gopher&lt;br /&gt;
 acl Safe_ports port 210		# wais&lt;br /&gt;
 acl Safe_ports port 1025-65535	# unregistered ports&lt;br /&gt;
 acl Safe_ports port 280		# http-mgmt&lt;br /&gt;
 acl Safe_ports port 488		# gss-http&lt;br /&gt;
 acl Safe_ports port 591		# filemaker&lt;br /&gt;
 acl Safe_ports port 777		# multiling http&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
&lt;br /&gt;
Defineixen elements [[ACL]] (Accés Control List). La sintaxi és la següent:&lt;br /&gt;
&lt;br /&gt;
 acl aclname acltype argument ...&lt;br /&gt;
 acl aclname acltype &amp;quot;file&amp;quot; ...&lt;br /&gt;
&lt;br /&gt;
On&lt;br /&gt;
:*'''acl_name''': És el nom que li donem a la llista d'accés&lt;br /&gt;
:*'''acl_type''': indica el tipus de llista. Hi han molts tipus de llista que podeu consultar al [http://www.squid-cache.org/Versions/v3/3.0/cfgman/acl.html manual] (també podeu consultar els desplegables de [[webmin]]). Algunes de les més important permeten declarar adreces IP, rangs d'adreces, MACs, URLs, expressions regulats, ports, etc.&lt;br /&gt;
:*'''argument''': Segons el tipus de llista pot ser un text, una IP, una MAC, una expressió regular, una URL, un mime-type...&lt;br /&gt;
:*'''file''': Es pot indicar un fitxer on trobar les acl (una per línia)&lt;br /&gt;
&lt;br /&gt;
Alguns exemples:&lt;br /&gt;
&lt;br /&gt;
 acl macaddress arp 09:00:2b:23:45:67&lt;br /&gt;
 acl myexample dst_as 1241&lt;br /&gt;
 acl password proxy_auth REQUIRED&lt;br /&gt;
 acl fileupload req_mime_type -i ^multipart/form-data$&lt;br /&gt;
 acl javascript rep_mime_type -i ^application/x-javascript$&lt;br /&gt;
&lt;br /&gt;
Consulteu l'apartat [[#ACLs]] per tal d'obtenir més informació.&lt;br /&gt;
&lt;br /&gt;
Tornant al fitxer bàsic de configuració. La primera línia:&lt;br /&gt;
&lt;br /&gt;
 acl manager proto cache_object&lt;br /&gt;
&lt;br /&gt;
Defineix un acl de tipus proto (protocol) anomenada manager amb argument cache_object. El protocol cache_object és el protocol que utilitza l'eina [[Squid#cachemgr | cachemgr]] per accedir a squid. La següent acl:&lt;br /&gt;
 &lt;br /&gt;
 acl localhost src 127.0.0.1/32&lt;br /&gt;
&lt;br /&gt;
Defineix que és localhost. Les acl es declaren per tal de ser utilitzades per altres directives en línies posteriors del fitxer de configuració. Per exemple les acl localhost i manager s'utilitzen a:&lt;br /&gt;
&lt;br /&gt;
 http_access allow manager localhost&lt;br /&gt;
 ...&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access deny all&lt;br /&gt;
&lt;br /&gt;
Recordeu que les acces entry són ANDs i per tant:&lt;br /&gt;
&lt;br /&gt;
 http_access allow manager localhost&lt;br /&gt;
 http_access deny manager&lt;br /&gt;
&lt;br /&gt;
Només permet les consultes de [Squid#cachemgr | cachemgr]] des de localhost (la resta estan impedides per la línia deny). Després permetem utilitzar el proxy squid a la màquina localhost i deneguem la resta&lt;br /&gt;
&lt;br /&gt;
{{nota|Tingueu doncs en compte, que per defecte la configuració d'Squid no ens permet utilitzar el servidor des de altres màquines de la xarxa. Consulteu [[Squid#Com_definir_quins_seran_els_clients_que_podran_utilitzar_el_servidor_Squid|Com_definir_quins_seran_els_clients_que_podran_utilitzar_el_servidor_Squid]]. Cal tenir en compte que el port sortirà obert però no passarem les ACL del servidor}}&lt;br /&gt;
&lt;br /&gt;
El següent element ACL és defineix però no s'utilitza:&lt;br /&gt;
&lt;br /&gt;
 acl to_localhost dst 127.0.0.0/8&lt;br /&gt;
&lt;br /&gt;
La següent línia és necessària per al correcte funcionament de les connexions HTTPS a través del Proxy:&lt;br /&gt;
&lt;br /&gt;
 acl SSL_ports port 443&lt;br /&gt;
&lt;br /&gt;
El protocol [[HTTP]] té diferents [[http://en.wikipedia.org/wiki/Hypertext_Transfer_Protocol#Request_methods Request methods]]. Els més coneguts són GET, POST i HEAD. Però el protocol [[HTTPS] no pot ser caxejat i per tant amb aquest port s'utilitza el Request Method '''CONNECT''' que el que fa és un túnel directe, Més endavant al fitxer trobem les directives:&lt;br /&gt;
&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
Que només permet utilitzar el metode HTTP '''CONNECT''' al port 443.&lt;br /&gt;
&lt;br /&gt;
Algunes ACL poden ser llistes d'ítems. Per exemple:&lt;br /&gt;
&lt;br /&gt;
 acl Safe_ports port 80		# http&lt;br /&gt;
 acl Safe_ports port 21		# ftp&lt;br /&gt;
 acl Safe_ports port 443		# https&lt;br /&gt;
 acl Safe_ports port 70		# gopher&lt;br /&gt;
 acl Safe_ports port 210		# wais&lt;br /&gt;
 acl Safe_ports port 1025-65535	# unregistered ports&lt;br /&gt;
 acl Safe_ports port 280		# http-mgmt&lt;br /&gt;
 acl Safe_ports port 488		# gss-http&lt;br /&gt;
 acl Safe_ports port 591		# filemaker&lt;br /&gt;
 acl Safe_ports port 777		# multiling http&lt;br /&gt;
&lt;br /&gt;
Defineix una llista de ports anomenada '''Safe_ports'''. Més endavant al fitxer de configuració:&lt;br /&gt;
 &lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
&lt;br /&gt;
Impedeix l'accés HTTP a qualsevol port que no sigui un dels especificats com a segurs. Això és així per tal d'evitar usos il·lícits d'Squid com per exemple utilitzar-lo de relay SMTP. A la [http://wiki.squid-cache.org/SquidFaq/SquidAcl#Why_does_Squid_deny_some_port_numbers.3F wiki d'Squid] expliquen amb més detall per que certs ports poden ser insegurs.&lt;br /&gt;
&lt;br /&gt;
Després trobem les directives:&lt;br /&gt;
&lt;br /&gt;
 icp_access deny all&lt;br /&gt;
 htcp_access deny all&lt;br /&gt;
&lt;br /&gt;
Per defecte no estan activats els protocols per a fer Cache distribuït. Els protocols són [[ICP]] i [[HTCP]]. De totes maneres més endavant s'indica el port ICP:&lt;br /&gt;
&lt;br /&gt;
 icp_port 3130&lt;br /&gt;
&lt;br /&gt;
La directiva:&lt;br /&gt;
 &lt;br /&gt;
 http_port 3128&lt;br /&gt;
&lt;br /&gt;
Defineix el port al qual escolta peticions el servidor Squid.&lt;br /&gt;
&lt;br /&gt;
La directiva: &lt;br /&gt;
&lt;br /&gt;
 access_log [[/var/log/squid3/access.log]] squid&lt;br /&gt;
&lt;br /&gt;
Defineix a on es guarda el log d'acces. Aquí Squid registra tots els accessos al servidor i és el fitxer bàsic per a realitzar informes del proxy.&lt;br /&gt;
&lt;br /&gt;
Les directives:&lt;br /&gt;
&lt;br /&gt;
 [ hierarchy_stoplist] cgi-bin ?&lt;br /&gt;
&lt;br /&gt;
Després venen les indicacions &lt;br /&gt;
 [http://www.squid-cache.org/Versions/v3/3.0/cfgman/refresh_pattern.html refresh_pattern] ^ftp:		1440	20%	10080&lt;br /&gt;
 refresh_pattern ^gopher:	1440	0%	1440&lt;br /&gt;
 refresh_pattern (cgi-bin|\?)	0	0%	0&lt;br /&gt;
 refresh_pattern .		0	20%	4320&lt;br /&gt;
&lt;br /&gt;
La sintaxi de refresh_pattern és:&lt;br /&gt;
&lt;br /&gt;
 refresh_pattern [-i] regex min percent max [options]&lt;br /&gt;
&lt;br /&gt;
On:&lt;br /&gt;
&lt;br /&gt;
:*'''regex''': s'utilitzen [[expressions regulars]] (per defecte són case-sensitive, es pot desactivar amb l'opció -i).&lt;br /&gt;
:*'''Min''': és el temps en minuts que un objecte sense un temps d'expiració implícit pot ser considerat un objecte fresc. El valor recomanat és 0, qualsevol altre valor pot provocar que les aplicacions dinàmiques no funcionin correctament si el programador de l'aplicació no ha establert explícitament el temps d'expiració.&lt;br /&gt;
:*'''Percent''': és el percentatge de temps respecte a l'edat de l'objecte (temps des de la última modificació) que un objecte sense un temps explícit d'expiració pot ser considerat un objecte fresc.&lt;br /&gt;
:*'''Max''': defineix quina és la edat màxima del objecte per tal de poder-lo considerar fresc&lt;br /&gt;
:*'''Opcions''':&lt;br /&gt;
::* override-expire&lt;br /&gt;
::* override-lastmod&lt;br /&gt;
::* reload-into-ims&lt;br /&gt;
::* ignore-reload&lt;br /&gt;
::* ignore-no-cache&lt;br /&gt;
::* ignore-no-store&lt;br /&gt;
::* ignore-private&lt;br /&gt;
::* ignore-auth&lt;br /&gt;
::* refresh-ims&lt;br /&gt;
&lt;br /&gt;
Per tant:&lt;br /&gt;
&lt;br /&gt;
 refresh_pattern ^ftp:		1440	20%	10080&lt;br /&gt;
&lt;br /&gt;
Controla quan es refresquen les peticions a una URL amb el protocol FTP (^ indica inici de la url). 1440 és un dia (24 hores) en minuts. Són els valor estàndard del protocol FTP. El mateix pel protocol [[gopher]]:&lt;br /&gt;
&lt;br /&gt;
 refresh_pattern ^gopher:	1440	0%	1440&lt;br /&gt;
&lt;br /&gt;
Les pàgines dinàmiques ([[CGI]]) no tenen cache:&lt;br /&gt;
&lt;br /&gt;
 refresh_pattern (cgi-bin|\?)	0	0%	0&lt;br /&gt;
&lt;br /&gt;
La resta:&lt;br /&gt;
&lt;br /&gt;
 refresh_pattern .		0	20%	4320&lt;br /&gt;
&lt;br /&gt;
És a dir que:&lt;br /&gt;
&lt;br /&gt;
 Si no hi ha temps d'expiració indicat aleshores es torna a demanar l'objecte&lt;br /&gt;
 Si hi ha data explicita&lt;br /&gt;
 La edat màxima d'un objecte és 3 dies (7320 minuts) i es pot considerar fresc un màxim del 205 (14,4h)&lt;br /&gt;
&lt;br /&gt;
el protocol per definir si un fitxer de la cache és fresc (FRESH) o no (STALE) és:&lt;br /&gt;
&lt;br /&gt;
 FRESH if expires &amp;lt; now, else STALE&lt;br /&gt;
 STALE if age &amp;gt; max&lt;br /&gt;
 FRESH if lm-factor &amp;lt; percent, else STALE&lt;br /&gt;
 FRESH if age &amp;lt; min&lt;br /&gt;
 else STALE&lt;br /&gt;
&lt;br /&gt;
I finalment hi ha la directiva d'on posar els core_dumps (en cas que succeixin)&lt;br /&gt;
&lt;br /&gt;
 [http://www.squid-cache.org/Versions/v3/3.0/cfgman/coredump_dir.html coredump_dir] /var/spool/squid3&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#Do_you_have_a_squid.conf_example.3F&lt;br /&gt;
&lt;br /&gt;
===Modificar el fitxer de configuració===&lt;br /&gt;
&lt;br /&gt;
És més còmode treballar amb un fitxer sens comentaris. Fer una còpia de l'original i elimineu els comentaris amb:&lt;br /&gt;
&lt;br /&gt;
 $ cd /etc/squid3&lt;br /&gt;
 $ sudo cp squid.conf squid.conf.reference&lt;br /&gt;
 $ sudo bash -c &amp;quot;cat squid.conf | grep -i -v '^#\|^$\|^;' &amp;gt;  squid.conf.backup&amp;quot;&lt;br /&gt;
 $ sudo mv squid.conf.backup squid.conf&lt;br /&gt;
&lt;br /&gt;
Cada cop que modifiqueu el fitxer comproveu la sintaxi amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo squid3 -k parse&lt;br /&gt;
&lt;br /&gt;
I aplique els canvis amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/init.d/squid3 reload&lt;br /&gt;
&lt;br /&gt;
===Com definir quins seran els clients que podran utilitzar el servidor Squid===&lt;br /&gt;
&lt;br /&gt;
Cal definir una ACL com per exemple:&lt;br /&gt;
&lt;br /&gt;
 acl myclients src 192.168.0.0/24&lt;br /&gt;
&lt;br /&gt;
I utilitzar una llista d'accés http:&lt;br /&gt;
&lt;br /&gt;
 http_access allow myclients&lt;br /&gt;
&lt;br /&gt;
===ACLs===&lt;br /&gt;
&lt;br /&gt;
Les [[ACL]] (Accés Control List) defineixen les tasquest que es poden realitzar en un servidor Squid. Cal tenir en compte que tenim:&lt;br /&gt;
&lt;br /&gt;
:*'''Elements ACL (ACL elements)''': es defineixen elements amb la directiva acl. Faciliten la definició d'ACLs&lt;br /&gt;
:*'''Llistes d'accés (ACL) (access entry)'''': hi ha una sèrie de directives per definir que es pot fer i que no. També s'anomenen acces_entry. Més aval les podeu consultar.&lt;br /&gt;
&lt;br /&gt;
Per definir els elements ACL la sintaxi és:&lt;br /&gt;
&lt;br /&gt;
 acl aclname acltype argument ...&lt;br /&gt;
 acl aclname acltype &amp;quot;file&amp;quot; ...&lt;br /&gt;
&lt;br /&gt;
On&lt;br /&gt;
:*'''acl_name''': És el nom que li donem a la llista d'accés&lt;br /&gt;
:*'''acl_type''': indica el tipus de llista. Hi han molts tipus de llista que podeu consultar al [http://www.squid-cache.org/Versions/v3/3.0/cfgman/acl.html manual] (també podeu consultar els desplegables de [[webmin]]). Algunes de les més important permeten declarar adreces IP, rangs d'adreces, MACs, URLs, expressions regulats, ports, etc.&lt;br /&gt;
:*'''argument''': Segons el tipus de llista pot ser un text, una IP, una MAC, una expressió regular, una URL, un mime-type... Podeu consultar tots els tipus a la [http://wiki.squid-cache.org/SquidFaq/SquidAcl#ACL_elements wiki de Squid].&lt;br /&gt;
:*'''file''': Es pot indicar un fitxer on trobar les acl (una entrada per línia)&lt;br /&gt;
&lt;br /&gt;
Alguns exemples:&lt;br /&gt;
&lt;br /&gt;
 acl macaddress arp 09:00:2b:23:45:67&lt;br /&gt;
 acl myexample dst_as 1241&lt;br /&gt;
 acl password proxy_auth REQUIRED&lt;br /&gt;
 acl fileupload req_mime_type -i ^multipart/form-data$&lt;br /&gt;
 acl javascript rep_mime_type -i ^application/x-javascript$&lt;br /&gt;
&lt;br /&gt;
Posteriorment cal definir la ACL amb alguna de les següents directives:&lt;br /&gt;
&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/http_access/ http_access]''': permet als clients especificats (navegadors) accedir al port de l'Squid. Aquesta és la forma principal de controlar l'accés a Squid. Es poden fer controls per IP, per rangs d'adreces, per tipus de navegador, per MAC...&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/http_reply_access http_reply_access]''': Permet als clients HTTP (navegadors) rebre la resposta a la petició (request) que han realitzat. S'utilitza per bloquejar certs continguts com p. ex. diferents tipus de continguts segons el seu mime-type ( directiva rep_mime_type acl).&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/icp_access icp_access]''': Permet a altres caches (p. ex. altres Squid) accedir a la cache del servidor mitjançant el protocol ICP.&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/miss_access miss_access]''': miss_access: Permet a certs clients reenviar els fitxers que falten a la cache (cache MISSES). Serveix per treballar amb caches distribuïdes.&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/cache cache]''': Defineix respostes que no han de ser catxejades.&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/url_rewrite_access url_rewrite_access]''': Controla quines peticions s'envien al redirector pool&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/ident_lookup_access ident_lookup_access]''': Controla quines peticions necessiten d'una cerca Ident (Ident looku).&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/always_direct always_direct]''': Controla quines peticions s'han d'enviar sempre directament als servidors originals de la petició. &lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/never_direct never_direct]''': Contrari de l'anterior. Quines peticions no s'han d'enviar mai directament al servidor original&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/snmp_access snmp_access]''': Controla l'accés de clients [[snmp]].&lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/broken_posts broken_posts]''': &lt;br /&gt;
:*'''[http://www.squid-cache.org/Doc/config/cache_peer_access cache_peer_access]''': Serveix per treballar amb memòries cau distribuïdes.&lt;br /&gt;
&lt;br /&gt;
Qüestions a tenir en compte:&lt;br /&gt;
&lt;br /&gt;
*No es poden definir dos ACL amb el mateix nom&lt;br /&gt;
*Es poden definir diferents valors un per línia. Squid els converteix en una llista.&lt;br /&gt;
*No tots els elements ACL els podrem utilitzar en tots les tasques de control d'accés. Per exemple la snmp_community només té sentit am snmp_access&lt;br /&gt;
*Per utilitzar MACs cal fer servir l'opció --enable-arp-acl. &lt;br /&gt;
*Els elements ACL de SNMP requereixen: --enable-snmp&lt;br /&gt;
*Algunes ACL poden provocar retards en els temps de resposta. Per exemple utilitzar noms de màquina (src_domain i srcdom_regex) fan consultes DNS.&lt;br /&gt;
*Les llistes ACL són de tipus OR. En cas que hi haguí més d'un element la llista es compleix si almenys es compleix un dels elements&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
http://wiki.squid-cache.org/SquidFaq/SquidAcl&lt;br /&gt;
&lt;br /&gt;
==== Llista completa de ACLs ====&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
&lt;br /&gt;
 http://wiki.squid-cache.org/SquidFaq/SquidAcl#ACL_elements&lt;br /&gt;
&lt;br /&gt;
====Entendre les ACL. Com combinar ACLs====&lt;br /&gt;
&lt;br /&gt;
Cal tenir en compte que tenim:&lt;br /&gt;
&lt;br /&gt;
:*'''Elements ACL (ACL elements)''': tots els elements definits a una llista són ORs.&lt;br /&gt;
:*'''Llistes d'accés (ACL) o acces entry''': tots els elements definits són ANDs.&lt;br /&gt;
&lt;br /&gt;
{{nota| No es poden utilitzar doncs altres combinacions d'ORs o ANDs.}}&lt;br /&gt;
&lt;br /&gt;
Un exemple que no funciona:&lt;br /&gt;
&lt;br /&gt;
 acl ME src 10.0.0.1&lt;br /&gt;
 acl YOU src 10.0.0.2 &lt;br /&gt;
 http_access allow ME YOU&lt;br /&gt;
&lt;br /&gt;
http_access allow és una accés entry i per tant ME i YOU són un AND, és a dir li esteu demanant que el client sigui alhora la IP 10.0.0.1 i 10.0.0.2. Hauria de ser:&lt;br /&gt;
&lt;br /&gt;
 acl ME src 10.0.0.1&lt;br /&gt;
 acl YOU src 10.0.0.2&lt;br /&gt;
 http_access allow ME&lt;br /&gt;
 http_access allow YOU &lt;br /&gt;
&lt;br /&gt;
o:&lt;br /&gt;
&lt;br /&gt;
 acl US src 10.0.0.1 10.0.0.2&lt;br /&gt;
 http_access allow US&lt;br /&gt;
&lt;br /&gt;
====Depurar les ACL. Fitxer de log cache.log====&lt;br /&gt;
&lt;br /&gt;
Es pot activar la depuració amb:&lt;br /&gt;
&lt;br /&gt;
 debug_options ALL,1 33,2&lt;br /&gt;
&lt;br /&gt;
I torneu a iniciar Squid:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/init.d/squid3 restart&lt;br /&gt;
&lt;br /&gt;
Ara al fitxer [[/var/log/squid3/cache.log]]:&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/squid3/cache.log&lt;br /&gt;
&lt;br /&gt;
Veureu informació de cada petició i per que és acceptada o no. Podeu augmentar el nivell de depuració posant:&lt;br /&gt;
 &lt;br /&gt;
 debug_options ALL,1 33,2 28,9&lt;br /&gt;
&lt;br /&gt;
La sintaxi és força senzilla, Squid ésta dividit en seccions. ALL val dir totes les seccions i si només volem depurar una secció la hem d'indicar pel seu número. Les seccions les podeu consultar a:&lt;br /&gt;
&lt;br /&gt;
 http://www.linofee.org/~jel/proxy/Squid/debug.shtml&lt;br /&gt;
&lt;br /&gt;
Les seccions que hem elevat el nivell de depuració són:&lt;br /&gt;
&lt;br /&gt;
 28 Access Control&lt;br /&gt;
 33 Client-side Routines&lt;br /&gt;
&lt;br /&gt;
Va de 1 a 9, sent 9 l'opció més xerraire.&lt;br /&gt;
&lt;br /&gt;
==== Browser ACLs====&lt;br /&gt;
&lt;br /&gt;
Permeten fer normes d'accés depenent del navegador. Per exemple per crear una ACL per a Firefox:&lt;br /&gt;
&lt;br /&gt;
 acl firefox browser -i firefox&lt;br /&gt;
&lt;br /&gt;
{{nota|És important l'opció -i que ignora majúscules/minúscules si no no funciona correctament ja que molst user agents tenen la primera lletra en majúscules, p.ex. Firefox}}&lt;br /&gt;
&lt;br /&gt;
{{nota|firefox és una expressió regular per tant quadra amb qualsevol navegador on al user-agent aparegui la paraula firefox}}&lt;br /&gt;
&lt;br /&gt;
Després es pot utilitzar, per exemple, amb:&lt;br /&gt;
&lt;br /&gt;
 http_access deny !firefox&lt;br /&gt;
&lt;br /&gt;
que només permetrà navegar amb firefox.&lt;br /&gt;
&lt;br /&gt;
Si teniu activat el [[user agent]] log els podeu consultar amb:&lt;br /&gt;
&lt;br /&gt;
 $ [[sudo]] [[tail]] -f [[/var/log/squid3/useragent.log]]&lt;br /&gt;
 192.168.1.126 [02/Feb/2010:11:27:56 +0100] &amp;quot;Mozilla/5.0 (X11; U; Linux i686; ca; rv:1.9.1.7) Gecko/20100106 Ubuntu/9.10 (karmic) Firefox/3.5.7&amp;quot;&lt;br /&gt;
 192.168.1.126 [02/Feb/2010:11:27:57 +0100] &amp;quot;Mozilla/5.0 (X11; U; Linux i686; ca; rv:1.9.1.7) Gecko/20100106 Ubuntu/9.10 (karmic) Firefox/3.5.7&amp;quot;&lt;br /&gt;
 192.168.1.126 [02/Feb/2010:11:27:57 +0100] &amp;quot;Mozilla/5.0 (X11; U; Linux i686; ca; rv:1.9.1.7) Gecko/20100106 Ubuntu/9.10 (karmic) Firefox/3.5.7&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== Especificar una ACL per a una xarxa ====&lt;br /&gt;
&lt;br /&gt;
 acl localnet src 10.0.0.0/8	# RFC1918 possible internal network&lt;br /&gt;
&lt;br /&gt;
===Canvis en els DNS===&lt;br /&gt;
&lt;br /&gt;
A la carpeta:&lt;br /&gt;
&lt;br /&gt;
 /etc/resolvconf.d/update-libc.d&lt;br /&gt;
&lt;br /&gt;
Hi ha un script que recarrega squid quan hi ha un canvi al fitxer:&lt;br /&gt;
&lt;br /&gt;
 [[/etc/resolv.conf]]&lt;br /&gt;
&lt;br /&gt;
és a dir si hi ha algun canvi en les DNS de la màquina.&lt;br /&gt;
&lt;br /&gt;
===Port de funcionament d'squid===&lt;br /&gt;
&lt;br /&gt;
És un dels pocs serveis que no apareix al fitxer '''/etc/services'''. El port que s'utilitza normalment és el 3128 i es pot modificar utilitzant el paràmetre '''http_port''' del fitxer '''/etc/squid/squid.conf'''&lt;br /&gt;
&lt;br /&gt;
 # Squid normally listens to port 3128&lt;br /&gt;
 http_port 3128&lt;br /&gt;
&lt;br /&gt;
Amb webmin ho podem canviar a:&lt;br /&gt;
&lt;br /&gt;
[[Imatge:Portssquid.png]]&lt;br /&gt;
&lt;br /&gt;
Podem comprovar el funcionament d'Squid amb les comandes:&lt;br /&gt;
&lt;br /&gt;
 $ sudo nmap localhost -p 3128&lt;br /&gt;
 $ telnet localhost 3128&lt;br /&gt;
&lt;br /&gt;
=== Opció -k ===&lt;br /&gt;
&lt;br /&gt;
 $ squid3 --help&lt;br /&gt;
 squid3: invalid option -- '-'&lt;br /&gt;
 Usage: squid [-cdhvzCDFNRVYX] [-s | -l facility] [-f config-file] [-[au] port] [-k signal]&lt;br /&gt;
        -a port   Specify HTTP port number (default: 3128).&lt;br /&gt;
        -d level  Write debugging to stderr also.&lt;br /&gt;
        -f file   Use given config-file instead of&lt;br /&gt;
                  /etc/squid3/squid.conf&lt;br /&gt;
        -h        Print help message.&lt;br /&gt;
        '''-k reconfigure|rotate|shutdown|interrupt|kill|debug|check|parse&lt;br /&gt;
                  Parse configuration file, then send signal to &lt;br /&gt;
                  running copy (except -k parse) and exit.'''&lt;br /&gt;
        -s | -l facility&lt;br /&gt;
                  Enable logging to syslog.&lt;br /&gt;
        -u port   Specify ICP port number (default: 3130), disable with 0.&lt;br /&gt;
        -v        Print version.&lt;br /&gt;
        -z        Create swap directories&lt;br /&gt;
        -C        Do not catch fatal signals.&lt;br /&gt;
        -D        Disable initial DNS tests.&lt;br /&gt;
        -F        Don't serve any requests until store is rebuilt.&lt;br /&gt;
        -N        No daemon mode.&lt;br /&gt;
        -R        Do not set REUSEADDR on port.&lt;br /&gt;
        -S        Double-check swap during rebuild.&lt;br /&gt;
        -X        Force full debugging.&lt;br /&gt;
        -Y        Only return UDP_HIT or UDP_MISS_NOFETCH during fast reload.&lt;br /&gt;
&lt;br /&gt;
===Comprovar la sintaxi del fitxer de configuració===&lt;br /&gt;
&lt;br /&gt;
 $ sudo squid3 -k parse&lt;br /&gt;
&lt;br /&gt;
Si hi ha algun error us el dirà:&lt;br /&gt;
&lt;br /&gt;
 $ sudo squid3 -k parse&lt;br /&gt;
 2010/05/07 05:49:24| Processing Configuration File: /etc/squid3/squid.conf (depth 0)&lt;br /&gt;
 '''2010/05/07 05:49:24| cache_cf.cc(346) squid.conf:73 unrecognized: 'useragent_log''''&lt;br /&gt;
&lt;br /&gt;
===Access Control Lists (ACLs)===&lt;br /&gt;
&lt;br /&gt;
'''Passos a seguir amb Webmin'''&lt;br /&gt;
:*Primer creem una ACL de tipus Adreces Client. Podem utilitzar una adreça específica o un rang&lt;br /&gt;
:*Un cop creada l'ACL l'afegim a la llista de restriccions&lt;br /&gt;
:*Afegim restricció de proxy&lt;br /&gt;
:*Escollim l'opció permet i la ACL que acabem de crear&lt;br /&gt;
:*Ara reordenem les restriccions per assegurar-nos que la nostra ACL esta abans que la restricció '''denega all'''. &lt;br /&gt;
:*'''MOLT IMPORTANT''': Aplicar els canvis a Squid&lt;br /&gt;
&lt;br /&gt;
===Memòria cau (cache)===&lt;br /&gt;
&lt;br /&gt;
La memòria cau es guarda per defecte a:&lt;br /&gt;
&lt;br /&gt;
 /var/spool/squid3&lt;br /&gt;
&lt;br /&gt;
Els fitxers que la componen són:&lt;br /&gt;
&lt;br /&gt;
 $ ls -la /var/spool/squid3&lt;br /&gt;
 total 76&lt;br /&gt;
 drwxr-xr-x  18 proxy proxy 4096 2010-01-23 18:17 .&lt;br /&gt;
 drwxr-xr-x   8 root  root  4096 2010-01-23 18:17 ..&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 00&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 01&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 02&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 03&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 04&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 05&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 06&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 07&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 08&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 09&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0A&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0B&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0C&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0D&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0E&lt;br /&gt;
 drwxr-x--- 258 proxy proxy 4096 2010-01-23 18:17 0F&lt;br /&gt;
 -rw-r-----   1 proxy proxy   52 2010-01-23 18:17 swap.state&lt;br /&gt;
&lt;br /&gt;
Que cal tenir en compte:&lt;br /&gt;
:*Deixar sempre prou espai en disc per a la memòria cau. Si es queda sense espai Squid es trenca. &lt;br /&gt;
:*Val la pena tenir un bon marge de disc per evitar fragmentació. Com a mínim cal deixar un marge del 10%&lt;br /&gt;
&lt;br /&gt;
La mida de la cau s'indica amb:&lt;br /&gt;
&lt;br /&gt;
 cache_dir ... 7000 16 256&lt;br /&gt;
&lt;br /&gt;
On:&lt;br /&gt;
&lt;br /&gt;
:*'''7000''': són 7GB de cau&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#What_.27.27cache_dir.27.27_size_should_I_use.3F&lt;br /&gt;
&lt;br /&gt;
====cachemgr====&lt;br /&gt;
&lt;br /&gt;
El cache manager és un script [[CGI]] (cachemgr.cgi) que permet consultar les estadístiques de la cau i l'execució de l'squid. Per tal d'utilitzar aquesta aplicació cal tenir un [[servidor web]] com per exemple [[Apache]]. En sistemes de la família Debian cal instal·lar el paquet:&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install squid3-cgi&lt;br /&gt;
&lt;br /&gt;
Els fitxers proporcionats són:&lt;br /&gt;
&lt;br /&gt;
 $ sudo dpkg -L squid3-cgi&lt;br /&gt;
 /.&lt;br /&gt;
 /usr&lt;br /&gt;
 /usr/share&lt;br /&gt;
 /usr/share/doc&lt;br /&gt;
 /usr/share/doc/squid3-cgi&lt;br /&gt;
 /usr/share/doc/squid3-cgi/README&lt;br /&gt;
 /usr/share/doc/squid3-cgi/copyright&lt;br /&gt;
 /usr/share/doc/squid3-cgi/TODO.gz&lt;br /&gt;
 /usr/share/doc/squid3-cgi/changelog.Debian.gz&lt;br /&gt;
 /usr/share/man&lt;br /&gt;
 /usr/share/man/man8&lt;br /&gt;
 /usr/share/man/man8/cachemgr3.cgi.8.gz&lt;br /&gt;
 /usr/lib&lt;br /&gt;
 /usr/lib/cgi-bin&lt;br /&gt;
 /usr/lib/cgi-bin/cachemgr3.cgi&lt;br /&gt;
 /etc&lt;br /&gt;
 /etc/squid3&lt;br /&gt;
 /etc/squid3/cachemgr.conf &lt;br /&gt;
&lt;br /&gt;
es proporciona un petit manual:&lt;br /&gt;
&lt;br /&gt;
 $ [[man]] cachemgr3.cgi&lt;br /&gt;
&lt;br /&gt;
L'script CGI està a:&lt;br /&gt;
&lt;br /&gt;
 /usr/lib/cgi-bin/cachemgr3.cgi&lt;br /&gt;
&lt;br /&gt;
La [http://wiki.squid-cache.org/SquidFaq/CacheManager?highlight=%28cachemgr%29#Cache_manager_configuration_for_Apache_2.x configuració per Apache 2] és:&lt;br /&gt;
&lt;br /&gt;
 $ [[sudo]] [[joe]] /etc/apache2/sites-available/cachemgr&lt;br /&gt;
&lt;br /&gt;
Afegiu:&lt;br /&gt;
&lt;br /&gt;
 ScriptAlias /Squid/cgi-bin/cachemgr.cgi /usr/lib/cgi-bin/cachemgr3.cgi&lt;br /&gt;
 &lt;br /&gt;
 &amp;lt;Location /Squid/cgi-bin/cachemgr.cgi&amp;gt;&lt;br /&gt;
  order allow,deny&lt;br /&gt;
  allow from IP_DEL_CLIENT&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Activeu el site i torneu a iniciar Apache:&lt;br /&gt;
&lt;br /&gt;
 $ sudo a2ensite cachemgr&lt;br /&gt;
 Enabling site cachemgr.&lt;br /&gt;
 Run '/etc/init.d/apache2 reload' to activate new configuration!&lt;br /&gt;
 $ sudo /etc/init.d/apache2 reload&lt;br /&gt;
&lt;br /&gt;
Accediu amb Firefox:&lt;br /&gt;
&lt;br /&gt;
 http://IP_SERVIDOR//Squid/cgi-bin/cachemgr.cgi&lt;br /&gt;
&lt;br /&gt;
Es pot protegir l'accés amb paraula de pas d'Apache:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Location /Squid/cgi-bin/cachemgr.cgi&amp;gt;&lt;br /&gt;
  AuthUserFile /path/to/password/file&lt;br /&gt;
  AuthGroupFile /dev/null&lt;br /&gt;
  AuthName User/Password Required&lt;br /&gt;
  AuthType Basic&lt;br /&gt;
  require user cachemanager&lt;br /&gt;
 &amp;lt;/Location&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/CacheManager?highlight=%28cachemgr%29&lt;br /&gt;
*http://www.example.com/Squid/cgi-bin/cachemgr.cgi&lt;br /&gt;
&lt;br /&gt;
=====Exemples des de squidclient=====&lt;br /&gt;
&lt;br /&gt;
Consultar el rendiment dels redirectors:&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:redirector&lt;br /&gt;
&lt;br /&gt;
=====Usuari i paraula de pas=====&lt;br /&gt;
&lt;br /&gt;
Només són necessaris per a apagar la cache (shutdown) o tornar a demanar una URL d'un objecte. Per la resta de dades informatives no cal.  De totes formes es configura al fitxer squid.conf amb la directiva:&lt;br /&gt;
&lt;br /&gt;
 cachemgr_passwd&lt;br /&gt;
&lt;br /&gt;
=====Cache Client List=====&lt;br /&gt;
&lt;br /&gt;
És l'opció més interessant del menú, mostra tots els clients i les seves estadístiques.&lt;br /&gt;
&lt;br /&gt;
=====Accés des del client=====&lt;br /&gt;
&lt;br /&gt;
Consulteu [[#Client Squid]].&lt;br /&gt;
&lt;br /&gt;
====No fer cau d'algunes pàgines. Connexions directes====&lt;br /&gt;
&lt;br /&gt;
 acl gmail dstdomain .gmail.com&lt;br /&gt;
 always_direct allow gmail&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#Can_I_make_Squid_go_direct_for_some_sites.3F&lt;br /&gt;
&lt;br /&gt;
===Exemples de configuració===&lt;br /&gt;
&lt;br /&gt;
====Configurar els errors en català====&lt;br /&gt;
&lt;br /&gt;
Afegiu:&lt;br /&gt;
&lt;br /&gt;
 #Errors en català&lt;br /&gt;
 error_directory /usr/share/squid-langpack/ca&lt;br /&gt;
&lt;br /&gt;
Els idiomes son proveïts pel paquet:&lt;br /&gt;
&lt;br /&gt;
 squid-langpack&lt;br /&gt;
&lt;br /&gt;
====Impedir la descàrrega de fitxers grans====&lt;br /&gt;
&lt;br /&gt;
Cal utilitzar:&lt;br /&gt;
&lt;br /&gt;
 reply_body_max_size &lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#Can_I_prevent_users_from_downloading_large_files.3F&lt;br /&gt;
&lt;br /&gt;
====No fer cau de certs servidors====&lt;br /&gt;
&lt;br /&gt;
 acl someserver dstdomain .someserver.com&lt;br /&gt;
 cache deny someserver&lt;br /&gt;
&lt;br /&gt;
====Impedir l'accés a cert servidor====&lt;br /&gt;
&lt;br /&gt;
 acl Cooking2 dstdomain www.gourmet-chef.com&lt;br /&gt;
 http_access deny Cooking2&lt;br /&gt;
 http_access allow all&lt;br /&gt;
&lt;br /&gt;
====Impedir totes les pàgines que continguin una paraula o paraules concretes====&lt;br /&gt;
&lt;br /&gt;
 acl Cooking1 url_regex cooking&lt;br /&gt;
 acl Recipe1 url_regex recipe&lt;br /&gt;
 acl myclients src 172.16.5.0/24&lt;br /&gt;
 http_access deny Cooking1&lt;br /&gt;
 http_access deny Recipe1&lt;br /&gt;
 http_access allow myclients&lt;br /&gt;
 http_access deny all&lt;br /&gt;
&lt;br /&gt;
====Paràmetres d'Squid per configurar com a proxy d'apt-get (paquets debian)====&lt;br /&gt;
&lt;br /&gt;
 # Mantenir els paquets Debian 30 dies i els Packages.gz un dia&lt;br /&gt;
 refresh_pattern deb$ 43200 100% 43200&lt;br /&gt;
 refresh_pattern Packages.gz$ 1440 100% 1440&lt;br /&gt;
 #Augmentar la mida màxima d'objecte a la cache&lt;br /&gt;
 maximum_object_size 102400 KB&lt;br /&gt;
 &lt;br /&gt;
 cache_dir ufs /var/spool/squid 1000 16 256&lt;br /&gt;
&lt;br /&gt;
====Permetre només a un client concret accedir a una URL concreta====&lt;br /&gt;
&lt;br /&gt;
 acl special_client src 10.1.2.3&lt;br /&gt;
 acl special_url url_regex ^http://www.squid-cache.org/Doc/FAQ/$&lt;br /&gt;
 http_access allow special_client special_url&lt;br /&gt;
 http_access deny special_url&lt;br /&gt;
&lt;br /&gt;
====Permetre l'accés segons un horari====&lt;br /&gt;
&lt;br /&gt;
 acl FOO src 10.1.2.3 10.1.2.4&lt;br /&gt;
 acl WORKING time MTWHF 08:30-17:30&lt;br /&gt;
 http_access allow FOO WORKING&lt;br /&gt;
 http_access deny FOO&lt;br /&gt;
&lt;br /&gt;
Per a usuaris concrets:&lt;br /&gt;
&lt;br /&gt;
 acl USER1 proxy_auth Dick&lt;br /&gt;
 acl USER2 proxy_auth Jane&lt;br /&gt;
 acl DAY time 06:00-18:00&lt;br /&gt;
 http_access allow USER1 DAY&lt;br /&gt;
 http_access deny USER1&lt;br /&gt;
 http_access allow USER2 !DAY&lt;br /&gt;
 http_access deny USER2&lt;br /&gt;
&lt;br /&gt;
====Impedir fitxers grans====&lt;br /&gt;
&lt;br /&gt;
 #&lt;br /&gt;
 # Restringim mida màxima de fitxers&lt;br /&gt;
 #&lt;br /&gt;
 request_header_max_size 10 KB&lt;br /&gt;
 request_body_max_size 512 KB&lt;br /&gt;
 reply_body_max_size 3584000 allow all&lt;br /&gt;
&lt;br /&gt;
====Noms de domini====&lt;br /&gt;
&lt;br /&gt;
 .foo.com impedeix qualsevol pàgina del domini foo.com (www.foo.com, wiki.foo.com o elquesigui.foo.com)&lt;br /&gt;
 foo.com Només impedeix foo.com&lt;br /&gt;
&lt;br /&gt;
====Servidor proxy transparent====&lt;br /&gt;
&lt;br /&gt;
Cal posar:&lt;br /&gt;
&lt;br /&gt;
 http_port 3128 intercept&lt;br /&gt;
&lt;br /&gt;
{{nota| Abans es posava transparent. Ara és [[obsolet]]/[[deprecated]] i es recomana posar intercept que indica millor el que fa el servidor Squid}}&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
:*http://www.squid-cache.org/Versions/v3/3.1/cfgman/http_port.html&lt;br /&gt;
&lt;br /&gt;
{{nota|'''Molt important!''': Squid no fa cache de pàgines HTTPS. Això és per evitar atacs [[man-in-the-middle]]. Amb un proxy transparent (AFAIK) no es poden filtrar pàgines HTTPS. Tingueu en compte que això implica que a moltes pàgines si podrà accedir igualment encara que filtreu, p. ex. https:///www.facebook.es}}&lt;br /&gt;
&lt;br /&gt;
{{nota|També s'anomena [[Interception Caching]], [[Transparent Proxying]] o [[Cache Redirection]]  }}&lt;br /&gt;
&lt;br /&gt;
Interception Caching is the process by which HTTP connections coming from remote clients are redirected to a cache server, without their knowledge or explicit configuration.&lt;br /&gt;
&lt;br /&gt;
'''Avantatges'''&lt;br /&gt;
&lt;br /&gt;
:* No cal configurar els clients. Aquesta és la raó per la qual en xarxes amb moltes màquines se sol valorar aquesta opció.&lt;br /&gt;
:* Es poden implementar millors im ñes fiables estrategies per tal de mantenir l'accés dels clients en case de que la infraestructura de cache no funcioni.&lt;br /&gt;
&lt;br /&gt;
'''Inconvenients''':&lt;br /&gt;
:* Interceptar HTTP trenca els estàndards TCP/IP per què els user agents (navegadors dels clients ) creuen que estan parlant directament alm el servidor original&lt;br /&gt;
:* Necessita IPv4 am suport per a NAT ([[iptables]])&lt;br /&gt;
:* Provoca que no funcioni path-MTU (PMTUD) i és possible que alguns llocs remots no estiguin accessibles. Normalment això no és un problema per a clients connectats per Ethernet o DSL PPPoATM on el MTU de tots els enllaços entre la cache i el client és de 1500 o més. En canvi si els clients es connectant per DSL PPPoE ja que tenen normalment un MTU reduit (1472 és lo habitual).&lt;br /&gt;
:* A versions antigues de IE (abans de la 6) no funciona ctrl-reload de la fomra esperada.&lt;br /&gt;
:* Autenticació de proxy no funciona, i l'autenticació per IP tampoc funciona per què els usuaris provenen tots (tenen la IP d'origen de la màquina que intercepta) de la màquina que intercepta i no pas de la IP original.&lt;br /&gt;
:* No es pot utilitzar IDENT lookups (que de totes formes són molt insegures)&lt;br /&gt;
:* '''NOMÉS SUPORTA HTTP'''. NO FUNCIONA AMB [[gopher]], [[SSL]], o [[FTP]]. No es poden utilitzar ordres de redirecció amb altres protocols que no siguin HTTP &lt;br /&gt;
:* Intercepting Caches are incompatible with IP filtering designed to prevent address spoofing.&lt;br /&gt;
:* Clients are still expected to have full Internet DNS resolving capabilities; in certain intranet/firewalling setups, this is not always wanted.&lt;br /&gt;
:* Related to above: suppose the users browser connects to a site which is down. However, due to the transparent proxying, it gets a connected state to the interceptor. The end user may get wrong error messages or a hung browser, for seemingly unknown reasons to them. &lt;br /&gt;
&lt;br /&gt;
{{important|No es pot utilitzar autenticació amb el mode Interception!}}&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
:*http://wiki.squid-cache.org/SquidFaq/InterceptionProxy&lt;br /&gt;
&lt;br /&gt;
=====Configuració=====&lt;br /&gt;
&lt;br /&gt;
Configuració del fitxer '''/etc/squid3/squid.conf''':&lt;br /&gt;
&lt;br /&gt;
 httpd_accel_host virtual&lt;br /&gt;
 httpd_accel_port 0&lt;br /&gt;
 httpd_accel_whith_proxy on&lt;br /&gt;
 httpd_accel_uses_host_header on&lt;br /&gt;
&lt;br /&gt;
i sobretot:&lt;br /&gt;
&lt;br /&gt;
 http_port 3128 transparent&lt;br /&gt;
&lt;br /&gt;
{{nota|A partir de Squid 3.1 cal:}}&lt;br /&gt;
&lt;br /&gt;
 http_port 3128 intercept&lt;br /&gt;
&lt;br /&gt;
Cal tenir [[sysctl]] configurat amb:&lt;br /&gt;
&lt;br /&gt;
 # Controls IP packet forwarding&lt;br /&gt;
 net.ipv4.ip_forward = 1 &lt;br /&gt;
 &lt;br /&gt;
 # Controls source route verification&lt;br /&gt;
 net.ipv4.conf.default.rp_filter = 0&lt;br /&gt;
 &lt;br /&gt;
 # Do not accept source routing&lt;br /&gt;
 net.ipv4.conf.default.accept_source_route = 0&lt;br /&gt;
&lt;br /&gt;
Consulteu que tingueu:&lt;br /&gt;
&lt;br /&gt;
 $ cat /proc/sys/net/ipv4/ip_forward &lt;br /&gt;
 1&lt;br /&gt;
 $ cat /proc/sys/net/ipv4/conf/all/rp_filter &lt;br /&gt;
 0&lt;br /&gt;
 $ cat /proc/sys/net/ipv4/conf/all/accept_source_route &lt;br /&gt;
 0&lt;br /&gt;
&lt;br /&gt;
També cal configurar IPTABLES.Consulteu la secció [[Netfilter/iptables#Proxy_transparent_amb_iptables | Proxy_transparent_amb_iptables]] de l'article [[Netfilter/iptables]].&lt;br /&gt;
&lt;br /&gt;
Amb webmin tenim l'apartat '''Port Redirection Setup''':&lt;br /&gt;
&lt;br /&gt;
[[Imatge:PortRedirectionSetup.png]]&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Intercept/LinuxDnat&lt;br /&gt;
&lt;br /&gt;
====cache_peer, exemples de jerarquia amb pares i/o germans====&lt;br /&gt;
cache_peer&lt;br /&gt;
&lt;br /&gt;
és el paràmetre que ens permet personalitzar el nostre Squid per indicar-li amb quins altres proxy-cache&lt;br /&gt;
s'ha de relacionar i quin tipus de relació hi ha de tenir: pares o&lt;br /&gt;
germans.&lt;br /&gt;
&lt;br /&gt;
La sintaxi bàsica és:&lt;br /&gt;
&lt;br /&gt;
cache_peer servidor tipus http_port icp_port opcions&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Un escenari amb un pare:'''&lt;br /&gt;
&lt;br /&gt;
Si el nostre servidor de cache està per sota d'un altre servidor de cache, un pare, que té la IP 10.138.100.2, que escolta les peticions HTTP pel port 8080 i les peticions ICP pel port 3130, si no volem que ens desi a la nostra cache els objectes que ja estiguin a la cache del proxy pare:&lt;br /&gt;
&lt;br /&gt;
 cache_peer 10.138.100.2 parent 8080 3130 proxy-only&lt;br /&gt;
&lt;br /&gt;
En xarxes on hi ha diversos servidors proxy, que emmagatzemen contingut d'Internet a les seves caches, és interessant que treballin de manera conjunta. Tenir definits caches com a germans (sibbling) és interessant perquè abans de demanar una&lt;br /&gt;
cosa a fora es fa la consulta a la mateixa LAN (optimitzem ampla de banda per evitar descarregar coses que ja tenim a la mateixa xarxa).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Per autenticar-nos a un pare, si falla, al següent''&lt;br /&gt;
&lt;br /&gt;
Es tracta d'una solució molt útil de cara a preveure fallades. Si un proxy falla (per manteniment per exemple) l'squid intentarà fer una connexió al següent de la llista amb autenticació. Així podem reenviar el transit del nostre proxy a un altre.&lt;br /&gt;
&lt;br /&gt;
 cache_peer 10.139.xx.01 parent 3128  3128  proxy-only no-query no-digest  default login=USUARI:CONTRASSENYA&lt;br /&gt;
 cache_peer 10.139.xx.02 parent 3128  3128  proxy-only no-query no-digest  default login=USUARI:CONTRASSENYA&lt;br /&gt;
 cache_peer 10.139.xx.03 parent 3128  3128  proxy-only no-query no-digest  default login=USUARI:CONTRASSENYA&lt;br /&gt;
&lt;br /&gt;
Si el primer falla intentarà la connexió amb el següent fins que en trobi un que funcioni.&lt;br /&gt;
&lt;br /&gt;
'''Alerta''': No comprova quin és millor, senzillament va intentant seqüencialment un per un i el primer que funciona s'hi queda.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Un escenari amb germans:'''&lt;br /&gt;
&lt;br /&gt;
Si el nostre servidor de cache està treballant de manera paral·lela amb tres servidors de cache germans, que tenen les IP 10.138.101.2, 10.138.102.2 i 10.138.103.2, els tres escolten les peticions HTTP pel port 8080 i les peticions ICP&lt;br /&gt;
pel 3130, si no volem que ens desi a la nostra cache els objectes que ja estan a les caches dels germans:&lt;br /&gt;
&lt;br /&gt;
 cache_peer 10.138.101.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
 cache_peer 10.138.102.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
 cache_peer 10.138.103.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Escenari amb pare i germans:'''&lt;br /&gt;
&lt;br /&gt;
Podem fer les combinacions que ens calgui, per evitar sortir a fora si ja ho tenim a la LAN:&lt;br /&gt;
&lt;br /&gt;
 cache_peer 10.138.100.2 parent 8080 3130 proxy-only&lt;br /&gt;
 cache_peer 10.138.101.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
 cache_peer 10.138.102.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
 cache_peer 10.138.103.2 sibbling 8080 3130 proxy-only&lt;br /&gt;
&lt;br /&gt;
'''Font:''' [http://guifi.net/ca/node/1714 Blog lluis.dalmau]&lt;br /&gt;
'''Més informació:''' [http://guifi.net/ca/node/1683 Blog lluis.dalmau]&lt;br /&gt;
&lt;br /&gt;
====Modificar/fer a mida les pàgines d'error====&lt;br /&gt;
&lt;br /&gt;
Les trobareu a la carpeta:&lt;br /&gt;
&lt;br /&gt;
 $ ls /etc/squid/errors&lt;br /&gt;
 ERR_ACCESS_DENIED            ERR_DNS_FAIL           ERR_FTP_NOT_FOUND     ERR_INVALID_REQ   ERR_ONLY_IF_CACHED_MISS  ERR_TOO_BIG&lt;br /&gt;
 ERR_CACHE_ACCESS_DENIED      ERR_FORWARDING_DENIED  ERR_FTP_PUT_CREATED   ERR_INVALID_RESP  ERR_READ_ERROR           ERR_UNSUP_REQ&lt;br /&gt;
 ERR_CACHE_MGR_ACCESS_DENIED  ERR_FTP_DISABLED       ERR_FTP_PUT_ERROR     ERR_INVALID_URL   ERR_READ_TIMEOUT         ERR_URN_RESOLVE&lt;br /&gt;
 ERR_CANNOT_FORWARD           ERR_FTP_FAILURE        ERR_FTP_PUT_MODIFIED  ERR_LIFETIME_EXP  ERR_SHUTTING_DOWN        ERR_WRITE_ERROR&lt;br /&gt;
 ERR_CONNECT_FAIL             ERR_FTP_FORBIDDEN      ERR_FTP_UNAVAILABLE   ERR_NO_RELAY      ERR_SOCKET_FAILURE       ERR_ZERO_SIZE_OBJECT&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/SquidAcl#I_want_to_customize.2C_or_make_my_own_error_messages.&lt;br /&gt;
&lt;br /&gt;
Podeu crear un fitxer (/usr/local/squid/etc/porno.txt) amb un text com:&lt;br /&gt;
&lt;br /&gt;
 Our company policy is to deny requests to known porno sites.  If you&lt;br /&gt;
 feel you've received this message in error, please contact&lt;br /&gt;
 the support staff (support@this.company.com, 555-1234).&lt;br /&gt;
&lt;br /&gt;
I després posar&lt;br /&gt;
 &lt;br /&gt;
 acl porn url_regex &amp;quot;/usr/local/squid/etc/porno.txt&amp;quot;&lt;br /&gt;
 deny_info ERR_NO_PORNO porn&lt;br /&gt;
 http_access deny porn&lt;br /&gt;
 &lt;br /&gt;
{{nota| A les plantilles d'Error l'hora està en GMT. Per mostrar l'hora local cal posar %t en comptes de %T a les plantilles}}&lt;br /&gt;
&lt;br /&gt;
====Delay Pools====&lt;br /&gt;
&lt;br /&gt;
Cal tenir squid compilat amb l'opció '''--enable-delay-pools''':&lt;br /&gt;
&lt;br /&gt;
 $ squid3 -v | grep pool&lt;br /&gt;
 configure options:  '--build=i486-linux-gnu' '--prefix=/usr' '--includedir=${prefix}/include' '--mandir=${prefix}/share/man' '--infodir=${prefix}/share/info' &lt;br /&gt;
 ...&lt;br /&gt;
 --enable-removal-policies=lru,heap' ''''--enable-delay-pools'''' '--enable-cache-digests' '--enable-underscores' '--enable-icap-client' '--enable-follow-x-forwarded-for'  &lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
Directiva '''delay_pools''':&lt;br /&gt;
&lt;br /&gt;
 delay_pools N&lt;br /&gt;
&lt;br /&gt;
On N és el nombre de delay pools.&lt;br /&gt;
&lt;br /&gt;
La directiva delay_class indica el tipus de delay pool:&lt;br /&gt;
&lt;br /&gt;
 delay_class id class &lt;br /&gt;
&lt;br /&gt;
On id identifica el delay pool i id_class la classe&lt;br /&gt;
&lt;br /&gt;
Hi ha 3 classes a Squid 2.0:&lt;br /&gt;
&lt;br /&gt;
:*'''Classe 1''': Es defineix una única estructura de control, limitant el ús del canal sense distingir entre màquines client. També s'anomena un únic '''[[aggregate bucket]]'''. Es indicat per tal de controlar l'ús de l'ample de banda sense importa l'ús que en fan els clients.&lt;br /&gt;
:*'''Clase 2''': Esta format per 256 Delay Pools de classe 1. Es parla d'un aggregate bucket i 256 individual buckets. S'utilitza en xarxes de classe C i Squid assigna un delay pool a cada possible client.&lt;br /&gt;
:*'''Clase 3''': Són 256 Delay Pools de classe 2. 1 aggregate bucket, 256 network buckets, i 65,536 individual buckets. Xarxes de classe B.&lt;br /&gt;
&lt;br /&gt;
Un exemple:&lt;br /&gt;
&lt;br /&gt;
 delay_pools 3&lt;br /&gt;
 delay_class 1 3 ## el Delay Pool 1 és classe 3&lt;br /&gt;
 delay_class 2 1 ## el Delay Pool 2 és classe 1&lt;br /&gt;
 delay_class 3 2 ## el Dalay Pool 3 és classe 2 &lt;br /&gt;
&lt;br /&gt;
Per especificar els paràmetres del delay pool:&lt;br /&gt;
&lt;br /&gt;
 delay_parameters id rate/size [ rate/size [rate/size]] &lt;br /&gt;
&lt;br /&gt;
Es defineixen tres rate/size:&lt;br /&gt;
&lt;br /&gt;
:*El primer és obligatori.&lt;br /&gt;
&lt;br /&gt;
{{nota|Les mides s'especifiquen en Bytes tant el rate com el size. Cal tenir en compte que les mides d'ample de banda són normalment en bps, bits per segon i per tant cal fer la conversió.}}&lt;br /&gt;
&lt;br /&gt;
Exemple de conversió:&lt;br /&gt;
&lt;br /&gt;
Si vegeu un valor de 76800, estem indicant els Bytes/s. Per passar a Kbps:&lt;br /&gt;
&lt;br /&gt;
 76800*8/1024=600Kbps&lt;br /&gt;
&lt;br /&gt;
En una línia ADSL teòrica de 6Mbps, passant un [http://www.adsl4ever.com/test/11/ test ADSL]:&lt;br /&gt;
&lt;br /&gt;
 Download Speed: 2215 kbps (276.9 KB/sec transfer rate)&lt;br /&gt;
 Upload Speed: 494 kbps (61.8 KB/sec transfer rate)&lt;br /&gt;
&lt;br /&gt;
Vegem un exemple de Delay Pool de classe 1:&lt;br /&gt;
&lt;br /&gt;
 delay_parameters 1 76800/230400&lt;br /&gt;
&lt;br /&gt;
S'utilitza un ampla de banda màxim de 76800bps (600Kb/s) permeten ràfages per a una mida màxima de 1800Kb (1,8M aprox.)&lt;br /&gt;
&lt;br /&gt;
Altres exemples:&lt;br /&gt;
&lt;br /&gt;
 # asigno el canal a hosts en una red clase C sin límite global&lt;br /&gt;
 &lt;br /&gt;
 delay_parameters 1 -1/-1 10000/200000  &lt;br /&gt;
 &lt;br /&gt;
 # asigno canal en una red clase B a hosts individuales sin límites por subred&lt;br /&gt;
 &lt;br /&gt;
 delay_parameters 2 340787/1022361 -1/-1 10000/200000 &lt;br /&gt;
 &lt;br /&gt;
 # asigno canal en una red clase B a cada su red sin importar los hosts &lt;br /&gt;
 &lt;br /&gt;
 delay_parameters 3 340787/1022361 10000/200000 -1/-1  &lt;br /&gt;
&lt;br /&gt;
*http://www.bulma.net/body.phtml?nIdNoticia=2284&lt;br /&gt;
&lt;br /&gt;
=====Monitoritzar Delay Pools=====&lt;br /&gt;
&lt;br /&gt;
Es pot fer amb l'ordre:&lt;br /&gt;
&lt;br /&gt;
 squidclient mgr:delay | less &lt;br /&gt;
&lt;br /&gt;
Les podeu observar en temps real amb [[watch]]:&lt;br /&gt;
&lt;br /&gt;
 $ watch -n 1 &amp;quot;squidclient mgr:delay | less&amp;quot; &lt;br /&gt;
&lt;br /&gt;
Per provar el correcte funcionament dels delay pools utilitzeu [[wget]] o [[iptraf]] ja que els navegadors fan mitges i poden emmanscarar el resultat final.&lt;br /&gt;
&lt;br /&gt;
====Fitxer de configuració de l'INS de l'Ebre====&lt;br /&gt;
&lt;br /&gt;
 $ sudo cat /etc/squid3/squid.conf|more&lt;br /&gt;
 acl manager proto cache_object&lt;br /&gt;
 acl localhost src 127.0.0.1/32&lt;br /&gt;
 acl to_localhost dst 127.0.0.0/8&lt;br /&gt;
 acl SSL_ports port 443&lt;br /&gt;
 acl SSL_ports port 563 # snews&lt;br /&gt;
 acl SSL_ports port 993 # IMAP GMAIL&lt;br /&gt;
 acl Safe_ports port 80 # http&lt;br /&gt;
 acl Safe_ports port 21 # ftp&lt;br /&gt;
 acl Safe_ports port 443 # https&lt;br /&gt;
 acl Safe_ports port 563 # snews&lt;br /&gt;
 acl Safe_ports port 70 # gopher&lt;br /&gt;
 acl Safe_ports port 210 # wais&lt;br /&gt;
 acl Safe_ports port 1025-65535 # unregistered ports&lt;br /&gt;
 acl Safe_ports port 280 # http-mgmt&lt;br /&gt;
 acl Safe_ports port 488 # gss-http&lt;br /&gt;
 acl Safe_ports port 591 # filemaker&lt;br /&gt;
 acl Safe_ports port 777 # multiling http&lt;br /&gt;
 acl CONNECT method CONNECT&lt;br /&gt;
 acl Aules_informatica src 192.168.7.0/255.255.255.0&lt;br /&gt;
 acl unrestricted_ips src &amp;quot;/etc/squid3/src_unrestricted_ip.acl&amp;quot;&lt;br /&gt;
 acl unrestricted_macs arp &amp;quot;/etc/squid3/src_unrestricted_mac.acl&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 http_access allow manager localhost&lt;br /&gt;
 http_access deny manager&lt;br /&gt;
 http_access deny !Safe_ports&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 &lt;br /&gt;
 visible_hostname ebrecop1&lt;br /&gt;
 cache_mgr informatica@iesebre.com&lt;br /&gt;
 &lt;br /&gt;
 #No cache&lt;br /&gt;
 acl no_cache_hosts url_regex -i &amp;quot;/etc/squid3/dst_nocache_url.acl&amp;quot;&lt;br /&gt;
 cache deny no_cache_hosts&lt;br /&gt;
 &lt;br /&gt;
 cache_mem 750 MB&lt;br /&gt;
 cache_dir aufs /var/spool/squid3 10000 16 256&lt;br /&gt;
 &lt;br /&gt;
 #Errors en català&lt;br /&gt;
 error_directory /usr/share/squid-langpack/ca&lt;br /&gt;
 #Activar user agent log&lt;br /&gt;
 #useragent_log /var/log/squid3/user_agent.log&lt;br /&gt;
 &lt;br /&gt;
 strip_query_terms off  &lt;br /&gt;
 &lt;br /&gt;
 #Navegadors&lt;br /&gt;
 acl navegadors browser -i firefox&lt;br /&gt;
 acl navegadors browser -i explorer&lt;br /&gt;
 acl navegadors browser -i chrome&lt;br /&gt;
 &lt;br /&gt;
 #Utilitzar usuaris del fitxer /etc/squid3/users&lt;br /&gt;
 auth_param basic program /usr/lib/squid3/ncsa_auth /etc/squid3/users&lt;br /&gt;
 auth_param basic children 30&lt;br /&gt;
 auth_param basic realm Servidor Proxy del Institut de l'Ebre&lt;br /&gt;
 auth_param basic credentialsttl 6 hours&lt;br /&gt;
 auth_param basic casesensitive off&lt;br /&gt;
 &lt;br /&gt;
 #Usuaris&lt;br /&gt;
 acl guestuser proxy_auth guest&lt;br /&gt;
 acl ncsa_users proxy_auth REQUIRED&lt;br /&gt;
 &lt;br /&gt;
 #Clients sense restriccions&lt;br /&gt;
 http_access allow unrestricted_ips unrestricted_macs&lt;br /&gt;
 &lt;br /&gt;
 #Permetre totes les aplicacions que no siguin els navegadors&lt;br /&gt;
 http_access allow Aules_informatica !navegadors&lt;br /&gt;
 http_access allow ncsa_users&lt;br /&gt;
 &lt;br /&gt;
 #TODO: Crear un delay pool per a l'usuari convidat:&lt;br /&gt;
 #User: alumne&lt;br /&gt;
 #Password: guest&lt;br /&gt;
 #Forçar que funcioni més lentament  &lt;br /&gt;
 &lt;br /&gt;
 delay_pools 1&lt;br /&gt;
 delay_class 1 1&lt;br /&gt;
 &lt;br /&gt;
 delay_parameters 1 640/400000&lt;br /&gt;
 &lt;br /&gt;
 delay_access 1 allow guestuser&lt;br /&gt;
 delay_access 1 deny all &lt;br /&gt;
 &lt;br /&gt;
 http_access deny all&lt;br /&gt;
 &lt;br /&gt;
 #Activar SquidGuard&lt;br /&gt;
 redirect_program /usr/bin/squidGuard -c /etc/squid/squidGuard.conf&lt;br /&gt;
 redirect_children 50&lt;br /&gt;
 redirector_bypass on&lt;br /&gt;
 &lt;br /&gt;
 icp_access deny all&lt;br /&gt;
 htcp_access deny all&lt;br /&gt;
 http_port 3128&lt;br /&gt;
 hierarchy_stoplist cgi-bin ?&lt;br /&gt;
 access_log /var/log/squid3/access.log squid&lt;br /&gt;
 refresh_pattern ^ftp:		1440	20%	10080&lt;br /&gt;
 refresh_pattern ^gopher:	1440	0%	1440&lt;br /&gt;
 refresh_pattern (cgi-bin|\?)	0	0%	0&lt;br /&gt;
 refresh_pattern .		0	20%	4320&lt;br /&gt;
 icp_port 3130&lt;br /&gt;
 coredump_dir /var/spool/squid3&lt;br /&gt;
&lt;br /&gt;
====Fitxers de hosts i llistes de denegació====&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://rlwpx.free.fr/WPFF/hosts.htm&lt;br /&gt;
&lt;br /&gt;
====Limitar el nombre de connexions simultànies d'un client====&lt;br /&gt;
&lt;br /&gt;
 acl ACCOUNTSDEPT 192.168.5.0/24&lt;br /&gt;
 acl limitusercon maxconn 3&lt;br /&gt;
 http_access deny ACCOUNTSDEPT limitusercon&lt;br /&gt;
&lt;br /&gt;
:*http://www.cyberciti.biz/tips/howto-limit-squid-proxy-number-web-connections.html&lt;br /&gt;
&lt;br /&gt;
==== NO fer cache de certes pàgines. Directiva nocache ====&lt;br /&gt;
&lt;br /&gt;
TODO&lt;br /&gt;
&lt;br /&gt;
 Utilitzar la directiva no_cache ...&lt;br /&gt;
&lt;br /&gt;
=Fitxers de Log=&lt;br /&gt;
&lt;br /&gt;
 Consulteu a la wiki d'Squid el [http://wiki.squid-cache.org/SquidFaq/SquidLogs?highlight=%28squid%29|%28request%29|%28status%29 FAQ sobre els logs]&lt;br /&gt;
&lt;br /&gt;
Es pot modificar el format del fitxer de log amb la directiva [http://www.squid-cache.org/Doc/config/logformat/ logformat]:&lt;br /&gt;
&lt;br /&gt;
 logformat &amp;lt;name&amp;gt; &amp;lt;format specification&amp;gt;&lt;br /&gt;
&lt;br /&gt;
On &amp;lt;format specification&amp;gt; és una cadena de text amb format codes que comencen per %.&lt;br /&gt;
&lt;br /&gt;
'''Format codes''':&lt;br /&gt;
&lt;br /&gt;
 	        &amp;gt;a	Client source IP address&lt;br /&gt;
 		&amp;gt;A	Client FQDN&lt;br /&gt;
 		&amp;gt;p	Client source port&lt;br /&gt;
 		&amp;lt;A	Server IP address or peer name&lt;br /&gt;
 		la	Local IP address (http_port)&lt;br /&gt;
 		lp	Local port number (http_port)&lt;br /&gt;
 		ts	Seconds since epoch&lt;br /&gt;
 		tu	subsecond time (milliseconds)&lt;br /&gt;
 		tl	Local time. Optional strftime format argument&lt;br /&gt;
 			default %d/%b/%Y:%H:%M:%S %z&lt;br /&gt;
 		tg	GMT time. Optional strftime format argument&lt;br /&gt;
 			default %d/%b/%Y:%H:%M:%S %z&lt;br /&gt;
 		tr	Response time (milliseconds)&lt;br /&gt;
 		&amp;gt;h	Request header. Optional header name argument&lt;br /&gt;
 			on the format header[:[separator]element]&lt;br /&gt;
 		&amp;lt;h	Reply header. Optional header name argument&lt;br /&gt;
 			as for &amp;gt;h&lt;br /&gt;
 		un	User name&lt;br /&gt;
 		ul	User name from authentication&lt;br /&gt;
 		ui	User name from ident&lt;br /&gt;
 		us	User name from SSL&lt;br /&gt;
 		ue	User name from external acl helper&lt;br /&gt;
 		Hs	HTTP status code&lt;br /&gt;
 		Ss	Squid request status (TCP_MISS etc)&lt;br /&gt;
 		Sh	Squid hierarchy status (DEFAULT_PARENT etc)&lt;br /&gt;
 		mt	MIME content type&lt;br /&gt;
 		rm	Request method (GET/POST etc)&lt;br /&gt;
 		ru	Request URL&lt;br /&gt;
 		rp	Request URL-Path excluding hostname&lt;br /&gt;
 		rv	Request protocol version&lt;br /&gt;
 		et	Tag returned by external acl&lt;br /&gt;
 		ea	Log string returned by external acl&lt;br /&gt;
 		&amp;lt;st	Reply size including HTTP headers&lt;br /&gt;
 		&amp;gt;st	Request size including HTTP headers&lt;br /&gt;
 		st	Request+Reply size including HTTP headers&lt;br /&gt;
 		&amp;lt;sH	Reply high offset sent&lt;br /&gt;
 		&amp;lt;sS	Upstream object size&lt;br /&gt;
 		%	a literal % character&lt;br /&gt;
 &lt;br /&gt;
Els formats ja existents són:&lt;br /&gt;
 &lt;br /&gt;
 logformat squid %ts.%03tu %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt&lt;br /&gt;
 logformat squidmime %ts.%03tu %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt [%&amp;gt;h] [%&amp;lt;h]&lt;br /&gt;
 logformat common %&amp;gt;a %ui %un [%tl] &amp;quot;%rm %ru HTTP/%rv&amp;quot; %Hs %&amp;lt;st %Ss:%Sh&lt;br /&gt;
 logformat combined %&amp;gt;a %ui %un [%tl] &amp;quot;%rm %ru HTTP/%rv&amp;quot; %Hs %&amp;lt;st &amp;quot;%{Referer}&amp;gt;h&amp;quot; &amp;quot;%{User-Agent}&amp;gt;h&amp;quot; %Ss:%Sh&lt;br /&gt;
&lt;br /&gt;
Al fitxer de configuració per defecte la línia:&lt;br /&gt;
&lt;br /&gt;
 access_log /var/log/squid3/access.log squid&lt;br /&gt;
&lt;br /&gt;
Determina que el format escollir és squid:&lt;br /&gt;
 &lt;br /&gt;
 %ts.%03tu %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt&lt;br /&gt;
&lt;br /&gt;
o&lt;br /&gt;
&lt;br /&gt;
 time elapsed remotehost code/status bytes method URL rfc931 peerstatus/peerhost type&lt;br /&gt;
&lt;br /&gt;
 1264350783.235    391 192.168.1.14 TCP_REFRESH_UNMODIFIED/304 399 GET http://www.tv3.cat/cuines/img/menu/072.gif - DIRECT/194.224.66.35 image/gif&lt;br /&gt;
&lt;br /&gt;
On &lt;br /&gt;
&lt;br /&gt;
:*'''%ts''': Seconds since epoch (marca de temps). A l'exemple: 1264350783&lt;br /&gt;
:*'''%tu''': subsecond time (milliseconds): 235&lt;br /&gt;
:*'''%6tr''': Response time (milliseconds). A l'exemple: 391&lt;br /&gt;
:*'''%&amp;gt;a''': Client source IP address. A l'exemple: 192.168.1.14&lt;br /&gt;
:*'''%Ss/%03Hs''': Squid request status (TCP_MISS etc) + / + HTTP Status Code. A l'exemple: TCP_REFRESH_UNMODIFIED/304&lt;br /&gt;
:*'''%&amp;lt;st''': Reply size including HTTP headers. A l'exemple:339&lt;br /&gt;
:*'''%rm''': Request method (GET/POST etc). A l'exemple:GET&lt;br /&gt;
:*'''%ru''': Request URL. A l'exemple: http://www.tv3.cat/cuines/img/menu/072.gif&lt;br /&gt;
:*'''%un''': Username (si s'aplica) (sinó surt un guió)&lt;br /&gt;
:*'''%Sh/%&amp;lt;A''': Squid hierarchy status (DEFAULT_PARENT etc) + / + Server IP address or peer name. A l'exemple: DIRECT/194.224.66.35&lt;br /&gt;
:*'''%mt''': MIME content type. A l'exemple: image/gif&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/SquidLogs?highlight=%28squid%29|%28request%29|%28status%29#access.log_native_format_in_detail&lt;br /&gt;
&lt;br /&gt;
==Formats predefinits de fitxer de log==&lt;br /&gt;
&lt;br /&gt;
Hi ha els següents:&lt;br /&gt;
&lt;br /&gt;
 logformat squid %ts.%03tu %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt&lt;br /&gt;
 logformat squidmime %ts.%03tu %6tr %&amp;gt;a %Ss/%03Hs %&amp;lt;st %rm %ru %un %Sh/%&amp;lt;A %mt [%&amp;gt;h] [%&amp;lt;h]&lt;br /&gt;
 logformat common %&amp;gt;a %ui %un [%tl] &amp;quot;%rm %ru HTTP/%rv&amp;quot; %Hs %&amp;lt;st %Ss:%Sh&lt;br /&gt;
 logformat combined %&amp;gt;a %ui %un [%tl] &amp;quot;%rm %ru HTTP/%rv&amp;quot; %Hs %&amp;lt;st &amp;quot;%{Referer}&amp;gt;h&amp;quot; &amp;quot;%{User-Agent}&amp;gt;h&amp;quot; %Ss:%Sh&lt;br /&gt;
&lt;br /&gt;
S'indica quin s'utilitza amb:&lt;br /&gt;
&lt;br /&gt;
  access_log /var/log/squid3/access.log '''format'''&lt;br /&gt;
&lt;br /&gt;
Per defecte teniu:&lt;br /&gt;
&lt;br /&gt;
 access_log /var/log/squid3/access.log squid&lt;br /&gt;
&lt;br /&gt;
==Squid Result codes==&lt;br /&gt;
&lt;br /&gt;
{{nota|IMS vol dir If-Modified-Since}}&lt;br /&gt;
&lt;br /&gt;
 TCP_HIT Un còpia de l'objecte vàlida s'ha obtingut de la memòria cau.&lt;br /&gt;
 &lt;br /&gt;
 TCP_MISS L'objecte no era a la memòria cau.&lt;br /&gt;
 &lt;br /&gt;
 TCP_REFRESH_HIT o TCP_REFRESH_UNMODIFIED L'objecte era a la memòria cau però estava caducat (STALE). La petició IMS (If-Modified-Since) ha retornat un codi de resposta HTTP &lt;br /&gt;
 &amp;quot;304 not modified&amp;quot;.&lt;br /&gt;
 &lt;br /&gt;
 TCP_REFRESH_FAIL_HIT L'objecte era a la memòria cau però estava caducat (STALE). La petició IMS ha fallat i es retorna l'objecte caducat&lt;br /&gt;
 &lt;br /&gt;
 TCP_REFRESH_MISS L'objecte era a la memòria cau però estava caducat (STALE). La petició IMS ha retornat el nou contingut&lt;br /&gt;
 &lt;br /&gt;
 TCP_CLIENT_REFRESH_MISS El client a demanat una nova versió del fitxer&lt;br /&gt;
 &lt;br /&gt;
 TCP_IMS_HIT El client ha fer una petició IMS d'un objecte que estava fresc a la memòria cau.&lt;br /&gt;
 &lt;br /&gt;
 TCP_SWAPFAIL_MISS Error! L'objecte s'esperava trobar-lo a la memòria cau però no s'ha trobat. &lt;br /&gt;
 &lt;br /&gt;
 TCP_NEGATIVE_HIT S'ha demanat un objecte que esta la memòria cau però amb una resposta negativa (&amp;quot;404 not found&amp;quot;). Depèn del negative TTL.&lt;br /&gt;
 for negative_ttl in your squid.conf file.&lt;br /&gt;
 &lt;br /&gt;
 TCP_MEM_HIT Una còpia del fitxer estava en memòria RAM i no a calgut accedir a disc.&lt;br /&gt;
 &lt;br /&gt;
 TCP_DENIED L'accés a estat denegat per aquesta petició&lt;br /&gt;
 &lt;br /&gt;
 TCP_OFFLINE_HIT L'objecte ha estat demanat en mode offline&lt;br /&gt;
 &lt;br /&gt;
 TCP_STALE_HIT Tot i estar caducat l'objecte s'ha servit. &lt;br /&gt;
 &lt;br /&gt;
 TCP_ASYNC_HIT ...&lt;br /&gt;
 &lt;br /&gt;
 TCP_ASYNC_MISS ...&lt;br /&gt;
 &lt;br /&gt;
També hi ha peticions similars per a UDP:&lt;br /&gt;
&lt;br /&gt;
UDP_HIT, UDP_MISS, UDP_DENIED, UDP_INVALID...&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/SquidLogs#Squid_result_codes&lt;br /&gt;
&lt;br /&gt;
==Control d'accés. access.log==&lt;br /&gt;
&lt;br /&gt;
En temps real podeu monitoritzar l'ús que s'està gent del proxy amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/squid3/access.log&lt;br /&gt;
 1183497461.620    206 87.219.199.153 TCP_NEGATIVE_HIT/404 619 GET http://xarxantoni.net:8080/favicon.ico - NONE/- text/html&lt;br /&gt;
 1183497461.728      5 87.219.199.153 TCP_NEGATIVE_HIT/404 619 GET http://xarxantoni.net:8080/favicon.ico - NONE/- text/html&lt;br /&gt;
 1183497487.892      5 87.219.199.153 TCP_NEGATIVE_HIT/404 619 GET http://xarxantoni.net:8080/favicon.ico - NONE/- text/html&lt;br /&gt;
 1183497489.056   8714 87.219.199.153 TCP_MISS/200 4217 GET http://xarxantoni.net:8080/mediawiki/index.php? - DIRECT/217.149.150.24 text/html&lt;br /&gt;
 1183497489.240     45 87.219.199.153 TCP_NEGATIVE_HIT/404 619 GET http://xarxantoni.net:8080/favicon.ico - NONE/- text/html&lt;br /&gt;
 1183497509.789    772 87.219.199.153 TCP_MISS/302 568 POST http://xarxantoni.net:8080/mediawiki/index.php? - DIRECT/217.149.150.24 text/html&lt;br /&gt;
 1183497510.528      5 87.219.199.153 TCP_NEGATIVE_HIT/404 619 GET&lt;br /&gt;
&lt;br /&gt;
O podeu escollir les columnes que voleu visualitzar amb [[awk]]:&lt;br /&gt;
&lt;br /&gt;
 # tail -f /var/log/squid3/access.log | awk '{print$3 &amp;quot; &amp;quot; $8 &amp;quot; &amp;quot; $7}'&lt;br /&gt;
&lt;br /&gt;
===Llegir el fitxer de log amb dates humanes ===&lt;br /&gt;
&lt;br /&gt;
Les dates dels fitxers de log d'Squid estan en [[epoch]]s un format per a ordinadors. Per posar les dates en forma humà:&lt;br /&gt;
&lt;br /&gt;
  $ sudo tail -f /var/log/squid/access.log | awk '{ print strftime(&amp;quot;%c &amp;quot;, $1) $0; }'&lt;br /&gt;
&lt;br /&gt;
A Debian:&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install gawk&lt;br /&gt;
 $ sudo tail -f /var/log/squid/access.log | gawk '{ print strftime(&amp;quot;%c &amp;quot;, $1) $0; }'&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
 &lt;br /&gt;
 [[Date#Conversi.C3.B3_d.27epoch_a_data|Conversió d'epoch a data]]&lt;br /&gt;
&lt;br /&gt;
==Exemple d'ús dels fitxers de log==&lt;br /&gt;
&lt;br /&gt;
Consultar els navegador (browsers agents) utilitzats i mostrar una estadística d'ús:&lt;br /&gt;
&lt;br /&gt;
 $ sudo cat /var/log/squid/user_agent.log | awk '{print $4}' | sort|uniq -c | sort -n&lt;br /&gt;
&lt;br /&gt;
==/var/log/squid3/cache.log==&lt;br /&gt;
&lt;br /&gt;
 $ [[sudo]] [[tail]] -f /var/log/squid3/cache.log &lt;br /&gt;
 2010/01/23 18:17:50|         0 Objects expired.&lt;br /&gt;
 2010/01/23 18:17:50|         0 Objects cancelled.&lt;br /&gt;
 2010/01/23 18:17:50|         0 Duplicate URLs purged.&lt;br /&gt;
 2010/01/23 18:17:50|         0 Swapfile clashes avoided.&lt;br /&gt;
 2010/01/23 18:17:50|   Took 1.00 seconds (  0.00 objects/sec).&lt;br /&gt;
 2010/01/23 18:17:50| Beginning Validation Procedure&lt;br /&gt;
 2010/01/23 18:17:50|   Completed Validation Procedure&lt;br /&gt;
 2010/01/23 18:17:50|   Validated 25 Entries&lt;br /&gt;
 2010/01/23 18:17:50|   store_swap_size = 0&lt;br /&gt;
 2010/01/23 18:17:50| storeLateRelease: released 0 objects&lt;br /&gt;
&lt;br /&gt;
Es pot utilitzar per [[Squid#Depurar_les_ACL._Fitxer_de_log_cache.log|Depurar]].&lt;br /&gt;
&lt;br /&gt;
==Activar el log dels user-agents (navegadors)==&lt;br /&gt;
&lt;br /&gt;
{{nota|Cal tenir en compte que les versions binaries dels paquets d'Squid com per exemple els d'Ubuntu no han esta compilats amb suport per a user-agent. Si executeu Squid directament veureu:}}&lt;br /&gt;
&lt;br /&gt;
 $ sudo /usr/sbin/squid3&lt;br /&gt;
 2010/02/02 09:17:32| cache_cf.cc(346) squid.conf:57 unrecognized: 'useragent_log'&lt;br /&gt;
&lt;br /&gt;
La compilació s'ha de fer amb l'opció:&lt;br /&gt;
&lt;br /&gt;
 --enable-useragent-log&lt;br /&gt;
&lt;br /&gt;
Consulteu [[Squid#Recompilar_el_paquet_Debian]].&lt;br /&gt;
&lt;br /&gt;
Es pot comprovar si teniu suport per a user agent amb:&lt;br /&gt;
&lt;br /&gt;
 $ squid3 -v | grep userangent&lt;br /&gt;
&lt;br /&gt;
Cal afegir la següent línia al fitxer de configuració d'Squid [[/etc/squid3/squid.conf]]:&lt;br /&gt;
&lt;br /&gt;
 [http://www.squid-cache.org/Doc/config/useragent_log/ useragent_log] /var/log/squid3/useragent.log&lt;br /&gt;
&lt;br /&gt;
On el camí del fitxer de log el podeu escollir (ha de ser una carpeta on el procés squid pugui escriure, és a dir que hi tingui permisos l'usuari que executa el procés - proxy):&lt;br /&gt;
&lt;br /&gt;
 $ ls -la [[/var/log/squid3/]]&lt;br /&gt;
 total 23332&lt;br /&gt;
 drwxr-xr-x  2 '''proxy proxy'''     4096 2010-10-18 06:38 .&lt;br /&gt;
 drwxr-xr-x 15 root  root      4096 2010-10-18 06:38 ..&lt;br /&gt;
 -rw-r-----  1 proxy proxy  6900886 2010-10-18 11:33 access.log&lt;br /&gt;
 -rw-r-----  1 proxy proxy    56112 2010-10-17 20:24 access.log.1&lt;br /&gt;
 -rw-r-----  1 proxy proxy     1624 2010-10-16 22:03 access.log.2.gz&lt;br /&gt;
 -rw-r-----  1 proxy proxy  4487605 2010-10-18 07:52 cache.log&lt;br /&gt;
 -rw-r-----  1 proxy proxy  1495481 2010-10-17 06:54 cache.log.1&lt;br /&gt;
 -rw-r-----  1 proxy proxy    76722 2010-10-16 06:49 cache.log.2.gz&lt;br /&gt;
 -rw-r-----  1 proxy proxy 10545941 2010-10-18 11:33 store.log&lt;br /&gt;
 -rw-r-----  1 proxy proxy   258017 2010-10-18 06:24 store.log.1&lt;br /&gt;
 -rw-r-----  1 proxy proxy    36695 2010-10-17 06:24 store.log.2.gz&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Podeu consultar el User-agent de [[Firefox]] posant la URL:&lt;br /&gt;
&lt;br /&gt;
 about:config&lt;br /&gt;
&lt;br /&gt;
I consultant el paràmetre:&lt;br /&gt;
&lt;br /&gt;
 general.useragent.extra.firefox&lt;br /&gt;
&lt;br /&gt;
{{nota|De fet també el podeu modificar des d'aquí o utilitzant el plugin [https://addons.mozilla.org/en-US/firefox/addon/59 User Agent Switcher]}}&lt;br /&gt;
&lt;br /&gt;
===Format del fitxer de log dels user agents===&lt;br /&gt;
&lt;br /&gt;
==Format de log d'Apache. Analitzadors de logs d'Apache==&lt;br /&gt;
&lt;br /&gt;
Cal posar &lt;br /&gt;
&lt;br /&gt;
 emulate_httpd_log on&lt;br /&gt;
&lt;br /&gt;
Para emular el formato de log del apache, esto nos sirve para utilizar los analizadores de logs de apache&lt;br /&gt;
&lt;br /&gt;
:*http://www.babilonics.com/content/como-instalar-squid-en-debian-con-autentificacion-ldap-por-grupos-de-windows-2003&lt;br /&gt;
&lt;br /&gt;
=Client Squid=&lt;br /&gt;
&lt;br /&gt;
S'intal·la amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install squidclient&lt;br /&gt;
&lt;br /&gt;
Serveix per provar un servidor squid des de la línia de comandes:&lt;br /&gt;
&lt;br /&gt;
 $ squidclient -h proxy.domini.com -p 800 http://www.upc.edu&lt;br /&gt;
&lt;br /&gt;
==Accés al manager des del client squid==&lt;br /&gt;
&lt;br /&gt;
Vegeu també [[Squid#cachemgr | cachemgr]]&lt;br /&gt;
&lt;br /&gt;
 $ [[sudo]] [[apt-get]] install squidclient&lt;br /&gt;
 $ [[squidclient]] mgr:info&lt;br /&gt;
 HTTP/1.0 200 OK&lt;br /&gt;
 Server: squid/3.0.STABLE18&lt;br /&gt;
 Mime-Version: 1.0&lt;br /&gt;
 Date: Sun, 24 Jan 2010 20:25:42 GMT&lt;br /&gt;
 Content-Type: text/plain&lt;br /&gt;
 Expires: Sun, 24 Jan 2010 20:25:42 GMT&lt;br /&gt;
 Last-Modified: Sun, 24 Jan 2010 20:25:42 GMT&lt;br /&gt;
 X-Cache: MISS from localhost&lt;br /&gt;
 X-Cache-Lookup: MISS from localhost:3128&lt;br /&gt;
 Via: 1.0 localhost (squid/3.0.STABLE18)&lt;br /&gt;
 Proxy-Connection: close&lt;br /&gt;
 &lt;br /&gt;
 Squid Object Cache: Version 3.0.STABLE18&lt;br /&gt;
 Start Time:	Sun, 24 Jan 2010 20:25:40 GMT&lt;br /&gt;
 Current Time:	Sun, 24 Jan 2010 20:25:42 GMT&lt;br /&gt;
 Connection information for squid:&lt;br /&gt;
 	Number of clients accessing cache:	1&lt;br /&gt;
 	Number of HTTP requests received:	0&lt;br /&gt;
	Number of ICP messages received:	0&lt;br /&gt;
 	Number of ICP messages sent:	0&lt;br /&gt;
 	Number of queued ICP replies:	0&lt;br /&gt;
 	Number of HTCP messages received:	0&lt;br /&gt;
 	Number of HTCP messages sent:	0&lt;br /&gt;
 	Request failure ratio:	 0.00&lt;br /&gt;
 	Average HTTP requests per minute since start:	0.0&lt;br /&gt;
 	Average ICP messages per minute since start:	0.0&lt;br /&gt;
 	Select loop called: 140 times, 13.891 ms avg&lt;br /&gt;
 Cache information for squid:&lt;br /&gt;
	Hits as % of all requests:	5min: 0.0%, 60min: 0.0%&lt;br /&gt;
 	Hits as % of bytes sent:	5min: -0.0%, 60min: -0.0%&lt;br /&gt;
 	Memory hits as % of hit requests:	5min: 0.0%, 60min: 0.0%&lt;br /&gt;
 	Disk hits as % of hit requests:	5min: 0.0%, 60min: 0.0%&lt;br /&gt;
 	Storage Swap size:	5296 KB&lt;br /&gt;
 	Storage Swap capacity:	 5.2% used, 94.8% free&lt;br /&gt;
 	Storage Mem size:	108 KB&lt;br /&gt;
 	Storage Mem capacity:	 1.3% used, 98.7% free&lt;br /&gt;
 	Mean Object Size:	15.00 KB&lt;br /&gt;
 	Requests given to unlinkd:	0&lt;br /&gt;
 Median Service Times (seconds)  5 min    60 min:&lt;br /&gt;
 	HTTP Requests (All):   0.00000  0.00000&lt;br /&gt;
 	Cache Misses:          0.00000  0.00000&lt;br /&gt;
 	Cache Hits:            0.00000  0.00000&lt;br /&gt;
 	Near Hits:             0.00000  0.00000&lt;br /&gt;
 	Not-Modified Replies:  0.00000  0.00000&lt;br /&gt;
 	DNS Lookups:           0.00000  0.00000&lt;br /&gt;
 	ICP Queries:           0.00000  0.00000&lt;br /&gt;
 Resource usage for squid:&lt;br /&gt;
 	UP Time:	1.945 seconds&lt;br /&gt;
 	CPU Time:	0.052 seconds&lt;br /&gt;
 	CPU Usage:	2.67%&lt;br /&gt;
 	CPU Usage, 5 minute avg:	0.00%&lt;br /&gt;
 	CPU Usage, 60 minute avg:	0.00%&lt;br /&gt;
 	Process Data Segment Size via sbrk(): 2580 KB&lt;br /&gt;
 	Maximum Resident Size: 0 KB&lt;br /&gt;
 	Page faults with physical i/o: 0&lt;br /&gt;
 Memory usage for squid via mallinfo():&lt;br /&gt;
 	Total space in arena:    2848 KB&lt;br /&gt;
 	Ordinary blocks:         2812 KB      2 blks&lt;br /&gt;
 	Small blocks:               0 KB      0 blks&lt;br /&gt;
 	Holding blocks:         27704 KB     14 blks&lt;br /&gt;
 	Free Small blocks:          0 KB&lt;br /&gt;
 	Free Ordinary blocks:      35 KB&lt;br /&gt;
 	Total in use:           30516 KB 100%&lt;br /&gt;
 	Total free:                35 KB 0%&lt;br /&gt;
 	Total size:             30552 KB&lt;br /&gt;
 Memory accounted for:&lt;br /&gt;
 	Total accounted:         2174 KB   7%&lt;br /&gt;
 	memPool accounted:       2174 KB   7%&lt;br /&gt;
 	memPool unaccounted:    28377 KB  93%&lt;br /&gt;
 	memPoolAlloc calls:      3205&lt;br /&gt;
 	memPoolFree calls:       1090&lt;br /&gt;
 File descriptor usage for squid:&lt;br /&gt;
 	Maximum number of file descriptors:   65535&lt;br /&gt;
 	Largest file desc currently in use:     15&lt;br /&gt;
 	Number of file desc currently in use:   10&lt;br /&gt;
 	Files queued for open:                   0&lt;br /&gt;
 	Available number of file descriptors: 65525&lt;br /&gt;
 	Reserved number of file descriptors:   100&lt;br /&gt;
 	Store Disk files open:                   0&lt;br /&gt;
 Internal Data Structures:&lt;br /&gt;
 	   380 StoreEntries&lt;br /&gt;
 	    27 StoreEntries with MemObjects&lt;br /&gt;
 	    26 Hot Object Cache Items&lt;br /&gt;
 	   353 on-disk objects&lt;br /&gt;
&lt;br /&gt;
El podeu consultar en temps real amb l'ordre [[watch]]:&lt;br /&gt;
&lt;br /&gt;
  $ watch -n 1 &amp;quot;squidclient mgr:info&amp;quot;&lt;br /&gt;
&lt;br /&gt;
=== Pàgines del cache manager===&lt;br /&gt;
&lt;br /&gt;
client_list&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:client_list | more&lt;br /&gt;
 HTTP/1.0 200 OK&lt;br /&gt;
 Server: squid/3.0.STABLE18&lt;br /&gt;
 Mime-Version: 1.0&lt;br /&gt;
 Date: Mon, 17 May 2010 10:16:53 GMT&lt;br /&gt;
 Content-Type: text/plain&lt;br /&gt;
 Expires: Mon, 17 May 2010 10:16:53 GMT&lt;br /&gt;
 Last-Modified: Mon, 17 May 2010 10:16:53 GMT&lt;br /&gt;
 X-Cache: MISS from localhost&lt;br /&gt;
 X-Cache-Lookup: MISS from localhost:3128&lt;br /&gt;
 Via: 1.0 localhost (squid/3.0.STABLE18)&lt;br /&gt;
 Proxy-Connection: close&lt;br /&gt;
 &lt;br /&gt;
 Cache Clients:&lt;br /&gt;
 Address: 192.168.2.57&lt;br /&gt;
 Name:    192.168.2.57&lt;br /&gt;
 Currently established connections: 0&lt;br /&gt;
     ICP  Requests 0&lt;br /&gt;
     HTTP Requests 27&lt;br /&gt;
         TCP_MISS                  23  85%&lt;br /&gt;
         TCP_CLIENT_REFRESH_M       4  15% &lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Podeu veure la llista completa a:&lt;br /&gt;
&lt;br /&gt;
http://tilt.lib.tsinghua.edu.cn/docs/books/squid/TheDefinitiveGuideChinese/0596001622/squid-CHP-14-SECT-2.html&lt;br /&gt;
&lt;br /&gt;
=Autenticació=&lt;br /&gt;
&lt;br /&gt;
Squid permet que els usuaris del Proxy s'hagin d'autenticar abans de poder-lo utilitzar. L'autenticació es pot fer amb:&lt;br /&gt;
&lt;br /&gt;
:*'''[[LDAP]]''': Protocol Lightweight Directory Access Protocol&lt;br /&gt;
:*'''[[NCSA]]''': Fitxer NCSA-style d'usuaris i paraules de pas&lt;br /&gt;
:*'''[[MSNT]]''': Utilitza un domini Windows NT per l'autenticació&lt;br /&gt;
:*'''[[PAM]]''': Unix Pluggable Authentication Modules.&lt;br /&gt;
:*'''[[SMB]]''': Utilitza [[Samba]] o el protocol [[SMB]] de xarxes Windows.&lt;br /&gt;
:*'''[[getpwam]]''': Utilitza el fitxer de password de Unix.&lt;br /&gt;
:*'''[[SASL]]''': Llibreries SALS.&lt;br /&gt;
:*'''[[mswin_sspi]]''': Windows native authenticator&lt;br /&gt;
:*'''[[YP]]''': Utilitza la base de dades de [[NIS]].&lt;br /&gt;
:*'''[[NTLM]]''': Sistema que suporta el xifratge de les dades d'autenticació.&lt;br /&gt;
:*'''[[MySQL]]''': Autenticació mitjançant una base de dades&lt;br /&gt;
&lt;br /&gt;
La directiva d'Squid que s'utilitza per activar l'autenticació és [http://www.eu.squid-cache.org/Doc/config/auth_param auth param]. La sintaxi és:&lt;br /&gt;
&lt;br /&gt;
 auth_param scheme parameter [setting]&lt;br /&gt;
&lt;br /&gt;
{{important| No és possible utilitzar autenticació amb un [[Proxy transparent]]}}&lt;br /&gt;
&lt;br /&gt;
Extret del fitxer original de configuració proporcionat per Squid:&lt;br /&gt;
&lt;br /&gt;
 #       format: auth_param scheme parameter [setting]&lt;br /&gt;
 #&lt;br /&gt;
 #       The order in which authentication schemes are presented to the client is&lt;br /&gt;
 #       dependent on the order the scheme first appears in config file. IE&lt;br /&gt;
 #       has a bug (it's not RFC 2617 compliant) in that it will use the basic&lt;br /&gt;
 #       scheme if basic is the first entry presented, even if more secure&lt;br /&gt;
 #       schemes are presented. For now use the order in the recommended  &lt;br /&gt;
 #       settings section below. If other browsers have difficulties (don't&lt;br /&gt;
 #       recognize the schemes offered even if you are using basic) either &lt;br /&gt;
 #       put basic first, or disable the other schemes (by commenting out their&lt;br /&gt;
 #       program entry).&lt;br /&gt;
 #&lt;br /&gt;
 #       Once an authentication scheme is fully configured, it can only be&lt;br /&gt;
 #       shutdown by shutting squid down and restarting. Changes can be made on&lt;br /&gt;
 #       the fly and activated with a reconfigure. I.E. You can change to a&lt;br /&gt;
 #       different helper, but not unconfigure the helper completely.&lt;br /&gt;
 #&lt;br /&gt;
 #       Please note that while this directive defines how Squid processes&lt;br /&gt;
 #       authentication it does not automatically activate authentication.&lt;br /&gt;
 #       To use authentication you must in addition make use of ACLs based&lt;br /&gt;
 #       on login name in http_access (proxy_auth, proxy_auth_regex or&lt;br /&gt;
 #       external with %LOGIN used in the format tag). The browser will be&lt;br /&gt;
 #       challenged for authentication on the first such acl encountered  &lt;br /&gt;
 #       in http_access processing and will also be re-challenged for new &lt;br /&gt;
 #       login credentials if the request is being denied by a proxy_auth &lt;br /&gt;
 #       type acl.&lt;br /&gt;
 #&lt;br /&gt;
 #       WARNING: authentication can't be used in a transparently intercepting&lt;br /&gt;
 #       proxy as the client then thinks it is talking to an origin server and&lt;br /&gt;
 #       not the proxy. This is a limitation of bending the TCP/IP protocol to&lt;br /&gt;
 #       transparently intercepting port 80, not a limitation in Squid.&lt;br /&gt;
 #       Ports flagged 'transparent' or 'tproxy' have authentication disabled. &lt;br /&gt;
 #&lt;br /&gt;
 #       === Parameters for the basic scheme follow. ===&lt;br /&gt;
 #&lt;br /&gt;
 #       &amp;quot;program&amp;quot; cmdline&lt;br /&gt;
 #       '''Specify the command for the external authenticator.  Such a program&lt;br /&gt;
 #       reads a line containing &amp;quot;username password&amp;quot; and replies &amp;quot;OK&amp;quot; or&lt;br /&gt;
 #       &amp;quot;ERR&amp;quot; in an endless loop'''. &amp;quot;ERR&amp;quot; responses may optionally be followed&lt;br /&gt;
 #       by a error description available as %m in the returned error page.  &lt;br /&gt;
 #       If you use an authenticator, make sure you have 1 acl of type proxy_auth.&lt;br /&gt;
 #&lt;br /&gt;
 #       By default, the basic authentication scheme is not used unless a&lt;br /&gt;
 #       program is specified.&lt;br /&gt;
 #&lt;br /&gt;
 #       If you want to use the traditional NCSA proxy authentication, set&lt;br /&gt;
 #       this line to something like&lt;br /&gt;
 #&lt;br /&gt;
 #       auth_param basic program /usr/lib/squid3/ncsa_auth /usr/etc/passwd&lt;br /&gt;
 #&lt;br /&gt;
 #       &amp;quot;children&amp;quot; numberofchildren&lt;br /&gt;
 #       The number of authenticator processes to spawn. If you start too few&lt;br /&gt;
 #       Squid will have to wait for them to process a backlog of credential &lt;br /&gt;
 #       verifications, slowing it down. When password verifications are&lt;br /&gt;
 #       done via a (slow) network you are likely to need lots of&lt;br /&gt;
 #       authenticator processes.&lt;br /&gt;
 #       auth_param basic children 5&lt;br /&gt;
 #&lt;br /&gt;
 #       &amp;quot;concurrency&amp;quot; concurrency&lt;br /&gt;
 #       The number of concurrent requests the helper can process.&lt;br /&gt;
 #       The default of 0 is used for helpers who only supports   &lt;br /&gt;
 #       one request at a time. Setting this changes the protocol used to&lt;br /&gt;
 #       include a channel number first on the request/response line, allowing&lt;br /&gt;
 #       multiple requests to be sent to the same helper in parallell without &lt;br /&gt;
 #       wating for the response.&lt;br /&gt;
 #       Must not be set unless it's known the helper supports this.&lt;br /&gt;
 #       auth_param basic concurrency 0&lt;br /&gt;
 # &lt;br /&gt;
 #       &amp;quot;realm&amp;quot; realmstring&lt;br /&gt;
 #       Specifies the realm name which is to be reported to the&lt;br /&gt;
 #       client for the basic proxy authentication scheme (part of&lt;br /&gt;
 #       the text the user will see when prompted their username and&lt;br /&gt;
 #       password). There is no default.&lt;br /&gt;
 #       auth_param basic realm Squid proxy-caching web server&lt;br /&gt;
 #&lt;br /&gt;
 #       &amp;quot;credentialsttl&amp;quot; timetolive&lt;br /&gt;
 #       Specifies how long squid assumes an externally validated&lt;br /&gt;
 #       username:password pair is valid for - in other words how&lt;br /&gt;
 #       often the helper program is called for that user. Set this&lt;br /&gt;
 #       low to force revalidation with short lived passwords.  Note&lt;br /&gt;
 #       setting this high does not impact your susceptibility&lt;br /&gt;
 #       to replay attacks unless you are using an one-time password&lt;br /&gt;
 #       system (such as SecureID).  If you are using such a system,&lt;br /&gt;
 #       you will be vulnerable to replay attacks unless you also   &lt;br /&gt;
 #       use the max_user_ip ACL in an http_access rule.&lt;br /&gt;
 #&lt;br /&gt;
 #       &amp;quot;casesensitive&amp;quot; on|off&lt;br /&gt;
 #       Specifies if usernames are case sensitive. Most user databases are&lt;br /&gt;
 #       case insensitive allowing the same username to be spelled using both&lt;br /&gt;
 #       lower and upper case letters, but some are case sensitive. This&lt;br /&gt;
 #       makes a big difference for user_max_ip ACL processing and similar.&lt;br /&gt;
 #       auth_param basic casesensitive off&lt;br /&gt;
  &lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
 &lt;br /&gt;
*http://wiki.squid-cache.org/Features/Authentication&lt;br /&gt;
&lt;br /&gt;
==Helpers==&lt;br /&gt;
&lt;br /&gt;
S'anomenen així els binaris o scripts que s'utilitzen per a implementar els diferents mètodes d'autenticació. Els podeu tornar a la carpeta:&lt;br /&gt;
&lt;br /&gt;
 /usr/lib/squid3/&lt;br /&gt;
&lt;br /&gt;
Són els fitxers acabats en auth:&lt;br /&gt;
&lt;br /&gt;
 $ ls /usr/lib/squid3/ | grep auth&lt;br /&gt;
 digest_ldap_auth&lt;br /&gt;
 digest_pw_auth&lt;br /&gt;
 getpwname_auth&lt;br /&gt;
 msnt_auth&lt;br /&gt;
 ncsa_auth&lt;br /&gt;
 ntlm_auth&lt;br /&gt;
 pam_auth&lt;br /&gt;
 sasl_auth&lt;br /&gt;
 smb_auth&lt;br /&gt;
 smb_auth.pl&lt;br /&gt;
 smb_auth.sh&lt;br /&gt;
 squid_kerb_auth&lt;br /&gt;
 squid_ldap_auth&lt;br /&gt;
 yp_auth&lt;br /&gt;
&lt;br /&gt;
==Directives d'Squid==&lt;br /&gt;
&lt;br /&gt;
:*'''[http://www.squid-cache.org/Versions/v3/3.0/cfgman/auth_param.html auth_param]''': Configura el helper i els seus paràmetres&lt;br /&gt;
:*'''[http://www.squid-cache.org/Versions/v3/3.0/cfgman/authenticate_cache_garbage_interval.html authenticate_cache_garbage_interval]''':&lt;br /&gt;
:*'''[http://www.squid-cache.org/Versions/v3/3.0/cfgman/authenticate_ttl.html authenticate_ttl]''': El temps que es manté una autenticació.&lt;br /&gt;
:*'''[http://www.squid-cache.org/Versions/v3/3.0/cfgman/authenticate_ip_ttl.html authenticate_ip_ttl]''': Utilitzat conjuntament amb l'ACL max_user_ip.&lt;br /&gt;
:*'''auth-bypass''': permet especificar pàgines que no utilitzaran autenticació&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Les podeu consultar totes a:&lt;br /&gt;
&lt;br /&gt;
 http://www.squid-cache.org/Doc/config/&lt;br /&gt;
&lt;br /&gt;
== Excepcions a l'autenticació. auth-bypass ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[auth-bypass]] permet indicar llocs web als quals no se'ls aplicarà autenticació:&lt;br /&gt;
&lt;br /&gt;
TODO Example:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Navegadors'''&lt;br /&gt;
Es pode combinar acls que detecten el tipus de navegador per tal de no aplicar autenticació a lo que no siguin navegadors.&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
:*http://www.wlug.org.nz/SquidNotes&lt;br /&gt;
&lt;br /&gt;
==NCSA==&lt;br /&gt;
&lt;br /&gt;
Primer cal crear el fitxers d'usuaris i paraules de pas. Per al primer usuari cal crear el fitxers amb l'opció -c&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[htpasswd]] -c /etc/squid3/passwd user&lt;br /&gt;
 New password: &lt;br /&gt;
 Re-type new password: &lt;br /&gt;
 Adding password for user user&lt;br /&gt;
&lt;br /&gt;
La resta d'usuaris es poden crear amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[htpasswd]] /etc/squid3/passwd user2&lt;br /&gt;
&lt;br /&gt;
El fitxer conté els usuaris i les paraules de pas xifrades:&lt;br /&gt;
&lt;br /&gt;
 $ [[cat]] /etc/squid3/passwd&lt;br /&gt;
 user:zDlXpFhxK0hUQ&lt;br /&gt;
 user2:b8esg7No8XZgc&lt;br /&gt;
&lt;br /&gt;
Assegureu-vos que l'usuari amb que s'executa Squid pot llegir el fitxer:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[chmod]] o+r /etc/squid3/passwd&lt;br /&gt;
&lt;br /&gt;
Localitzem el helper:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L squid3 | grep ncsa_auth&lt;br /&gt;
 /usr/lib/squid3/ncsa_auth&lt;br /&gt;
&lt;br /&gt;
Configurem Squid:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[joe]] /etc/squid3/squid.conf&lt;br /&gt;
&lt;br /&gt;
Afegiu el bloc:&lt;br /&gt;
&lt;br /&gt;
 auth_param basic program /usr/lib/squid3/ncsa_auth /etc/squid3/passwd&lt;br /&gt;
 auth_param basic children 5&lt;br /&gt;
 auth_param basic realm Squid proxy-caching web server&lt;br /&gt;
 auth_param basic credentialsttl 2 hours&lt;br /&gt;
 auth_param basic casesensitive off&lt;br /&gt;
&lt;br /&gt;
després de les ACL&lt;br /&gt;
&lt;br /&gt;
On:&lt;br /&gt;
&lt;br /&gt;
:*'''program''': El helper de ncsa&lt;br /&gt;
:*'''children''': El número de processos d'autenticació que s'engeguen. Quan més usuaris tingueu que utilitzin el sistema de forma concurrent major haurà de ser aquest número&lt;br /&gt;
:*'''realm''': Nom del reialme d'autenticació. És part del text que veuran els usuaris quan els hi preguntin per l'usuari i la paraula de pas&lt;br /&gt;
:*'''credentialsttl''': Temps que es mantindrà un usuari logat&lt;br /&gt;
:*'''casesensitive''': Especifica si els noms d'usuari són [[case sensitive]].&lt;br /&gt;
&lt;br /&gt;
Després d'aquest bloc definiu la acl:&lt;br /&gt;
&lt;br /&gt;
 acl ncsa_users proxy_auth REQUIRED&lt;br /&gt;
&lt;br /&gt;
I ara definiu '''abans del''':&lt;br /&gt;
&lt;br /&gt;
 http_access deny all &lt;br /&gt;
&lt;br /&gt;
la línia:&lt;br /&gt;
&lt;br /&gt;
 http_access allow ncsa_users&lt;br /&gt;
&lt;br /&gt;
{{nota|tingueu en compte que si teniu una acl que permet accedir a tots els clients segons un rang d'IPs, ara ja no necessiteu aquesta línia. Borreu-la}}&lt;br /&gt;
&lt;br /&gt;
I apliqueu els canvis:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/init.d/squid3 reload&lt;br /&gt;
&lt;br /&gt;
Proveu el navegador, us demanarà un usuari i paraula de pas.&lt;br /&gt;
&lt;br /&gt;
Si ara observeu el fitxers de log veure que ja surt l'usuari:&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/squid3/access.log&lt;br /&gt;
 ...&lt;br /&gt;
 1265094172.358    168 192.168.1.126 TCP_MISS/200 518 GET http://www10.gencat.cat/dursi/ca/posat/img/separador_ligerob.gif '''user''' DIRECT/83.247.128.163 image/gif&lt;br /&gt;
 1265094172.398     83 192.168.1.126 TCP_MISS/200 762 GET http://www.gencat.cat/js/gencatAnalitica_id.js '''user''' DIRECT/83.247.129.60 application/x-javascript&lt;br /&gt;
 1265094172.424    193 192.168.1.126 TCP_MISS/200 1764 GET http://www10.gencat.cat/dursi/ca/posat/img/ajuda.gif '''user''' DIRECT/83.247.128.163 image/gif&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{nota| [http://www.ncsa.illinois.edu/ ncsa] National Center for Supercomputing Applications són qui van desenvolupar el servidor web httpd (precedent d'Apache)}}&lt;br /&gt;
&lt;br /&gt;
*http://www.cyberciti.biz/tips/linux-unix-squid-proxy-server-authentication.html&lt;br /&gt;
&lt;br /&gt;
=== Només demanar paraula de pas als navegadors ===&lt;br /&gt;
&lt;br /&gt;
Moltes eines del sistema utilitzen Internet i n'hi forces que no suporten autenticació de Proxy o que simplement no suporten proxy. Podem configurar squid per tal que només apliqui la restricció d'autenticació al navegador web:&lt;br /&gt;
&lt;br /&gt;
 http_access allow clients !firefox&lt;br /&gt;
 http_access allow ncsa_users&lt;br /&gt;
 http_access deny all&lt;br /&gt;
&lt;br /&gt;
On l'ACL de firefox és:&lt;br /&gt;
&lt;br /&gt;
 acl firefox browser -i firefox&lt;br /&gt;
&lt;br /&gt;
També podeu utilitzar una llista de navegadors:&lt;br /&gt;
&lt;br /&gt;
 #Navegadors&lt;br /&gt;
 acl navegadors browser -i firefox &lt;br /&gt;
 acl navegadors browser -i explorer&lt;br /&gt;
 acl navegadors browser -i chrome  &lt;br /&gt;
&lt;br /&gt;
aleshores:&lt;br /&gt;
&lt;br /&gt;
 http_access allow clients !navegadors&lt;br /&gt;
 http_access allow ncsa_users&lt;br /&gt;
 http_access deny all&lt;br /&gt;
&lt;br /&gt;
===Firefox i recordar paraules de pas===&lt;br /&gt;
&lt;br /&gt;
Quan introduïu per primer cop el vostre nom d'usuari i paraula de pas amb Firefox us preguntarà si voleu guardar la paraula de pas. Li podeu dir que la guardi permanentment.&lt;br /&gt;
&lt;br /&gt;
Per borrar la paraula de pas aneu al menú Edita (Eines a Windows) i l'opció Preferències. Aneu a l'apartat '''Seguretat''' i feu clic a '''contrasenyes desades'''. Localitzeu l'usuari i contrasenya i l'esborreu.&lt;br /&gt;
&lt;br /&gt;
Heu de tancar tot el navegador per tornar a iniciar una sessió.&lt;br /&gt;
&lt;br /&gt;
==NTLM==&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Authenticate/Ntlm&lt;br /&gt;
&lt;br /&gt;
==Squid + LDAP o Active Directory==&lt;br /&gt;
&lt;br /&gt;
=== Documentació===&lt;br /&gt;
&lt;br /&gt;
Hi ha una entrada del manual:&lt;br /&gt;
&lt;br /&gt;
 $ [[man]] squid_ldap_auth&lt;br /&gt;
 squid_ldap_auth(8)                                                                                                                                        squid_ldap_auth(8)&lt;br /&gt;
 &lt;br /&gt;
 NAME&lt;br /&gt;
        squid_ldap_auth - Squid LDAP authentication helper &lt;br /&gt;
 &lt;br /&gt;
 SYNOPSIS&lt;br /&gt;
       squid_ldap_auth -b &amp;quot;base DN&amp;quot; [-u attribute] [options] [ldap_server_name[:port]|URI]...&lt;br /&gt;
       squid_ldap_auth -b &amp;quot;base DN&amp;quot; -f &amp;quot;LDAP search filter&amp;quot; [options] [ldap_server_name[:port]|URI]...&lt;br /&gt;
 &lt;br /&gt;
 DESCRIPTION&lt;br /&gt;
        This  helper  allows Squid to connect to a LDAP directory to validate the user name and password of Basic HTTP authentication.  LDAP options are specified as parame‐&lt;br /&gt;
        ters on the command line, while the username(s) and password(s) to be checked against the LDAP directory are specified on subsequent lines of input  to  the  helper,&lt;br /&gt;
        one username/password pair per line separated by a space.&lt;br /&gt;
 &lt;br /&gt;
        As  expected  by  the basic authentication construct of Squid, after specifying a username and password followed by a new line, this helper will produce either OK or&lt;br /&gt;
        ERR on the following line to show if the specified credentials are correct according to the LDAP directory.&lt;br /&gt;
 &lt;br /&gt;
        The program has two major modes of operation. In the default mode of operation the users DN is constructed using the base DN and user attribute. In the other mode of&lt;br /&gt;
        operation a search filter is used to locate valid user DN's below the base DN.&lt;br /&gt;
 &lt;br /&gt;
        -b basedn (REQUIRED)&lt;br /&gt;
               Specifies the base DN under which the users are located.&lt;br /&gt;
 &lt;br /&gt;
        -f filter&lt;br /&gt;
               LDAP  search  filter  to locate the user DN. Required if the users are in a hierarchy below the base DN, or if the login name is not what builds the user spe‐&lt;br /&gt;
               cific part of the users DN.&lt;br /&gt;
 &lt;br /&gt;
               The search filter can contain up to 15 occurrences of %s which will be replaced by the username, as in  &amp;quot;uid=%s&amp;quot;  for  RFC2037  directories.  For  a  detailed&lt;br /&gt;
               description of LDAP search filter syntax see RFC2254.  &lt;br /&gt;
 &lt;br /&gt;
       -u userattr&lt;br /&gt;
              Specifies  the name of the DN attribute that contains the username/login.  Combined with the base DN to construct the users DN when no search filter is speci‐&lt;br /&gt;
              fied (-f option). Defaults to 'uid'&lt;br /&gt;
 &lt;br /&gt;
              Note: This can only be done if all your users are located directly under the same position in the LDAP tree and the login name is used for  naming  each  user&lt;br /&gt;
              object.  If your LDAP tree does not match these criterias or if you want to filter who are valid users then you need to use a search filter to search for your&lt;br /&gt;
              users DN (-f option).&lt;br /&gt;
 &lt;br /&gt;
       -U passwordattr&lt;br /&gt;
              Use ldap_compare instead of ldap_simple_bind to verify the users password.  passwordattr is the LDAP attribute storing the users password.&lt;br /&gt;
 &lt;br /&gt;
       -s base|one|sub&lt;br /&gt;
              search scope when performing user DN searches specified by the -f option. Defaults to 'sub'.&lt;br /&gt;
 &lt;br /&gt;
              base object only, one level below the base object or subtree below the base object&lt;br /&gt;
 &lt;br /&gt;
       -D binddn -w password&lt;br /&gt;
              The DN and password to bind as while performing searches. Required by the -f flag if the directory does not allow anonymous searches.&lt;br /&gt;
 &lt;br /&gt;
              As the password needs to be printed in plain text in your Squid configuration it is strongly recommended to use a account with minimal associated  privileges.&lt;br /&gt;
              This to limit the damage in case someone could get hold of a copy of your Squid configuration file.&lt;br /&gt;
 &lt;br /&gt;
       -D binddn -W secretfile&lt;br /&gt;
              The DN and the name of a file containing the password to bind as while performing searches.&lt;br /&gt;
 &lt;br /&gt;
              Less insecure version of the former parameter pair with two advantages: The password does not occur in the process listing, and the password is not being com‐&lt;br /&gt;
              promised if someone gets the squid configuration file without getting the secretfile.&lt;br /&gt;
 &lt;br /&gt;
       -P     Use a persistent LDAP connection. Normally the LDAP connection is only open while validating a username to preserve resources at the LDAP server. This  option&lt;br /&gt;
              causes the LDAP connection to be kept open, allowing it to be reused for further user validations. Recommended for larger installations.&lt;br /&gt;
 &lt;br /&gt;
       -O     Only  bind  once  per  LDAP connection. Some LDAP servers do not allow re-binding as another user after a successful ldap_bind.  The use of this option always&lt;br /&gt;
              opens a new connection for each login attempt. If combined with the -P option for persistent LDAP connection then the connection used for  searching  for  the&lt;br /&gt;
              user DN is kept persistent but a new connection is opened to verify each users password once the DN is found.&lt;br /&gt;
 &lt;br /&gt;
       -R     do not follow referrals&lt;br /&gt;
 &lt;br /&gt;
       -a never|always|search|find&lt;br /&gt;
              when to dereference aliases. Defaults to 'never'&lt;br /&gt;
 &lt;br /&gt;
              never dereference aliases (default), always dereference aliases, only while searching or only to find the base object&lt;br /&gt;
 &lt;br /&gt;
       -H ldapuri&lt;br /&gt;
              Specity the LDAP server to connect to by LDAP URI (requires OpenLDAP libraries).  Servers can also be specified last on the command line.&lt;br /&gt;
 &lt;br /&gt;
       -h ldapserver&lt;br /&gt;
              Specify the LDAP server to connect to. Servers can also be specified last on the command line.&lt;br /&gt;
 &lt;br /&gt;
       -p ldapport&lt;br /&gt;
              Specify  an alternate TCP port where the ldap server is listening if other than the default LDAP port 389. Can also be specified within the server specificia‐&lt;br /&gt;
              tion by using servername:port syntax.&lt;br /&gt;
 &lt;br /&gt;
       -v 2|3 LDAP protocol version. Defaults to 2 if not specified.&lt;br /&gt;
 &lt;br /&gt;
       -Z     Use TLS encryption&lt;br /&gt;
 &lt;br /&gt;
       -Scertpath&lt;br /&gt;
              Enable LDAP over SSL (requires Netscape LDAP API libraries)&lt;br /&gt;
 &lt;br /&gt;
       -cconnect_timeout&lt;br /&gt;
              Specify timeout used when connecting to LDAP servers (requires Netscape LDAP API libraries)&lt;br /&gt;
 &lt;br /&gt;
       -tsearch_timeout&lt;br /&gt;
              Specify time limit on LDAP search operations&lt;br /&gt;
             The DN and the name of a file containing the password to bind as while performing searches.&lt;br /&gt;
 &lt;br /&gt;
              Less insecure version of the former parameter pair with two advantages: The password does not occur in the process listing, and the password is not being com‐&lt;br /&gt;
              promised if someone gets the squid configuration file without getting the secretfile.&lt;br /&gt;
 &lt;br /&gt;
       -P     Use a persistent LDAP connection. Normally the LDAP connection is only open while validating a username to preserve resources at the LDAP server. This  option&lt;br /&gt;
              causes the LDAP connection to be kept open, allowing it to be reused for further user validations. Recommended for larger installations.&lt;br /&gt;
&lt;br /&gt;
       -O     Only  bind  once  per  LDAP connection. Some LDAP servers do not allow re-binding as another user after a successful ldap_bind.  The use of this option always&lt;br /&gt;
              opens a new connection for each login attempt. If combined with the -P option for persistent LDAP connection then the connection used for  searching  for  the&lt;br /&gt;
              user DN is kept persistent but a new connection is opened to verify each users password once the DN is found.&lt;br /&gt;
 &lt;br /&gt;
       -R     do not follow referrals&lt;br /&gt;
 &lt;br /&gt;
       -a never|always|search|find&lt;br /&gt;
              when to dereference aliases. Defaults to 'never'&lt;br /&gt;
 &lt;br /&gt;
              never dereference aliases (default), always dereference aliases, only while searching or only to find the base object&lt;br /&gt;
 &lt;br /&gt;
       -H ldapuri&lt;br /&gt;
              Specity the LDAP server to connect to by LDAP URI (requires OpenLDAP libraries).  Servers can also be specified last on the command line.&lt;br /&gt;
 &lt;br /&gt;
       -h ldapserver&lt;br /&gt;
              Specify the LDAP server to connect to. Servers can also be specified last on the command line.&lt;br /&gt;
 &lt;br /&gt;
       -p ldapport&lt;br /&gt;
              Specify  an alternate TCP port where the ldap server is listening if other than the default LDAP port 389. Can also be specified within the server specificia‐&lt;br /&gt;
              tion by using servername:port syntax.&lt;br /&gt;
 &lt;br /&gt;
       -v 2|3 LDAP protocol version. Defaults to 2 if not specified.&lt;br /&gt;
 &lt;br /&gt;
       -Z     Use TLS encryption&lt;br /&gt;
 &lt;br /&gt;
       -Scertpath&lt;br /&gt;
              Enable LDAP over SSL (requires Netscape LDAP API libraries)&lt;br /&gt;
 &lt;br /&gt;
       -cconnect_timeout&lt;br /&gt;
              Specify timeout used when connecting to LDAP servers (requires Netscape LDAP API libraries)&lt;br /&gt;
 &lt;br /&gt;
       -tsearch_timeout&lt;br /&gt;
              Specify time limit on LDAP search operations&lt;br /&gt;
 &lt;br /&gt;
       -d     Debug mode where each step taken will get reported in detail.  Useful for understanding what goes wrong if the results is not what is expected.&lt;br /&gt;
 &lt;br /&gt;
 EXAMPLES&lt;br /&gt;
       For directories using the RFC2307 layout with a single domain, all you need to specify is usually the base DN under where your users are located and the server name:&lt;br /&gt;
 &lt;br /&gt;
              squid_ldap_auth -b &amp;quot;ou=people,dc=your,dc=domain&amp;quot; ldapserver&lt;br /&gt;
 &lt;br /&gt;
       If you have sub-domains then you need to use a search filter approach to locate your user DNs as these can no longer be constructed direcly  from  the  base  DN  and&lt;br /&gt;
       login name alone:&lt;br /&gt;
 &lt;br /&gt;
              squid_ldap_auth -b &amp;quot;dc=your,dc=domain&amp;quot; -f &amp;quot;uid=%s&amp;quot; ldapserver&lt;br /&gt;
 &lt;br /&gt;
       And similarily if you only want to allow access to users having a specific attribute&lt;br /&gt;
 &lt;br /&gt;
              squid_ldap_auth -b &amp;quot;dc=your,dc=domain&amp;quot; -f &amp;quot;(&amp;amp;(uid=%s)(specialattribute=value))&amp;quot; ldapserver&lt;br /&gt;
 &lt;br /&gt;
       Or  if the user attribute of the user DN is &amp;quot;cn&amp;quot; instead of &amp;quot;uid&amp;quot; and you do not want to have to search for the users then you could use something like the following&lt;br /&gt;
       example for Active Directory:&lt;br /&gt;
 &lt;br /&gt;
              squid_ldap_auth -u cn -b &amp;quot;cn=Users,dc=your,dc=domain&amp;quot; ldapserver&lt;br /&gt;
 &lt;br /&gt;
       If you want to search for the user DN and your directory does not allow anonymous searches then you must also use the -D and -w flags to specify a user DN and  pass‐&lt;br /&gt;
       word to log in as to perform the searches, as in the following complex Active Directory example&lt;br /&gt;
 &lt;br /&gt;
              squid_ldap_auth  -P  -R -b &amp;quot;dc=your,dc=domain&amp;quot; -D &amp;quot;cn=squid,cn=users,dc=your,dc=domain&amp;quot; -w &amp;quot;secretsquidpassword&amp;quot; -f &amp;quot;(&amp;amp;(userPrincipalName=%s)(objectClass=Per‐&lt;br /&gt;
              son))&amp;quot; activedirectoryserver&lt;br /&gt;
 &lt;br /&gt;
 NOTES&lt;br /&gt;
       When constructing search filters it is strongly recommended to test the filter using ldapsearch before you attempt to use squid_ldap_auth. This to  verify  that  the&lt;br /&gt;
       filter matches what you expect.&lt;br /&gt;
 &lt;br /&gt;
 AUTHOR&lt;br /&gt;
       This manual page was written by Henrik Nordstrom &amp;lt;hno@squid-cache.org&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
       squid_ldap_auth is written by Glenn Newton &amp;lt;gnewton@wapiti.cisti.nrc.ca&amp;gt; and Henrik Nordstrom &amp;lt;hno@squid-cache.org&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 KNOWN ISSUES&lt;br /&gt;
       Will crash if other % values than %s is used in -f, or if more than 15 %s is used.&lt;br /&gt;
&lt;br /&gt;
 QUESTIONS&lt;br /&gt;
       Any  questions  on  usage can be sent to Squid Users &amp;lt;squid-users@squid-cache.org&amp;gt;, or to your favorite LDAP list/friend if the question is more related to LDAP than&lt;br /&gt;
       Squid.&lt;br /&gt;
 &lt;br /&gt;
 REPORTING BUGS&lt;br /&gt;
       Report bugs or bug-fixes to Squid Bugs &amp;lt;squid-bugs@squid-cache.org&amp;gt; or ideas for new improvements to Squid Developers &amp;lt;squid-dev@squid-cache.org&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 SEE ALSO&lt;br /&gt;
       ldapsearch(1),&lt;br /&gt;
       Your favorite LDAP documentation&lt;br /&gt;
       RFC2254 - The String Representation of LDAP Search Filters,&lt;br /&gt;
&lt;br /&gt;
===Configuració ===&lt;br /&gt;
&lt;br /&gt;
El helper per a Ldap el trobareu al fitxer:&lt;br /&gt;
&lt;br /&gt;
 $ [[file]] /usr/lib/squid3/squid_ldap_auth&lt;br /&gt;
 /usr/lib/squid3/squid_ldap_auth: ELF 64-bit LSB executable, x86-64, version 1 (SYSV), dynamically linked (uses shared libs), for GNU/Linux 2.6.15, stripped&lt;br /&gt;
&lt;br /&gt;
Es tracta d'un executable.&lt;br /&gt;
&lt;br /&gt;
A la configuració d'Squid cal posar quelcom similar a:&lt;br /&gt;
&lt;br /&gt;
 auth_param basic program /usr/lib/squid/squid_ldap_auth -v 3 -b &amp;quot;dc=yourcompany,dc=com&amp;quot; -D uid=some-user,ou=People,dc=yourcompany,dc=com  -w password -f uid=%s   &lt;br /&gt;
 ldap.yourcompany.com&lt;br /&gt;
  &lt;br /&gt;
 auth_param basic children 5&lt;br /&gt;
 auth_param basic realm Web-Proxy&lt;br /&gt;
 auth_param basic credentialsttl 1 minute&lt;br /&gt;
 &lt;br /&gt;
 acl ldap-auth proxy_auth REQUIRED&lt;br /&gt;
 &lt;br /&gt;
 http_access allow ldap-auth&lt;br /&gt;
 http_access allow localhost&lt;br /&gt;
 http_access deny all&lt;br /&gt;
&lt;br /&gt;
On:&lt;br /&gt;
&lt;br /&gt;
:*'''-b''': defineix el context (la branca de l'arbre Ldap) on voleu buscar usuaris que tinguin accés al proxy.&lt;br /&gt;
:*'''-h''': Defineix el nom de màquina del servidor Ldap al qual us voleu connectar.&lt;br /&gt;
:*'''-D''': Usuari que es connecta al directori Ldap. Si no l'indiqueu la connexió serà anònima&lt;br /&gt;
:*'''-w'': Paraula de pas de l'usuari. No es posa si la connexió és anònima.&lt;br /&gt;
:*'''Filtre (-f)''': Filtre que s'ha d'aplicar al cerca usuaris: a l'exemple es busca per l'atribut '''uid''' (user identifier). %s és el nom que introdueix l'usuari al intentar.se connectar. &lt;br /&gt;
&lt;br /&gt;
{{important| Fitxeu-vos que l'anterior configuració no és gens segura, per diverses raons: la paraula de pas del servidor Ldap es guarda sense xifrar en un fitxer de text, a més si feu $ ps aux | grep squid, també veureu els helpers executant-se i apareixerà la paraula de pas}}&lt;br /&gt;
&lt;br /&gt;
El millor que podeu fer és connectar-vos al servidor Ldap anònimament, sense especificar la paraula de pas ni el usuari:&lt;br /&gt;
&lt;br /&gt;
 auth_param basic program /usr/lib/squid/squid_ldap_auth -v 3 -b &amp;quot;dc=yourcompany,dc=com&amp;quot;  -f uid=%s   &lt;br /&gt;
&lt;br /&gt;
:*http://wiki.squid-cache.org/ConfigExamples/Authenticate/Ldap&lt;br /&gt;
&lt;br /&gt;
=== Utilitzar grups Ldap ===&lt;br /&gt;
&lt;br /&gt;
TODO:&lt;br /&gt;
&lt;br /&gt;
In addition to simple authentication you may also want to grant different privileges to different users. The easiest way is to use LDAP groups. A group is just a list of dinstiguished names. Example group:&lt;br /&gt;
&lt;br /&gt;
    * dn=cn=Tim,ou=IT-Services,o=Company&lt;br /&gt;
    * dn=cn=Tina,ou=Management,o=Company&lt;br /&gt;
&lt;br /&gt;
Assume that these two users are allowed to use Google where all other users are not allowed. First you need to define the LDAP group mapping: &lt;br /&gt;
&lt;br /&gt;
external_acl_type ldapgroup %LOGIN /usr/lib/squid/squid_ldap_group -b o=Company&lt;br /&gt;
   -f (&amp;amp;(objectclass=person)(cn=%v)(groupMembership=cn=%a,ou=Proxygroups,o=Company))&lt;br /&gt;
   -D cn=Tim,ou=IT-Services,o=Company -w timspassword -h ldapserver&lt;br /&gt;
&lt;br /&gt;
The filter expression looks a little complicated. It just means that we are looking for any user (person) with the name we are looking for (%v) who is a member of the group we are looking for (groupMembership). You can now just create any number of groups in the tree like&lt;br /&gt;
&lt;br /&gt;
 cn=googleallowed,ou=Proxygroups,o=Company&lt;br /&gt;
&lt;br /&gt;
Then this pile of ACLs should block off everyone from google.com who is not a member of that group: &lt;br /&gt;
&lt;br /&gt;
 acl ldapgroup-googleallowed external ldapgroup googleallowed&lt;br /&gt;
 acl google dstdomain google.com&lt;br /&gt;
 http_access deny google !ldapgroup-googleallowed&lt;br /&gt;
&lt;br /&gt;
You may be curious how such a group authorizator works. Simple. It just reads line after line from STDIN (like the console) where each line looks like&lt;br /&gt;
&lt;br /&gt;
 username groupname&lt;br /&gt;
&lt;br /&gt;
and returns either OK or ERR depending on whether the user is a member of that group or not.&lt;br /&gt;
&lt;br /&gt;
:*http://workaround.org/squid-ldap&lt;br /&gt;
=== Recursos===&lt;br /&gt;
&lt;br /&gt;
*http://www.babilonics.com/content/como-instalar-squid-en-debian-con-autentificacion-ldap-por-grupos-de-windows-2003&lt;br /&gt;
*http://linkat.xtec.cat/portal_linkat/wikilinkat/index.php/Squid_Ldap&lt;br /&gt;
*http://workaround.org/squid-ldap&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Authenticate/Ldap&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Authenticate/WindowsActiveDirectory&lt;br /&gt;
&lt;br /&gt;
==Script per tal que els usuaris puguin canviar-se la paraula de pas==&lt;br /&gt;
&lt;br /&gt;
*http://www.squid-cache.org/htpasswd/&lt;br /&gt;
&lt;br /&gt;
==MySQL==&lt;br /&gt;
&lt;br /&gt;
{{nota| El paquet binari que es pot baixar dels repositoris d'Ubuntu no està compilat per suportar base de dades. Cal compilar Squid a partir de codi font:}}&lt;br /&gt;
&lt;br /&gt;
 $ sudo wget http://www.squid-cache.org/Versions/v2/2.7/squid-2.7.STABLE3.tar.gz&lt;br /&gt;
 $ sudo mv squid-2.7.STABLE3.tar.gz /opt&lt;br /&gt;
 $ cd /opt&lt;br /&gt;
 $ sudo tar zxvf squid-2.7.STABLE3.tar.gz&lt;br /&gt;
 $ sudo cd /opt/squid-2.7.STABLE&lt;br /&gt;
 $ sudo ./configure –enable-basic-auth-helpers=DB&lt;br /&gt;
 $ sudo make&lt;br /&gt;
 $ make install&lt;br /&gt;
 $ sudo cp /usr/local/squid/libexec/squid_db_auth /opt&lt;br /&gt;
 $ sudo rm -rf squid-2.7.STABLE&lt;br /&gt;
 $ rm -rf /usr/local/squid&lt;br /&gt;
 $ sudo apt-get install squid3&lt;br /&gt;
 $ sudo cp /opt/squid_db_auth /usr/lib/squid&lt;br /&gt;
&lt;br /&gt;
*http://www.ideaglu.net/?p=1732&lt;br /&gt;
&lt;br /&gt;
==Logging==&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Authenticate/LoggingOnly&lt;br /&gt;
&lt;br /&gt;
=Eines gràfiques=&lt;br /&gt;
&lt;br /&gt;
==Squid a Webmin==&lt;br /&gt;
&lt;br /&gt;
El mòdul Squid de Webmin esta pensat per a la versió 1 d'Squid. Per que funcioni correctament amb la versió 3 cal modificar la configuració del mòdul (part superior esquerrà '''Module Config'''):&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidwebminConfiguracio.png]]&lt;br /&gt;
&lt;br /&gt;
El fitxer de configuració és:&lt;br /&gt;
&lt;br /&gt;
 /etc/squid3/squid.conf&lt;br /&gt;
&lt;br /&gt;
=Rendiment (Performance)=&lt;br /&gt;
&lt;br /&gt;
*Sistema operatiu Linux&lt;br /&gt;
*Evitar l'ús de swap&lt;br /&gt;
*Sistema de fitxers: Tots van aprox. igual de bé&lt;br /&gt;
*Evitar RAID. Consulteu http://wiki.squid-cache.org/SquidFaq/RAID&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/BestOsForSquid&lt;br /&gt;
&lt;br /&gt;
==Monitoritzar el rendiment==&lt;br /&gt;
&lt;br /&gt;
Ús de la memòria:&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | grep arena&lt;br /&gt;
 	Total space in arena:    8180 KB&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | grep Resident&lt;br /&gt;
	Maximum Resident Size: 0 KB&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | grep sbrk&lt;br /&gt;
	Process Data Segment Size via sbrk(): 7904 KB&lt;br /&gt;
&lt;br /&gt;
Es pot consultar el nombre de '''Page faults''' amb:&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | grep 'Page faults'&lt;br /&gt;
 Page faults with physical i/o: 0&lt;br /&gt;
&lt;br /&gt;
Una page fault succeix quan el procés squid ha d'accedir a un àrea de memòria de la swap, es a dir, quan squid està utilitzant la swap. ES recomanable que això no passi mai (a poder ser) i per tant quan més baix sigui el número de page faults millor. Cal tenir en compte que el valor mostrar és el moment en que s'executa. Podeu executar:&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:5min | grep page_fault&lt;br /&gt;
 page_faults = 0.000000/sec&lt;br /&gt;
 &lt;br /&gt;
 $ squidclient mgr:60min | grep page_fault&lt;br /&gt;
 page_faults = 0.000000/sec&lt;br /&gt;
&lt;br /&gt;
Per obtenir els rates dels últims 5 minuts i dels últims 60 minuts.&lt;br /&gt;
&lt;br /&gt;
També és interessant el paràmetre quantitat de peticions HTTP:&lt;br /&gt;
&lt;br /&gt;
 # squidclient mgr:info | grep 'Number of HTTP requests'&lt;br /&gt;
 Number of HTTP requests received:       535805&lt;br /&gt;
&lt;br /&gt;
Es poden consultar uns rates amb:&lt;br /&gt;
&lt;br /&gt;
 # squidclient mgr:info | grep 'Average HTTP requests'&lt;br /&gt;
 Average HTTP requests per minute since start:   108.4&lt;br /&gt;
 # squidclient mgr:5min | grep 'client_http.requests'&lt;br /&gt;
 client_http.requests = 3.002991/sec&lt;br /&gt;
 # squidclient mgr:60min | grep 'client_http.requests'&lt;br /&gt;
 client_http.requests = 2.636987/sec&lt;br /&gt;
&lt;br /&gt;
'''Temps de servei (mediana)''':&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | more&lt;br /&gt;
 ...&lt;br /&gt;
 Median Service Times (seconds)  5 min    60 min:&lt;br /&gt;
 	HTTP Requests (All):   0.07825  0.32154&lt;br /&gt;
 	Cache Misses:          0.61549  0.72387&lt;br /&gt;
 	Cache Hits:            0.00000  0.00000&lt;br /&gt;
 	Near Hits:             0.10281  0.19742&lt;br /&gt;
 	Not-Modified Replies:  0.00000  0.00000&lt;br /&gt;
 	DNS Lookups:           0.84544  0.56687&lt;br /&gt;
  	ICP Queries:           0.00000  0.00000&lt;br /&gt;
&lt;br /&gt;
 # squidclient mgr:5min | grep client_http.all_median_svc_time&lt;br /&gt;
 client_http.all_median_svc_time = 0.127833 seconds&lt;br /&gt;
&lt;br /&gt;
Warning:&lt;br /&gt;
&lt;br /&gt;
 high_response_time_warning 700&lt;br /&gt;
&lt;br /&gt;
'''Temps de resposta DNS''':&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:5min | grep dns.median_svc_time&lt;br /&gt;
 dns.median_svc_time = 1.055573 seconds&lt;br /&gt;
 $ squidclient mgr:60min | grep dns.median_svc_time&lt;br /&gt;
 dns.median_svc_time = 0.677101 seconds&lt;br /&gt;
&lt;br /&gt;
'''Número de descriptors de fitxers''':&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:info | grep 'Number of file desc currently in use'&lt;br /&gt;
 	Number of file desc currently in use:  425&lt;br /&gt;
&lt;br /&gt;
'''Ús de CPU'''&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:60min | grep cpu_usage &lt;br /&gt;
&lt;br /&gt;
'''Informació de l'store dir''':&lt;br /&gt;
&lt;br /&gt;
 $ squidclient mgr:storedir&lt;br /&gt;
 HTTP/1.0 200 OK&lt;br /&gt;
 Server: squid/3.0.STABLE18&lt;br /&gt;
 Mime-Version: 1.0&lt;br /&gt;
 Date: Mon, 17 May 2010 10:36:35 GMT&lt;br /&gt;
 Content-Type: text/plain&lt;br /&gt;
 Expires: Mon, 17 May 2010 10:36:35 GMT&lt;br /&gt;
 Last-Modified: Mon, 17 May 2010 10:36:35 GMT&lt;br /&gt;
 X-Cache: MISS from localhost&lt;br /&gt;
 X-Cache-Lookup: MISS from localhost:3128&lt;br /&gt;
 Via: 1.0 localhost (squid/3.0.STABLE18)&lt;br /&gt;
 Proxy-Connection: close&lt;br /&gt;
 &lt;br /&gt;
 Store Directory Statistics:&lt;br /&gt;
 Store Entries          : 5319&lt;br /&gt;
 Maximum Swap Size      :   102400 KB&lt;br /&gt;
 Current Store Swap Size:    92160 KB&lt;br /&gt;
 Current Capacity       : 90% used, 10% free  &lt;br /&gt;
 &lt;br /&gt;
 Store Directory #0 (ufs): /var/spool/squid3&lt;br /&gt;
 FS Block Size 4096 Bytes&lt;br /&gt;
 First level subdirectories: 16&lt;br /&gt;
 Second level subdirectories: 256&lt;br /&gt;
 Maximum Size: 102400 KB&lt;br /&gt;
 Current Size: 92160 KB&lt;br /&gt;
 '''Percent Used: 90.00%'''&lt;br /&gt;
 Filemap bits in use: 5256 of 16384 (32%)&lt;br /&gt;
 '''Filesystem Space in use: 17521760/206424760 KB (8%)'''&lt;br /&gt;
 Filesystem Inodes in use: 106527/13107200 (1%)&lt;br /&gt;
 Flags: SELECTED&lt;br /&gt;
 Removal policy: lru&lt;br /&gt;
 LRU reference age: 0.02 days&lt;br /&gt;
&lt;br /&gt;
:*http://onlamp.com/pub/a/onlamp/2004/03/25/squid.html&lt;br /&gt;
&lt;br /&gt;
===Squid-rrd===&lt;br /&gt;
&lt;br /&gt;
Podeu trobar els fitxers a:&lt;br /&gt;
&lt;br /&gt;
 http://acacha.org/~sergi/squid-rrd.tar.gz&lt;br /&gt;
&lt;br /&gt;
Els passos seguits per instal·lar squid-rrd a una Ubuntu han estat:&lt;br /&gt;
&lt;br /&gt;
 $ cd /var/www/&lt;br /&gt;
 $ sudo mkdir squid-rrd/&lt;br /&gt;
 $ cd squid-rrd/&lt;br /&gt;
 $ sudo wget http://www.squid-cache.org/~wessels/squid-rrd/poll.pl&lt;br /&gt;
 $ sudo wget http://www.squid-cache.org/~wessels/squid-rrd/create.sh&lt;br /&gt;
 $ sudo wget http://www.squid-cache.org/~wessels/squid-rrd/1day-cgi&lt;br /&gt;
 $ sudo wget http://www.squid-cache.org/~wessels/squid-rrd/htaccess&lt;br /&gt;
 $ sudo mv htaccess .htaccess&lt;br /&gt;
 $ sudo mv 1day-cgi 1day.cgi &lt;br /&gt;
 $ sudo chmod +x ./create.sh &lt;br /&gt;
 $ sudo ./create.sh &lt;br /&gt;
&lt;br /&gt;
Canvieu els shebangs que molts apunten a fitxers de /usr/share/local.&lt;br /&gt;
&lt;br /&gt;
 $ sudo perl poll.pl localhost&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe /etc/cron.d/squid-rdd&lt;br /&gt;
&lt;br /&gt;
Afegiu la línia:&lt;br /&gt;
&lt;br /&gt;
 */5 * * * * root /var/www/squid-rrd/poll.pl localhost&lt;br /&gt;
 &lt;br /&gt;
Canvieu la línia on s'indica el path de l'eina rrdtool a:&lt;br /&gt;
&lt;br /&gt;
 my $rrdtool = '/usr/bin/rrdtool';&lt;br /&gt;
&lt;br /&gt;
 $ sudo chmod +x /var/www/squid-rrd/poll.pl &lt;br /&gt;
&lt;br /&gt;
Proveu l'script:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /var/www/squid-rrd/poll.pl localhost&lt;br /&gt;
&lt;br /&gt;
Configureu apache:&lt;br /&gt;
&lt;br /&gt;
 $ cd /etc/apache2/conf.d/&lt;br /&gt;
 $ sudo joe squid-rrd&lt;br /&gt;
&lt;br /&gt;
Afegiu:&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;Directory &amp;quot;/var/www/squid-rrd&amp;quot;&amp;gt;&lt;br /&gt;
  AllowOverride Indexes&lt;br /&gt;
  Options +ExecCGI&lt;br /&gt;
  AddHandler cgi-script .cgi&lt;br /&gt;
 &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 $ sudo a2enmod expires&lt;br /&gt;
 $ sudo /etc/init.d/apache2 restart&lt;br /&gt;
 $ cd /var/www/squid-rrd/&lt;br /&gt;
 $ sudo chmod 775 .&lt;br /&gt;
 $ sudo chown www-data:www-data .&lt;br /&gt;
&lt;br /&gt;
Al fitxer:&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe /var/www/squid-rrd/1day.cgi&lt;br /&gt;
&lt;br /&gt;
Canvieu el path de l'eina 1day.cgi al [[shebang]] poseu:&lt;br /&gt;
&lt;br /&gt;
 #!/usr/bin/rrdcgi&lt;br /&gt;
&lt;br /&gt;
I finalment:&lt;br /&gt;
&lt;br /&gt;
 $ sudo chmod +x /var/www/squid-rrd/1day.cgi&lt;br /&gt;
&lt;br /&gt;
:*http://www.squid-cache.org/~wessels/squid-rrd/&lt;br /&gt;
&lt;br /&gt;
==Benchmark==&lt;br /&gt;
&lt;br /&gt;
:*http://www.web-polygraph.org/&lt;br /&gt;
:*http://www.web-cache.com/benchmarking.html&lt;br /&gt;
&lt;br /&gt;
=Monitoritzar=&lt;br /&gt;
&lt;br /&gt;
Es pot utilitzar [[SNMP]], per activar SNMP al servidor Squid cal primer definir una ACL. Per exemple, al fitxer [[/etc/squid3/squid.conf]]:&lt;br /&gt;
&lt;br /&gt;
 acl snmppublic snmp_community public&lt;br /&gt;
&lt;br /&gt;
El port per defecte on squid escolta peticions SNMP és el 3401. Es pot canviar amb:&lt;br /&gt;
&lt;br /&gt;
 snmp_port 3401&lt;br /&gt;
&lt;br /&gt;
Per permetre que l'agent SNMP pugui fer consultes al servidor Squid:&lt;br /&gt;
&lt;br /&gt;
 snmp_access allow snmppublic localhost &lt;br /&gt;
 snmp_access deny all&lt;br /&gt;
&lt;br /&gt;
L'anterior configuració només permet l'accés a Squid per SNMP des de la màquina localhost.&lt;br /&gt;
&lt;br /&gt;
{{nota| Si no es defineix cap accés SNMP concret per defecte l'accés és denegat}}&lt;br /&gt;
&lt;br /&gt;
Finalment es pot definir a quines interfícies escoltar peticions SNMP&lt;br /&gt;
&lt;br /&gt;
 snmp_incoming_address 0.0.0.0&lt;br /&gt;
 snmp_outgoing_address 0.0.0.0 &lt;br /&gt;
&lt;br /&gt;
Que són els valors per defecte (totes les interfícies)&lt;br /&gt;
&lt;br /&gt;
:*http://wiki.squid-cache.org/Features/Snmp&lt;br /&gt;
&lt;br /&gt;
== Cacti==&lt;br /&gt;
&lt;br /&gt;
Es poden exportar una gràfiques de Cacti, utilitzant plantilles en format XML que trobareu a:&lt;br /&gt;
&lt;br /&gt;
:*http://forums.cacti.net/about4142.html&lt;br /&gt;
&lt;br /&gt;
Utilitzeu el menú Importar plantilles de Cacti. Abans cal haver activat SNMP a Squid tal com s'ha comentat a l'apartat anterior.&lt;br /&gt;
&lt;br /&gt;
=Jerarquia d'Squids o Squid distribuit. Squid Mesh=&lt;br /&gt;
&lt;br /&gt;
 TODO&lt;br /&gt;
&lt;br /&gt;
Els protocols utilitzats són:&lt;br /&gt;
&lt;br /&gt;
:*'''[http://en.wikipedia.org/wiki/Internet_Cache_Protocol ICP (Internet Cache Protocol)]''': Protocol bàsic per a fer cache distribüida.&lt;br /&gt;
:*'''[http://en.wikipedia.org/wiki/Hypertext_caching_protocol HTCP (Hypertext_caching_protocol)]''': Definit com el successor de ICP.&lt;br /&gt;
&lt;br /&gt;
{{nota|Tingueu en compte que a la configuració per defecte està impedit l'accés a aquest protocols.}}&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/Features/CacheHierarchy&lt;br /&gt;
&lt;br /&gt;
=Filtrar continguts=&lt;br /&gt;
&lt;br /&gt;
==Com indicar acls que no passaran pel redirector ==&lt;br /&gt;
&lt;br /&gt;
Podeu utilitzar [[redirector_access]]&lt;br /&gt;
&lt;br /&gt;
==Com aplicar múltiples redirectors==&lt;br /&gt;
&lt;br /&gt;
[[IPCOP]] ho fa quan per exemple es te instal·lat el plugin [[urlfilter]] &lt;br /&gt;
&lt;br /&gt;
A [[squid.conf]]:&lt;br /&gt;
&lt;br /&gt;
 ...&lt;br /&gt;
 url_rewrite_program /usr/sbin/redirect_wrapper&lt;br /&gt;
 url_rewrite_children 50&lt;br /&gt;
 ...&lt;br /&gt;
&lt;br /&gt;
El fitxer '''/usr/sbin/redirect_wrapper''' conté:&lt;br /&gt;
&lt;br /&gt;
 $ cat /usr/sbin/redirect_wrapper&lt;br /&gt;
 #!/bin/sh&lt;br /&gt;
 /usr/sbin/squidGuard | /usr/sbin/updxlrator&lt;br /&gt;
&lt;br /&gt;
Per tant amb una simple pipe es poden aplicar múltiples redirectors.&lt;br /&gt;
&lt;br /&gt;
==Impedir missatgeria instantània==&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples#Instant_Messaging_.2BAC8_Chat_Program_filtering&lt;br /&gt;
&lt;br /&gt;
===Messenger===&lt;br /&gt;
&lt;br /&gt;
Prèviament cal haver xapat amb iptables el port '''1836'''&lt;br /&gt;
&lt;br /&gt;
{{nota| S'ha observat que també cal tancar l'accés a hotmnail per tal d'impedir que les últimes versions de messenger funcionin}}&lt;br /&gt;
&lt;br /&gt;
 # MSN Messenger&lt;br /&gt;
 &lt;br /&gt;
 acl msn urlpath_regex -i gateway.dll&lt;br /&gt;
 acl msnd dstdomain messenger.msn.com gateway.messenger.hotmail.com&lt;br /&gt;
 acl msn1 req_mime_type application/x-msn-messenger&lt;br /&gt;
 &lt;br /&gt;
 http_access deny msnd&lt;br /&gt;
 http_access deny msn&lt;br /&gt;
 http_access deny msn1&lt;br /&gt;
 &lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Chat/MsnMessenger&lt;br /&gt;
&lt;br /&gt;
==Impedir eines de navegació anònima==&lt;br /&gt;
&lt;br /&gt;
Consulteu [[Com evitar les eines de navegació anònima]]. S'indica entre d'altres com prevenir [[Tor]], [[Ultrasurf]] i [[Proxies anònims]].&lt;br /&gt;
&lt;br /&gt;
*http://administradores.educarex.es/wiki/index.php/Proxy_cach%C3%A9_y_filtrador_web:_squid&lt;br /&gt;
&lt;br /&gt;
==Impedir Streaming==&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples#Instant_Messaging_.2BAC8_Chat_Program_filtering&lt;br /&gt;
&lt;br /&gt;
===Youtube===&lt;br /&gt;
&lt;br /&gt;
 http://www.bellera.cat/josep/videocache/&lt;br /&gt;
 http://cachevideos.com/&lt;br /&gt;
&lt;br /&gt;
 ## The videos come from several domains&lt;br /&gt;
 acl youtube_domains dstdomain .youtube.com .googlevideo.com .ytimg.com &lt;br /&gt;
 &lt;br /&gt;
 http_access deny youtube_domains&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/Streams/YouTube&lt;br /&gt;
&lt;br /&gt;
====Fer cache de youtube====&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/DynamicContent/YouTube&lt;br /&gt;
&lt;br /&gt;
==Redirectors==&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/Features/Redirectors&lt;br /&gt;
&lt;br /&gt;
===Squirm===&lt;br /&gt;
&lt;br /&gt;
*http://squirm.foote.com.au/&lt;br /&gt;
&lt;br /&gt;
===Redirectors a mida===&lt;br /&gt;
&lt;br /&gt;
====PHP====&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/ConfigExamples/PhpRedirectors&lt;br /&gt;
&lt;br /&gt;
====Cada X temps enviar a una pàgina concreta ====&lt;br /&gt;
&lt;br /&gt;
 #&lt;br /&gt;
 # startpage.pl (Squid Proxy Redirector)&lt;br /&gt;
 # joan.llopart@guifi.net 03-2008&lt;br /&gt;
 &lt;br /&gt;
 # Redirects proxy user to a defined startpage every certain time.&lt;br /&gt;
 &lt;br /&gt;
 use strict;&lt;br /&gt;
 &lt;br /&gt;
 #&lt;br /&gt;
 # --- CONFIG ---&lt;br /&gt;
 #&lt;br /&gt;
 # Startpage will be shown every ... (time in seconds)&lt;br /&gt;
 my $ref_time = 3600; # 1 hour&lt;br /&gt;
 #&lt;br /&gt;
 # Redirection to this webpage&lt;br /&gt;
 my $startp = &amp;quot;302:http://guifi.net&amp;quot;;&lt;br /&gt;
 #&lt;br /&gt;
 # Directory to save user/timestamp DB&lt;br /&gt;
 # (squid owner needs write permissions in this directory)&lt;br /&gt;
 my $dat_dir = &amp;quot;/tmp&amp;quot;;&lt;br /&gt;
 #&lt;br /&gt;
 # Track users by IP or username. Username only effective if proxy uses&lt;br /&gt;
 # some kind of authentication.&lt;br /&gt;
 my $match = &amp;quot;user&amp;quot;; # user / IP&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 # Autoflush STDOUT on each printed character&lt;br /&gt;
 local $| = 1; &lt;br /&gt;
 &lt;br /&gt;
 $SIG{INT} = sub { die &amp;quot;Bye!&amp;quot;; };&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 while ( 1 ) {&lt;br /&gt;
 &lt;br /&gt;
   # Get stuff from squid&lt;br /&gt;
   my $buff_in = &amp;lt;&amp;gt;;&lt;br /&gt;
   chomp( $buff_in );    &lt;br /&gt;
   my ( $url, $src_add, $ident, $method) = split( / /, $buff_in );&lt;br /&gt;
 &lt;br /&gt;
   # Quits if squid does&lt;br /&gt;
   if( !$url || !$src_add || !$ident || !$method ) { die(&amp;quot;Bye!&amp;quot;); };&lt;br /&gt;
 &lt;br /&gt;
   # Match by username or IP&lt;br /&gt;
   my $id = ($match eq &amp;quot;user&amp;quot;) ? $ident : $src_add;&lt;br /&gt;
 &lt;br /&gt;
   # Check user's timestamp &lt;br /&gt;
   open(DATA, &amp;quot;&amp;lt;$dat_dir/startpage.dat&amp;quot;);&lt;br /&gt;
   my $newdat='';&lt;br /&gt;
   # (flag1) 0 = new user / 1 = timestamp OK / 2 = update timestamp&lt;br /&gt;
   my $flag1=0; &lt;br /&gt;
   while ( my $line=&amp;lt;DATA&amp;gt; ) {&lt;br /&gt;
     chomp($line);&lt;br /&gt;
     my( $user, $ltime ) = split( /:/, $line );&lt;br /&gt;
     if( $user eq $id ) {&lt;br /&gt;
       $flag1=1;&lt;br /&gt;
       if( ($ltime + $ref_time) &amp;lt; time() ) {&lt;br /&gt;
         $flag1=2;&lt;br /&gt;
         $ltime=time();&lt;br /&gt;
       }&lt;br /&gt;
     } &lt;br /&gt;
     $newdat.=&amp;quot;$user:$ltime\n&amp;quot;;    &lt;br /&gt;
   }&lt;br /&gt;
  close(DATA);  &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
   # If new user or user timestamp changed, update DB&lt;br /&gt;
   if( $flag1!=1 ) {&lt;br /&gt;
     # New user? add it ...&lt;br /&gt;
     if( !$flag1 ) { $newdat.=&amp;quot;$id:&amp;quot;.time().&amp;quot;\n&amp;quot;; }&lt;br /&gt;
     open(DATA, &amp;quot;&amp;gt;$dat_dir/startpage.dat&amp;quot;);&lt;br /&gt;
     print DATA $newdat;&lt;br /&gt;
     close(DATA);&lt;br /&gt;
   }&lt;br /&gt;
 &lt;br /&gt;
   # Show startpage if necessary&lt;br /&gt;
   if( $flag1!=1 ) {&lt;br /&gt;
     print $startp.&amp;quot; &amp;quot;.$src_add.&amp;quot; &amp;quot;.$ident.&amp;quot; &amp;quot;.$method.&amp;quot;\n&amp;quot;;&lt;br /&gt;
   } else {&lt;br /&gt;
     print $url.&amp;quot; &amp;quot;.$src_add.&amp;quot; &amp;quot;.$ident.&amp;quot; &amp;quot;.$method.&amp;quot;\n&amp;quot;;&lt;br /&gt;
   }&lt;br /&gt;
   &lt;br /&gt;
 &lt;br /&gt;
 } # while( 1 ) &lt;br /&gt;
 &lt;br /&gt;
El poseu en el lloc que us agradi mes, en aquest l'exemple l'he guardat a /home/joan/scripts, amb el nom startpage.pl. Editeu el /etc/squid/squid.conf, busqueu on hi ha el Tag de url_rewrite_program i hi afegiu:&lt;br /&gt;
&lt;br /&gt;
 url_rewrite_program /home/joan/scripts/startpage.pl&lt;br /&gt;
&lt;br /&gt;
*http://www.guifi.net/node/14092&lt;br /&gt;
*http://www.guifi.net/ca/node/3567&lt;br /&gt;
&lt;br /&gt;
===SquidGuard===&lt;br /&gt;
&lt;br /&gt;
Consulteu&lt;br /&gt;
&lt;br /&gt;
 [[SquidGuard]]&lt;br /&gt;
&lt;br /&gt;
==DansGuardian==&lt;br /&gt;
&lt;br /&gt;
Consulteu:&lt;br /&gt;
&lt;br /&gt;
 [[DansGuardian]]&lt;br /&gt;
&lt;br /&gt;
==IPCOP==&lt;br /&gt;
&lt;br /&gt;
Consulteu [[IPCOP]]&lt;br /&gt;
&lt;br /&gt;
===Configuració d'Squid a IPCOP===&lt;br /&gt;
&lt;br /&gt;
Consulteu [[IPCOP#Proxy_SQUID]]&lt;br /&gt;
&lt;br /&gt;
Fòrum en castellà de pfSense, http://forum.pfsense.org/index.php/board,10.0.html (administrat per www.bellera.cat/josep/consultes)&lt;br /&gt;
&lt;br /&gt;
=Informes=&lt;br /&gt;
&lt;br /&gt;
==Squidtaild==&lt;br /&gt;
&lt;br /&gt;
 Definition: squidtaild: Squid log monitoring program Squidtaild is a very fast, highly configurable Perl program that will dynamicly create html pages that display the &lt;br /&gt;
 violations that people made one or more of the filters you have applied to the squid proxy logging system.&lt;br /&gt;
&lt;br /&gt;
==squidview==&lt;br /&gt;
&lt;br /&gt;
 $ apt-cache search squidview&lt;br /&gt;
 squidview - monitors and analyses squid access.log files&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Calamaris==&lt;br /&gt;
&lt;br /&gt;
En sistemes [[Debian]] com [[Ubuntu]] és pot instal·lar des dels [[repositoris]] amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[apt-get]] install calamaris&lt;br /&gt;
&lt;br /&gt;
Tal i com indica el resum del paquet:&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[apt-cache]] search calamaris&lt;br /&gt;
 calamaris - log analyzer for Squid or Oops proxy log files&lt;br /&gt;
&lt;br /&gt;
Es tracta d'un analitzador dels logs d'Squid que ens permet obtenir informes d'ús del proxy. Podeu veure una demo d'informe de calamaris en format text a:&lt;br /&gt;
&lt;br /&gt;
 http://cord.de/tools/squid/calamaris/calamaris-2.out&lt;br /&gt;
&lt;br /&gt;
O en format HTML a:&lt;br /&gt;
&lt;br /&gt;
 http://cord.de/tools/squid/calamaris/calamaris-2.html&lt;br /&gt;
&lt;br /&gt;
Els fitxers instal·lats són:&lt;br /&gt;
&lt;br /&gt;
 $ [[dpkg]] -L calamaris&lt;br /&gt;
 /.&lt;br /&gt;
 /usr&lt;br /&gt;
 /usr/bin&lt;br /&gt;
 /usr/bin/calamaris&lt;br /&gt;
 /usr/share&lt;br /&gt;
 /usr/share/man&lt;br /&gt;
 /usr/share/man/man1&lt;br /&gt;
 /usr/share/man/man1/calamaris.1.gz&lt;br /&gt;
 /usr/share/perl5&lt;br /&gt;
 /usr/share/perl5/calamaris&lt;br /&gt;
 /usr/share/perl5/calamaris/calAxestype.pm&lt;br /&gt;
 /usr/share/perl5/calamaris/calAxestype3d.pm&lt;br /&gt;
 /usr/share/perl5/calamaris/calBars3d.pm&lt;br /&gt;
 /usr/share/doc&lt;br /&gt;
 /usr/share/doc/calamaris&lt;br /&gt;
 /usr/share/doc/calamaris/README&lt;br /&gt;
 /usr/share/doc/calamaris/TODO&lt;br /&gt;
 /usr/share/doc/calamaris/README.Debian&lt;br /&gt;
 /usr/share/doc/calamaris/copyright&lt;br /&gt;
 /usr/share/doc/calamaris/examples&lt;br /&gt;
 /usr/share/doc/calamaris/examples/EXAMPLES.gz&lt;br /&gt;
 /usr/share/doc/calamaris/examples/EXAMPLES.v3.gz&lt;br /&gt;
 /usr/share/doc/calamaris/NEWS.Debian.gz&lt;br /&gt;
 /usr/share/doc/calamaris/changelog.gz&lt;br /&gt;
 /usr/share/doc/calamaris/BUGS.gz&lt;br /&gt;
 /usr/share/doc/calamaris/changelog.Debian.gz&lt;br /&gt;
 /etc&lt;br /&gt;
 /etc/calamaris&lt;br /&gt;
 /etc/calamaris/calamaris.conf&lt;br /&gt;
 /etc/cron.daily&lt;br /&gt;
 /etc/cron.daily/calamaris&lt;br /&gt;
 /var&lt;br /&gt;
 /var/log&lt;br /&gt;
 /var/log/calamaris&lt;br /&gt;
 /var/www&lt;br /&gt;
 /var/www/calamaris&lt;br /&gt;
 /var/www/calamaris/daily&lt;br /&gt;
 /var/www/calamaris/weekly&lt;br /&gt;
 /var/www/calamaris/monthly &lt;br /&gt;
&lt;br /&gt;
Segons el manual de l'aplicació:&lt;br /&gt;
&lt;br /&gt;
 $ [[man]] [http://linux.die.net/man/1/calamaris calamaris]&lt;br /&gt;
&lt;br /&gt;
Podem obtenir informes executant:&lt;br /&gt;
&lt;br /&gt;
 $ sudo cat /var/log/squid3/access.log | calamaris&lt;br /&gt;
&lt;br /&gt;
El resultat seria quelcom similar a:&lt;br /&gt;
&lt;br /&gt;
 $ cat /var/log/squid3/access.log | calamaris&lt;br /&gt;
 # Summary&lt;br /&gt;
 Calamaris statistics                                                            &lt;br /&gt;
 --------------------------------------------------------- -------------- ------ &lt;br /&gt;
 lines parsed:                                                      lines  23115 &lt;br /&gt;
 invalid lines:                                                     lines      0 &lt;br /&gt;
 parse time:                                                          sec     12 &lt;br /&gt;
 parse speed:                                                   lines/sec   1926 &lt;br /&gt;
 --------------------------------------------------------- -------------- ------ &lt;br /&gt;
 Proxy statistics                                                                &lt;br /&gt;
 --------------------------------------------------------- -------------- ------ &lt;br /&gt;
 Total amount:                                                   requests  23115 &lt;br /&gt;
 Total Bandwidth:                                                    Byte   405M &lt;br /&gt;
 Proxy efficiency (HIT [kB/sec] / DIRECT [kB/sec]):                factor   1.13 &lt;br /&gt;
 Average speed increase:                                                %   0.36 &lt;br /&gt;
 --------------------------------------------------------- -------------- ------ &lt;br /&gt;
 Cache statistics                                                                &lt;br /&gt;
 --------------------------------------------------------- -------------- ------ &lt;br /&gt;
 Total amount cached:                                            requests   6751 &lt;br /&gt;
 Request hit rate:                                                      %  29.21 &lt;br /&gt;
 Bandwidth savings:                                                  Byte 12974K &lt;br /&gt;
 Bandwidth savings in Percent (Byte hit rate):                          %   3.13 &lt;br /&gt;
 --------------------------------------------------------- -------------- ------   &lt;br /&gt;
  &lt;br /&gt;
 &lt;br /&gt;
 # Incoming requests by method&lt;br /&gt;
 method                          request      %  sec/req   Byte       %  kB/sec  &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 GET                                20850  90.20    0.85  413074K  99.53   23.33 &lt;br /&gt;
 POST                                2250   9.73    1.50  1991606   0.47    0.58 &lt;br /&gt;
 HEAD                                  15   0.06    0.45     6135   0.00    0.89 &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 Sum                                23115 100.00    0.91  415025K 100.00   19.68 &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 # Incoming UDP-requests by status&lt;br /&gt;
 no matching requests             &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 # Incoming TCP-requests by status&lt;br /&gt;
 status                          request      %  sec/req   Byte       %  kB/sec  &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 HIT                                 6751  29.21    0.09 13285256   3.13   22.18 &lt;br /&gt;
 MISS                               16360  70.78    1.25  401840K  96.82   19.61 &lt;br /&gt;
 ERROR                                  4   0.02    0.94   216243   0.05   55.91 &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 Sum                                23115 100.00    0.91  415025K 100.00   19.68 &lt;br /&gt;
  &lt;br /&gt;
 # Outgoing requests by status&lt;br /&gt;
 status                          request      %  sec/req   Byte       %  kB/sec  &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 DIRECT Fetch from Source           16360 100.00    1.25  401840K 100.00   19.61 &lt;br /&gt;
 SIBLING                                0   0.00    0.00        0   0.00    0.00 &lt;br /&gt;
 PARENT                                 0   0.00    0.00        0   0.00    0.00 &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 Sum                                16360 100.00    1.25  401840K 100.00   19.61 &lt;br /&gt;
   &lt;br /&gt;
 &lt;br /&gt;
 # Outgoing requests by destination&lt;br /&gt;
 neighbor type                   request      %  sec/req   Byte       %  kB/sec  &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 DIRECT                             16360 100.00    1.25  401840K 100.00   19.61 &lt;br /&gt;
 ------------------------------ --------- ------ ------- -------- ------ ------- &lt;br /&gt;
 Sum                                16360 100.00    1.25  401840K 100.00   19.61  &lt;br /&gt;
 &lt;br /&gt;
 Calamaris 2.99.4.0&lt;br /&gt;
 Copyright (C) 1997, 1998, 1999, 2000, 2001, 2002, 2003, 2004, 2005, 2006&lt;br /&gt;
 Cord Beermann. Authors: Cord Beermann and Michael Pophal.&lt;br /&gt;
 Calamaris comes with ABSOLUTELY NO WARRANTY. It is free software, and you are&lt;br /&gt;
 welcome to redistribute it under certain conditions. See source for details.&lt;br /&gt;
 http://Calamaris.Cord.de/&lt;br /&gt;
&lt;br /&gt;
Podeu concatenar tants fitxers de log com vulgueu:&lt;br /&gt;
&lt;br /&gt;
 $ sudo cat /var/log/squid3/access.log| sudo cat /var/log/squid3/access.log.1 | calamaris&lt;br /&gt;
&lt;br /&gt;
Calamaris també s'utilitza a [[IPCOP]]. Consulteu l'apartat:&lt;br /&gt;
&lt;br /&gt;
 [[IPCOP#Calamaris_addon]]&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://cord.de/tools/squid/calamaris/&lt;br /&gt;
&lt;br /&gt;
===Exemples d'ús de calamaris===&lt;br /&gt;
&lt;br /&gt;
Extrets del manual:&lt;br /&gt;
&lt;br /&gt;
 $ cat /var/log/squid/access.log | nice -39 calamaris -amH 'daily worf' | mail root&lt;br /&gt;
&lt;br /&gt;
 $ cat /var/log/squid/access.log | calamaris -a -o daily.`date +&amp;quot;%w&amp;quot;` &amp;gt; /dev/null&lt;br /&gt;
&lt;br /&gt;
 if [ $DAYOFWEEK = &amp;quot;0&amp;quot; ]; then calamaris -a -i daily.1:daily.2:daily.3:daily.4:daily.5:daily.6:daily.0 -zmH &amp;quot;weekly worf&amp;quot; | mail root fi&lt;br /&gt;
&lt;br /&gt;
====Crear un informe HTML====&lt;br /&gt;
&lt;br /&gt;
 $ sudo calamaris -a -F html /var/log/squid/access.log &amp;gt;/var/www/default/html/calamaris/index.html&lt;br /&gt;
&lt;br /&gt;
L'opció -a mostra tots els informes útils. Equival a:&lt;br /&gt;
&lt;br /&gt;
 --size-distribution-report 10 --domain-report 20 --performance-report 60 --requester-report 20 --status-report --type-report 20 &lt;br /&gt;
 --response-time-report --errorcode-distribution-report&lt;br /&gt;
&lt;br /&gt;
Sense la opció -F html el resultat seria un fitxer de text.&lt;br /&gt;
&lt;br /&gt;
I el podeu consultar si no teniu entorn gràfic amb [[lynx]]:&lt;br /&gt;
&lt;br /&gt;
 $ lynx /var/www/default/html/calamaris/index.html&lt;br /&gt;
&lt;br /&gt;
====Informes automàtics amb cron====&lt;br /&gt;
&lt;br /&gt;
Al instal·lar calamaris automàticament se us ha instal·lat un tasca de [[cron]]:&lt;br /&gt;
&lt;br /&gt;
 /etc/cron.daily/calamaris&lt;br /&gt;
&lt;br /&gt;
Que executa cada dia un script que es configura al fitxer:&lt;br /&gt;
&lt;br /&gt;
 $ cat /etc/calamaris/cron.conf&lt;br /&gt;
 # configuration file for calamaris&lt;br /&gt;
 # by Philipp Frauenfelder &amp;lt;pfrauenf@debian.org&amp;gt;&lt;br /&gt;
 # 1998-10-09 &lt;br /&gt;
 &lt;br /&gt;
 # There are three categories: daily, weekly and monthly. For each of these&lt;br /&gt;
 # one line is responsible. There must be a line for each category but only &lt;br /&gt;
 # one. &lt;br /&gt;
 &lt;br /&gt;
 # cat: [daily|weekly|monthly]&lt;br /&gt;
 # mailto: mailaddress, eg. root&lt;br /&gt;
 # webto: path incl. file name, eg. /var/www/calamaris/daily.html. &lt;br /&gt;
 #        The script does currently not check wether the directory &lt;br /&gt;
 #        exists and fails with a rather ugly error.&lt;br /&gt;
 # todo: [nothing|mail|web|both]&lt;br /&gt;
 # title: try it :-)&lt;br /&gt;
 &lt;br /&gt;
 # cat:mailto:webto:todo:title&lt;br /&gt;
 '''&amp;lt;nowiki&amp;gt;daily:root:/var/www/calamaris/daily/index.html:mail:'Squid diari'&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 '''&amp;lt;nowiki&amp;gt;weekly:root:/var/www/calamaris/weekly/index.html:mail:'Squid setmanalment'&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 '''&amp;lt;nowiki&amp;gt;monthly:root:/var/www/calamaris/monthly/index.html:mail:'Squid mensual'&amp;lt;/nowiki&amp;gt;'''&lt;br /&gt;
 # what log files should be parsed: [auto|squid|oops]&lt;br /&gt;
 #       auto: tries to find the log files in this order: squid, oops&lt;br /&gt;
 #       squid: parses a squid log file if available&lt;br /&gt;
 #       oops: parses a oops log file if available&lt;br /&gt;
 cache=auto&lt;br /&gt;
&lt;br /&gt;
Amb la configuració per defecte només s'envien correus electrònics (al correu intern de root que si no el teniu redireccionat no arribarà a ningú. Consulteu [[Mail]]) i a més amb squid3 no us funcionarà. Cal posar:&lt;br /&gt;
 ...&lt;br /&gt;
 # cat:mailto:webto:todo:title&lt;br /&gt;
 daily:'''sergi.tur@domini.cat''':/var/www/calamaris/daily/index.html:'''both''':'Squid diari'&lt;br /&gt;
 weekly:sergi.tur@domini.cat:/var/www/calamaris/weekly/index.html:both:'Squid setmanalment'&lt;br /&gt;
 monthly:sergi.tur@domini.cat:/var/www/calamaris/monthly/index.html:both:'Squid mensual'&lt;br /&gt;
 # what log files should be parsed: [auto|squid|oops]&lt;br /&gt;
 #       auto: tries to find the log files in this order: squid, oops&lt;br /&gt;
 #       squid: parses a squid log file if available&lt;br /&gt;
 #       oops: parses a oops log file if available&lt;br /&gt;
 '''cache=squid3'''&lt;br /&gt;
&lt;br /&gt;
{{nota|Canvieu sergi.tur@domini.cat per el vostre correu electrònic.}}&lt;br /&gt;
&lt;br /&gt;
Cron/Anacron s'executarà cada dia amb [[cron.daily]] (vegeu anacron). Podeu forçar la execució i comprovar que no teniu cap error amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/cron.daily/calamaris&lt;br /&gt;
&lt;br /&gt;
No us funcionarà per que cal corregir unes errors (està pensat per a squid en comptes d'squid3):&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe /etc/cron.daily/calamaris&lt;br /&gt;
&lt;br /&gt;
Feu Ctrl+k+f i busqueu squid. Amb Ctrl+l us podeu moure a la següent cerca, salteu els comentaris on aparegui la paraula squid (/var/log/squid3, /var/log/squid3/access.log).&lt;br /&gt;
&lt;br /&gt;
També canvieu la línia:&lt;br /&gt;
&lt;br /&gt;
 CACHE=auto&lt;br /&gt;
&lt;br /&gt;
per:&lt;br /&gt;
&lt;br /&gt;
 CACHE=squid3&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Com veureu es creen automàticament unes pàgines web a:&lt;br /&gt;
&lt;br /&gt;
 /var/www/calamaris&lt;br /&gt;
&lt;br /&gt;
Si no existeix la carpeta la creeu:&lt;br /&gt;
&lt;br /&gt;
 $ sudo mkdir -p /var/www/calamaris&lt;br /&gt;
 $ sudo mkdir -p /var/www/calamaris/daily&lt;br /&gt;
 $ sudo mkdir -p /var/www/calamaris/monthly&lt;br /&gt;
 $ sudo mkdir -p /var/www/calamaris/weekly&lt;br /&gt;
&lt;br /&gt;
A les qual podeu accedir (si teniu la configuració d'[[Apache]] per defecte) amb:&lt;br /&gt;
&lt;br /&gt;
 http://IP_SERVIDOR_PROXY/calamaris&lt;br /&gt;
&lt;br /&gt;
També és habitual canviar el fitxer [[/etc/cron.daily/calamaris]]:&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe  /etc/cron.daily/calamaris&lt;br /&gt;
&lt;br /&gt;
I afegir més opcions a la variable:&lt;br /&gt;
&lt;br /&gt;
 CALAMARISOPTIONS=&amp;quot;--size-distribution-report 10 --domain-report 500 --performance-report 60 --requester-report 500 --status-report --type-report 20 --response-time-report \&lt;br /&gt;
 --errorcode-distribution-report -f auto --config-file ${CALAMARIS_CONF_FILE}&amp;quot;&lt;br /&gt;
&lt;br /&gt;
I buscar les referències a squid i canviar-les per squid3:&lt;br /&gt;
&lt;br /&gt;
 ...&lt;br /&gt;
 # squid or oops?&lt;br /&gt;
 CACHE=squid3&lt;br /&gt;
 ...&lt;br /&gt;
 # look for cache log files  &lt;br /&gt;
 if [ &amp;quot;$CACHE&amp;quot; = &amp;quot;auto&amp;quot; ]; then&lt;br /&gt;
     if [ -r /var/log/squid3/access.log ]; then&lt;br /&gt;
        CACHE=squid3&lt;br /&gt;
        CACHELOGDIR=/var/log/squid3&lt;br /&gt;
&lt;br /&gt;
===Resolució de problemes===&lt;br /&gt;
&lt;br /&gt;
====/etc/cron.daily/calamaris: no cache log files found, exiting cleanly====&lt;br /&gt;
&lt;br /&gt;
Si no us funciona l'automatisme de cron proveu d'executar-los a mà:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /etc/cron.daily/calamaris&lt;br /&gt;
 /etc/cron.daily/calamaris: no cache log files found, exiting cleanly&lt;br /&gt;
&lt;br /&gt;
Si teniu Squid3 cal tenir en compte que la carpeta dels fitxers de log és:&lt;br /&gt;
&lt;br /&gt;
  /var/log/squid3&lt;br /&gt;
&lt;br /&gt;
En comptes de:&lt;br /&gt;
&lt;br /&gt;
  /var/log/squid&lt;br /&gt;
&lt;br /&gt;
Editeu el fitxer:&lt;br /&gt;
&lt;br /&gt;
 /etc/cron.daily/calamaris&lt;br /&gt;
&lt;br /&gt;
I busqueu i remplaceu totes les entrades incorrectes de:&lt;br /&gt;
&lt;br /&gt;
 squid&lt;br /&gt;
&lt;br /&gt;
per &lt;br /&gt;
&lt;br /&gt;
 squid3&lt;br /&gt;
&lt;br /&gt;
També cal modificar el fitxer de configuració. Per defecte està pensat per a squid (no squid3) i a més només envia notificacions per correu (i només a l'usuari root de la màquina local). Poseu:&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe /etc/calamaris/cron.conf&lt;br /&gt;
 # configuration file for calamaris&lt;br /&gt;
 # by Philipp Frauenfelder &amp;lt;pfrauenf@debian.org&amp;gt;&lt;br /&gt;
 # 1998-10-09&lt;br /&gt;
 &lt;br /&gt;
 # There are three categories: daily, weekly and monthly. For each of these&lt;br /&gt;
 # one line is responsible. There must be a line for each category but only&lt;br /&gt;
 # one.&lt;br /&gt;
 &lt;br /&gt;
 # cat: [daily|weekly|monthly]&lt;br /&gt;
 # mailto: mailaddress, eg. root&lt;br /&gt;
 # webto: path incl. file name, eg. /var/www/calamaris/daily.html.&lt;br /&gt;
 #        The script does currently not check wether the directory&lt;br /&gt;
 #        exists and fails with a rather ugly error.&lt;br /&gt;
 # todo: [nothing|mail|web|both]&lt;br /&gt;
 # title: try it :-)&lt;br /&gt;
 &lt;br /&gt;
 # cat:mailto:webto:todo:title&lt;br /&gt;
 '''daily:sergi.tur@domini.com:/var/www/calamaris/daily/index.html:both:'Squid diari''''&lt;br /&gt;
 '''weekly:sergi.tur@domini.com:/var/www/calamaris/weekly/index.html:both:'Squid setmanalment''''&lt;br /&gt;
 '''monthly:sergi.tur@domini.com:/var/www/calamaris/monthly/index.html:both:'Squid mensual''''&lt;br /&gt;
 # what log files should be parsed: [auto|squid|oops]&lt;br /&gt;
 #       auto: tries to find the log files in this order: squid, oops&lt;br /&gt;
 #       squid: parses a squid log file if available&lt;br /&gt;
 #       oops: parses a oops log file if available&lt;br /&gt;
 '''cache=squid3'''&lt;br /&gt;
&lt;br /&gt;
{{nota|Canvieu sergi.tur@domini.com pel vostre correu electrònic}}&lt;br /&gt;
&lt;br /&gt;
==Sarg==&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install sarg&lt;br /&gt;
&lt;br /&gt;
Tal com diu la comanda:&lt;br /&gt;
&lt;br /&gt;
 $ apt-cache search --names-only sarg&lt;br /&gt;
 sarg - squid analysis report generator&lt;br /&gt;
&lt;br /&gt;
Sarg crea unes pàgines web:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L sarg | grep www&lt;br /&gt;
 /var/www&lt;br /&gt;
 /var/www/squid-reports&lt;br /&gt;
&lt;br /&gt;
Si teniu la configuració per defecte d'[[Apache]] i podreu accedir amb:&lt;br /&gt;
&lt;br /&gt;
 http://IP_SERVIDOR_PROXY//squid-reports&lt;br /&gt;
&lt;br /&gt;
Al principi, la pàgina pot estar buida de continguts. Es creen continguts de forma automàtica amb [[cron]]&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L sarg | grep cron&lt;br /&gt;
 /etc/cron.daily&lt;br /&gt;
 /etc/cron.daily/sarg&lt;br /&gt;
 /etc/cron.weekly&lt;br /&gt;
 /etc/cron.weekly/sarg&lt;br /&gt;
 /etc/cron.monthly&lt;br /&gt;
 /etc/cron.monthly/sarg&lt;br /&gt;
&lt;br /&gt;
Si mireu el contingut dels fitxers, veureu que s'utilitza l'script '''/usr/sbin/sarg-reports''':&lt;br /&gt;
 &lt;br /&gt;
 $ cat /etc/cron.daily/sarg&lt;br /&gt;
 #!/bin/sh&lt;br /&gt;
 &lt;br /&gt;
 if [ -x /usr/sbin/sarg-reports ]; then&lt;br /&gt;
   '''/usr/sbin/sarg-reports daily'''&lt;br /&gt;
 fi&lt;br /&gt;
&lt;br /&gt;
Podeu forçar les execucions amb:&lt;br /&gt;
&lt;br /&gt;
 $ sudo /usr/sbin/sarg-reports daily&lt;br /&gt;
 $ sudo /usr/sbin/sarg-reports weekly&lt;br /&gt;
 $ sudo /usr/sbin/sarg-reports monthly&lt;br /&gt;
&lt;br /&gt;
'''NOTA''': Si us dona un error tingueu en compte que la carpeta del log a Squid 3 és /var/log/squid3 en comptes de /var/log/squid. Canvieu al fitxer:&lt;br /&gt;
&lt;br /&gt;
 /etc/squid/sarg.conf&lt;br /&gt;
&lt;br /&gt;
La línia.&lt;br /&gt;
&lt;br /&gt;
 access_log /var/log/squid/access.log&lt;br /&gt;
&lt;br /&gt;
per:&lt;br /&gt;
&lt;br /&gt;
 access_log /var/log/squid3/access.log&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://www.howtoforge.com/monitoring_squid&lt;br /&gt;
&lt;br /&gt;
=== Informes d'SquidGuard ===&lt;br /&gt;
&lt;br /&gt;
Cal comprovar-ho!.&lt;br /&gt;
&lt;br /&gt;
 # /usr/bin/sarg -z -L /var/log/squid3/blocked.log -l /var/log/squid3/access.log -o /var/www/squid-reports/Manual -d 14/10/2009-15/10/2009&lt;br /&gt;
&lt;br /&gt;
:*http://tuxjm.net/docs/temporales/Configuracion_de_Herramientas_de_Analisis_de_Logs_de_Squid.txt&lt;br /&gt;
&lt;br /&gt;
==webalizer==&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get install webalizer&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L webalizer&lt;br /&gt;
&lt;br /&gt;
Execució:&lt;br /&gt;
&lt;br /&gt;
 $ sudo webalizer &lt;br /&gt;
 Webalizer V2.01-10 (Linux 2.6.27-11-server) locale: ca_ES.UTF-8&lt;br /&gt;
 Usant el registre /var/log/apache2/access.log.1 (clf)&lt;br /&gt;
 Using default GeoIP database&lt;br /&gt;
 Creant resultats a /var/www/webalizer&lt;br /&gt;
 Resultats del servidor 'router'&lt;br /&gt;
 Llegint fitxer històric... webalizer.hist&lt;br /&gt;
 Generant resultats per August 2009&lt;br /&gt;
 Generant resultats resumits&lt;br /&gt;
 Guardant informació a l'històric...&lt;br /&gt;
 731 registres en 2,50 segons, 292/sec&lt;br /&gt;
&lt;br /&gt;
Hi ha un mòdul de [[webmin]] per a webalizer.&lt;br /&gt;
&lt;br /&gt;
= Generar trànsit per a fer informes de proves amb wget =&lt;br /&gt;
&lt;br /&gt;
[[Eines_per_a_tests_de_càrrega#Generar_tr.C3.A0nsit_amb_siege_i_fitxers_access.log_d.27un_Proxy_d.27un_entorn_d.27Execuci.C3.B3]]&lt;br /&gt;
&lt;br /&gt;
= Utilitzar un proxy remot amb túnels SSH =&lt;br /&gt;
&lt;br /&gt;
Una manera de securitzar el transit web (navegar xifrant les dades) és utilitzar SSH. Vegeu [[Túnel SSH]]. Si teniu accés a un servidor SSH i en aquell servidor també teniu instal·lat un proxy squid, podeu fer el seguent:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -L 6666:localhost:3128 usuari@ip_servidor_ssh_i_prozy&lt;br /&gt;
&lt;br /&gt;
I deixeu la connexió SSH oberta. Ara al navegador només cal que poseu com a dades del proxy:&lt;br /&gt;
&lt;br /&gt;
 IP: localhost&lt;br /&gt;
 Port : 6666&lt;br /&gt;
&lt;br /&gt;
Consulteu [[Configuraci%C3%B3_de_clients_proxy|Configuració de clients Proxy]] per tal de tenir més informació de com configurar el navegador.&lt;br /&gt;
&lt;br /&gt;
I podeu comprovar utilitzant qualsevol pàgina &amp;quot;Qual és mi ip&amp;quot; (busqueu Qual és mi IP a Google) qu esteu navegant a través de proxy. Tingueu en compte que les dades viatgen des de la vostra maquina al servidor SSH de forma segura (i per tant és una solució quan treballeu en xarxes LAN no confiables i per tal d'evitar eines com [[Ettercap]] o [[Dsniff]]).&lt;br /&gt;
&lt;br /&gt;
=Fer connexions anònimes=&lt;br /&gt;
&lt;br /&gt;
*http://wiki.squid-cache.org/SquidFaq/ConfiguringSquid#Can_Squid_anonymize_HTTP_requests.3F&lt;br /&gt;
&lt;br /&gt;
= Federació d'un proxy amb guifi.net =&lt;br /&gt;
&lt;br /&gt;
'''Què és un proxy federat'''&lt;br /&gt;
&lt;br /&gt;
Si editeu un servei de Proxy (només si en sou el propietari o en sou administrador), trobareu un apartat que diu:&lt;br /&gt;
&lt;br /&gt;
 '''Federació del proxy''':&lt;br /&gt;
  '''IN''' - Els usuaris d'altres proxis poden fer-lo servir&lt;br /&gt;
  '''OUT''' - els usuaris del proxi poden fer-ne servir d'altres&lt;br /&gt;
&lt;br /&gt;
El que dóna lloc a 4 possibles combinacions :&lt;br /&gt;
&lt;br /&gt;
:*'''ni IN ni OUT''' - Com s'ha dit avans, el proxy no estarà federat, per tant cap usuari extern al proxy el pot fer servir, i cap usuari del proxy pot fer servir els altres de guifi.net (exemple -&amp;gt; un proxy privat)&lt;br /&gt;
:*'''només OUT''' - El usuaris del proxy poden utilitzar qualsevol dels proxys que estiguin federats com a IN, pero els usuaris d'altres proxys no poden utilitzar-lo (exemple -&amp;gt; la guixa o el seminari)&lt;br /&gt;
:*'''només IN''' - Els usuaris del proxy nomes poden utilitzar el seu, pero qualsevol usuari d'un proxy marcat com a OUT pot fer servir aquest. (exemple -&amp;gt; ??? no crec que ni hagi cap, però les combinacions és lo que tenen)&lt;br /&gt;
:*'''IN i OUT''' - El proxy federat per exel·lència : els usuaris poden fer servir tots els proxys federats amb IN, i els usuaris d'altres proxys federats OUT poden fer-lo servir. (exemple -&amp;gt; esperança, elserrat, puntas ...)&lt;br /&gt;
&lt;br /&gt;
Els proxies com altres serveis de la xarxa guifi.net es poden publicitar a la web de guifi.net. Per exemple, podeu accedir a la pàgina del node que conté el proxy de l'institut de l'Ebre:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Si entreu a aquesta pàgina amb un usuari de guifi.net veureu que hi ha un enllaç/pestanya (usuaris), que és l'últim, a sota el nom del node (en aquest cas &amp;quot;TortosaINSEbre&amp;quot;). Les opcions són:&lt;br /&gt;
&lt;br /&gt;
 dades trastos distàncies gràfiques enllaços mapa de perfils serveis '''usuaris'''&lt;br /&gt;
&lt;br /&gt;
Escolliu l'última. Si feu clic a usuaris, us llistarà els usuaris. &lt;br /&gt;
&lt;br /&gt;
També teniu un boto que diu: &amp;quot;Afegir usuari&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
{{important|Si us dona l'error: &amp;quot;Pàgina no trobada!&amp;quot; és que potser esteu donant d'alta l'usuari des del servei i no pas des del node}}&lt;br /&gt;
&lt;br /&gt;
Al servidor on hi ha el proxy cal instal·lar (els passos són per a Debian o Ubuntu)&lt;br /&gt;
&lt;br /&gt;
 $ [[sudo]] [[joe]] /etc/apt/sources.list&lt;br /&gt;
&lt;br /&gt;
I afegiu la línia:&lt;br /&gt;
&lt;br /&gt;
 deb http://tramuntana.evt.cat/mirror/debian/ ./&lt;br /&gt;
&lt;br /&gt;
Per aplicar els canvis&lt;br /&gt;
&lt;br /&gt;
 $ sudo apt-get update&lt;br /&gt;
&lt;br /&gt;
El paquet a instal·lar és&lt;br /&gt;
&lt;br /&gt;
 $ sudo [[apt-get]] install guifi-proxy&lt;br /&gt;
&lt;br /&gt;
{{nota|Tingueu en compte que se suposa que el proxy [[Squid]] ja el teniu instal·lat i configurat!}}&lt;br /&gt;
&lt;br /&gt;
{{important| Si teniu el proxy amb Squid3, el paquet guifi-proxy uns instal·larà la versió 1 d'Squid i podeu tenir problemes si s'executen al mateix temps. Executeu:}}&lt;br /&gt;
&lt;br /&gt;
 sudo update-rc.d -f squid remove&lt;br /&gt;
&lt;br /&gt;
Els fitxers instal·lats són:&lt;br /&gt;
&lt;br /&gt;
 $ dpkg -L guifi-proxy&lt;br /&gt;
 /.&lt;br /&gt;
 /etc&lt;br /&gt;
 /etc/cron.d&lt;br /&gt;
 /etc/cron.d/guifi-proxy&lt;br /&gt;
 /etc/guifi-proxy&lt;br /&gt;
 /etc/logrotate.d&lt;br /&gt;
 /etc/logrotate.d/guifi-proxy&lt;br /&gt;
 /usr&lt;br /&gt;
 /usr/share&lt;br /&gt;
 /usr/share/guifi-proxy&lt;br /&gt;
 /usr/share/guifi-proxy/guifi-proxy.sh&lt;br /&gt;
 /usr/share/doc&lt;br /&gt;
 /usr/share/doc/guifi-proxy&lt;br /&gt;
 /usr/share/doc/guifi-proxy/README.Debian&lt;br /&gt;
 /usr/share/doc/guifi-proxy/copyright&lt;br /&gt;
 /usr/share/doc/guifi-proxy/changelog.gz&lt;br /&gt;
 /usr/share/man&lt;br /&gt;
 /usr/share/man/man1&lt;br /&gt;
 /usr/share/man/man1/guifi-proxy.1.gz&lt;br /&gt;
 /var&lt;br /&gt;
 /var/log&lt;br /&gt;
 /var/log/guifi-proxy&lt;br /&gt;
&lt;br /&gt;
&amp;quot;L'executable&amp;quot; és:&lt;br /&gt;
&lt;br /&gt;
 /usr/share/guifi-proxy/guifi-proxy.sh&lt;br /&gt;
&lt;br /&gt;
Amb el següent contingut:&lt;br /&gt;
&lt;br /&gt;
 #!/bin/sh&lt;br /&gt;
 &lt;br /&gt;
 #--- DEFAULT CONFIG ---&lt;br /&gt;
 node=2619; # overwrite by config file&lt;br /&gt;
 base_url='http://www.guifi.net'&lt;br /&gt;
 passwd_dir='/etc/guifi-proxy/'&lt;br /&gt;
 passwd=${passwd_dir}'passwd'&lt;br /&gt;
 passwd_md5=${passwd_dir}'passwd.md5'&lt;br /&gt;
 tmp='/tmp/passwd'&lt;br /&gt;
 tmp_md5='/tmp/passwd.md5'&lt;br /&gt;
 tmp_web_md5='/tmp/passwd_web_md5.txt'&lt;br /&gt;
 # Enable for Debian/Ubuntu &lt;br /&gt;
 reload='/etc/init.d/squid reload'&lt;br /&gt;
 # Enable for Fedora/RedHat&lt;br /&gt;
 #reload='service squid reload'&lt;br /&gt;
 #--- END DEFAULT CONFIG --- &lt;br /&gt;
 &lt;br /&gt;
 #--- LOAD CONFIG FILE ---&lt;br /&gt;
 config='/etc/guifi-proxy/config.sh' &lt;br /&gt;
 &lt;br /&gt;
 if [ -f $config ]&lt;br /&gt;
   then&lt;br /&gt;
   . $config&lt;br /&gt;
 fi&lt;br /&gt;
 #--- END LOAD CONFIG FILE --- &lt;br /&gt;
 &lt;br /&gt;
 #echo $node;&lt;br /&gt;
 #echo $base_url;&lt;br /&gt;
 #echo $passwd_dir;&lt;br /&gt;
 #echo $passwd;&lt;br /&gt;
 #echo $tmp;&lt;br /&gt;
 #echo $reload;&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 # Check if download passwd file is needed&lt;br /&gt;
 # Download md5 checksum&lt;br /&gt;
 wget $base_url/guifi/export/$node/federated_md5 -O $tmp_web_md5&lt;br /&gt;
 # Calc md5sum of $passwd&lt;br /&gt;
 touch $passwd&lt;br /&gt;
 md5sum $passwd &amp;gt; $passwd_md5 &lt;br /&gt;
  &lt;br /&gt;
 # Compare checksums&lt;br /&gt;
 hash_web=`cut -d&amp;quot; &amp;quot; -f1 $tmp_web_md5`&lt;br /&gt;
 hash_passwd=`cut -d&amp;quot; &amp;quot; -f1 $passwd_md5`&lt;br /&gt;
 #echo &amp;quot;md5=$hash_web=&amp;quot;&lt;br /&gt;
 #echo &amp;quot;md5=$hash_passwd=&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
 if [ $hash_web != $hash_passwd ]; then&lt;br /&gt;
   echo &amp;quot;[`date -R`] - Different Hash, New Passwd File&amp;quot;;&lt;br /&gt;
   wget $base_url/guifi/export/$node/federated -O $tmp&lt;br /&gt;
   md5sum $tmp &amp;gt; $tmp_md5&lt;br /&gt;
   hash_tmp=`cut -d&amp;quot; &amp;quot; -f1 $tmp_md5`  &lt;br /&gt;
   if [ $hash_web = $hash_tmp ]; then&lt;br /&gt;
     echo &amp;quot;[`date -R`] - Download OK, copying Passwd file to $passwd&amp;quot;;&lt;br /&gt;
     cp $tmp $passwd&lt;br /&gt;
     rm $tmp&lt;br /&gt;
     rm $tmp_md5&lt;br /&gt;
     rm $tmp_web_md5&lt;br /&gt;
     $reload&lt;br /&gt;
   fi;  &lt;br /&gt;
 fi;&lt;br /&gt;
 &lt;br /&gt;
 exit 0;&lt;br /&gt;
&lt;br /&gt;
{{important|Noteu la línia '''&amp;lt;nowiki&amp;gt;reload='/etc/init.d/squid reload'&amp;lt;/nowiki&amp;gt;'''. Si teniu squid3 la heu de canviar per '''&amp;lt;nowiki&amp;gt;reload='/etc/init.d/squid3 reload'&amp;lt;/nowiki&amp;gt;''' o modificar el fitxer '''/usr/share/guifi-proxy''' afegint la línia:}}&lt;br /&gt;
&lt;br /&gt;
 $ cat /etc/guifi-proxy/config.sh&lt;br /&gt;
 &lt;br /&gt;
 #!/bin/sh&lt;br /&gt;
 #&lt;br /&gt;
 # Script at /usr/share/guifi-proxy&lt;br /&gt;
 #&lt;br /&gt;
 # Server base url ex: http://www.guifi.net&lt;br /&gt;
 base_url='http://www.guifi.net';&lt;br /&gt;
 # Node ID&lt;br /&gt;
 node=50;&lt;br /&gt;
 reload='/etc/init.d/squid3 reload';&lt;br /&gt;
&lt;br /&gt;
L'script el que fa es baixar-se la URL:&lt;br /&gt;
&lt;br /&gt;
 http://guifi.net/guifi/export/numero_servei_proxy/federated&lt;br /&gt;
&lt;br /&gt;
Per exemple a:&lt;br /&gt;
&lt;br /&gt;
 http://guifi.net/guifi/export/2619/federated&lt;br /&gt;
&lt;br /&gt;
La baixada es comprova que sigui correcte ja que hi ha un MD5 per a cada fitxer. Per exemple:&lt;br /&gt;
&lt;br /&gt;
 http://guifi.net/guifi/export/2619/federated_md5&lt;br /&gt;
&lt;br /&gt;
Es configura [[cron]] per que a cada minut 55 es sincronitzi:&lt;br /&gt;
&lt;br /&gt;
 $ cat /etc/cron.d/guifi-proxy&lt;br /&gt;
 #&lt;br /&gt;
 # Regular cron jobs for the guifi-proxy package&lt;br /&gt;
 #&lt;br /&gt;
 55 *	* * *	root	/usr/share/guifi-proxy/guifi-proxy.sh &amp;gt;&amp;gt; /var/log/guifi-proxy/guifi-proxy.log 2&amp;gt;&amp;amp;1;&lt;br /&gt;
&lt;br /&gt;
Vegeu que es guarda al fitxer de log (a més es configura [[logrotate]]) el resultat de les sincronitzacions:&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/guifi-proxy&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
:*https://llistes.projectes.lafarga.org/pipermail/guifi-rdes/2007-November/003850.html&lt;br /&gt;
:*https://svn.projectes.lafarga.cat/svn/guifi/tools/packaging/debian/guifi-proxy/&lt;br /&gt;
:*http://guifi.net/ca/node/4427&lt;br /&gt;
&lt;br /&gt;
= Load Balancing i tcp_outgoing_address =&lt;br /&gt;
&lt;br /&gt;
Amb la directiva [[tcp_outgoing_address]], podem canviar la IP d'origen del paquet que surt de l'Squid a l'hora de buscar una pàgina d'Internet. Combinant-ho amb [[Policy Routing]] (Source Policy Rounting), podem encaminar per diferents gateways diferents peticions a un servidor Squid.&lt;br /&gt;
&lt;br /&gt;
:*[[Load_Balancing#Squid_i_tcp_outgoing_address]]&lt;br /&gt;
&lt;br /&gt;
=TroubleShooting. Resolució de problemes=&lt;br /&gt;
&lt;br /&gt;
== No es permet la connexió segura https (CONNECT) a un port no estàndard ==&lt;br /&gt;
&lt;br /&gt;
La configuració estàndard d'Squid només permet utilitzar el port estàndard de [[HTTP]]s. Les connexions HTTPS es fan amb el mètode CONNECT:&lt;br /&gt;
&lt;br /&gt;
 $ sudo joe /etc/squid3/squid.conf&lt;br /&gt;
 ...&lt;br /&gt;
 acl SSL_ports port 443&lt;br /&gt;
 ...&lt;br /&gt;
 http_access deny CONNECT !SSL_ports&lt;br /&gt;
&lt;br /&gt;
Per exemple no permet l'accés a QBID:&lt;br /&gt;
&lt;br /&gt;
 https://apps.cambrescat.es:8003/qBid/&lt;br /&gt;
&lt;br /&gt;
Cal afegir ports per a HTTPS  afegint la línia &lt;br /&gt;
&lt;br /&gt;
 acl SSL_ports port 8003&lt;br /&gt;
&lt;br /&gt;
després de:&lt;br /&gt;
&lt;br /&gt;
  acl SSL_ports port 443&lt;br /&gt;
&lt;br /&gt;
{{important|D'aquesta manera s'està obrint un possible forat de sortida ja que s'estan permeten connexions directes amb CONNECT al port 8003 (es pot utilitzar per accedir a un proxy extern que escolti peticions al port que obriu)}}&lt;br /&gt;
&lt;br /&gt;
==Problemes amb clients FTP==&lt;br /&gt;
&lt;br /&gt;
S'ha de carregar un mòdul del kernel específic per fer el connection tracking de FTP:&lt;br /&gt;
&lt;br /&gt;
 # modprobe ip_nat_ftp&lt;br /&gt;
&lt;br /&gt;
'''Recursos''':&lt;br /&gt;
*http://www.cyberciti.biz/tips/linux-setup-transparent-proxy-squid-howto.html&lt;br /&gt;
&lt;br /&gt;
==Error Iniciant Squid versió 1.0==&lt;br /&gt;
&lt;br /&gt;
Si us dona el següent error:&lt;br /&gt;
&lt;br /&gt;
 * Starting Squid HTTP proxy squid                                                                                                                              &lt;br /&gt;
 * Creating squid spool directory structure&lt;br /&gt;
 FATAL: Could not determine fully qualified hostname.  Please set 'visible_hostname'&lt;br /&gt;
 &lt;br /&gt;
 Squid Cache (Version 2.6.STABLE14): Terminated abnormally.&lt;br /&gt;
 CPU Usage: 0.004 seconds = 0.004 user + 0.000 sys&lt;br /&gt;
 Maximum Resident Size: 0 KB&lt;br /&gt;
 Page faults with physical i/o: 0&lt;br /&gt;
 Aborted (core dumped)&lt;br /&gt;
 FATAL: Could not determine fully qualified hostname.  Please set 'visible_hostname' &lt;br /&gt;
 &lt;br /&gt;
 Squid Cache (Version 2.6.STABLE14): Terminated abnormally.&lt;br /&gt;
 CPU Usage: 0.012 seconds = 0.012 user + 0.000 sys&lt;br /&gt;
 Maximum Resident Size: 0 KB&lt;br /&gt;
 Page faults with physical i/o: 0&lt;br /&gt;
 Aborted (core dumped)&lt;br /&gt;
&lt;br /&gt;
Potser heu instal·lat el paquet '''squid''' en comptes del paquet '''squid3'''?&lt;br /&gt;
&lt;br /&gt;
==Squid Rebutja Connexions==&lt;br /&gt;
&lt;br /&gt;
Si tenim el següent error la navegar a través d'un proxy:&lt;br /&gt;
&lt;br /&gt;
[[Imatge:SquidRebutjaConnexions.png]]&lt;br /&gt;
&lt;br /&gt;
Això vol dir que no tenim accés al proxy. Potser la IP o el port són incorrectes o s'ha perdut la connexió amb el proxy?&lt;br /&gt;
&lt;br /&gt;
==Consider increasing the number of url_rewriter processes..==&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/squid/cache.log&lt;br /&gt;
 ...&lt;br /&gt;
 WARNING: up to 13 pending requests queued&lt;br /&gt;
 2009/01/29 13:43:49| Consider increasing the number of url_rewriter processes to at least 18 in your config file.&lt;br /&gt;
&lt;br /&gt;
Cal modificar la variable [http://www.visolve.com/squid/squid26/externalsupport.php#url_rewrite_children url_rewrite_children]. Com a valor per defecte és 5 que pot ser molt poc. Si disposem de RAM cal augmentar aquest valor.&lt;br /&gt;
&lt;br /&gt;
Aquesta variable es troba al fitxer '''squid.conf'''. Un exemple en una màquina amb [[IPCOP]]:&lt;br /&gt;
&lt;br /&gt;
 # cat /var/ipcop/proxy/squid.conf&lt;br /&gt;
 ...&lt;br /&gt;
 url_rewrite_children 5&lt;br /&gt;
&lt;br /&gt;
 '''NOTA''': a IPCOP no es pot canviar aquest valor (ni cap altre) directament al fitxer. Cal fer-ho des de la interfície web&lt;br /&gt;
&lt;br /&gt;
Per fer-ho amb IPCOP consulteu:&lt;br /&gt;
&lt;br /&gt;
 [[IPCOP#Augmentar_el_nombre_de_processos_de_URL_filter]]&lt;br /&gt;
&lt;br /&gt;
==WARNING! Your cache is running out of filedescriptors==&lt;br /&gt;
&lt;br /&gt;
 $ sudo tail -f /var/log/squid/cache.log&lt;br /&gt;
 ...&lt;br /&gt;
 2010/03/15 10:48:43| comm_open: socket failure: (24) Too many open files&lt;br /&gt;
 ...&lt;br /&gt;
 2010/04/21 09:49:09| WARNING! Your cache is running out of filedescriptors&lt;br /&gt;
 2010/04/21 09:49:20| WARNING: All url_rewriter processes are busy.&lt;br /&gt;
 2010/04/21 09:49:20| WARNING: up to 25 pending requests queued&lt;br /&gt;
&lt;br /&gt;
Sembla que una solució és augmentar el nombre de descriptors de fitxers amb &lt;br /&gt;
 vi /etc/security/limits.conf&lt;br /&gt;
&lt;br /&gt;
I afegir al final la línia :&lt;br /&gt;
&lt;br /&gt;
 * - nofile 4096&lt;br /&gt;
&lt;br /&gt;
Guardar i sortir. Podem veure el nombre de descriptors que es permeten obrir fent&lt;br /&gt;
&lt;br /&gt;
 ulimit -a &lt;br /&gt;
&lt;br /&gt;
Però a la meva xarxa, encara que millorava, continuaven produïnt-se errors. Una solució pot ser modificar les directives quick_abort, que de fet a mi em solucionàven el problema. Entenc que els usuaris impacients (tots de fet) quan la línia ADSL funciona lenta, fan una ràpida successió de &amp;quot;Reloads&amp;quot; picant el botó de refresc del navegador i això fa que Squid es quedi sense descriptors de fitxers (en aquest cas sockets) amb les connexions que resten baixant quan es fa un abort de la pàgina que s'havia demanat.&lt;br /&gt;
&lt;br /&gt;
 #  TAG: quick_abort_min (KB)&lt;br /&gt;
 #  TAG: quick_abort_max (KB)&lt;br /&gt;
 #  TAG: quick_abort_pct (percent)&lt;br /&gt;
 #       The cache by default continues downloading aborted requests&lt;br /&gt;
 #       which are almost completed (less than 16 KB remaining). This&lt;br /&gt;
 #       may be undesirable on slow (e.g. SLIP) links and/or very busy&lt;br /&gt;
 #       caches.  Impatient users may tie up file descriptors and&lt;br /&gt;
 #       bandwidth by repeatedly requesting and immediately aborting&lt;br /&gt;
 #       downloads.&lt;br /&gt;
 #&lt;br /&gt;
 #       When the user aborts a request, Squid will check the&lt;br /&gt;
 #       quick_abort values to the amount of data transfered until&lt;br /&gt;
 #       then.&lt;br /&gt;
 #&lt;br /&gt;
 #       If the transfer has less than 'quick_abort_min' KB remaining,&lt;br /&gt;
 #       it will finish the retrieval.&lt;br /&gt;
 #&lt;br /&gt;
 #       If the transfer has more than 'quick_abort_max' KB remaining,&lt;br /&gt;
 #       it will abort the retrieval.&lt;br /&gt;
 #&lt;br /&gt;
 #       If more than 'quick_abort_pct' of the transfer has completed,&lt;br /&gt;
 #       it will finish the retrieval.&lt;br /&gt;
 #&lt;br /&gt;
 #       If you do not want any retrieval to continue after the client&lt;br /&gt;
 #       has aborted, set both 'quick_abort_min' and 'quick_abort_max'&lt;br /&gt;
 #       to '0 KB'.&lt;br /&gt;
 #&lt;br /&gt;
 #       If you want retrievals to always continue if they are being&lt;br /&gt;
 #       cached set 'quick_abort_min' to '-1 KB'.&lt;br /&gt;
 #&lt;br /&gt;
 #Default:&lt;br /&gt;
 # quick_abort_min 16 KB&lt;br /&gt;
 # quick_abort_max 16 KB&lt;br /&gt;
 # quick_abort_pct 95&lt;br /&gt;
 # pau&lt;br /&gt;
 quick_abort_min 0 KB&lt;br /&gt;
 quick_abort_max 0 KB&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Vegeu també=&lt;br /&gt;
&lt;br /&gt;
*[[Squidguard]]&lt;br /&gt;
*[[DansGuardian]]&lt;br /&gt;
*[[Configuració de clients proxy]]&lt;br /&gt;
*[[IPCOP]]&lt;br /&gt;
**[[IPCOP#Calamaris_addon]]&lt;br /&gt;
*[[MRTG]] i [[Nagios]] es poden utilitzar per monitoritzar un servidor Squid.&lt;br /&gt;
*[[tinyproxy]]&lt;br /&gt;
*[[Canviar el format d'hora a l'access.log d'squid]]&lt;br /&gt;
&lt;br /&gt;
=Enllaços externs=&lt;br /&gt;
&lt;br /&gt;
* http://weblog.patrice.ch/xml/atom/article/325/feed.xml&lt;br /&gt;
* http://oreilly.com/catalog/9780596001629/preview#preview&lt;br /&gt;
&lt;br /&gt;
[[Servidor_Proxy|&amp;lt;&amp;lt; Tornar a Servidor Proxy]]&lt;br /&gt;
&lt;br /&gt;
[[Categoria:Servidor]]&lt;br /&gt;
[[Categoria:Proxy]]&lt;/div&gt;</summary>
		<author><name>Bellera</name></author>	</entry>

	<entry>
		<id>http://ca.wiki.guifi.net/wiki/Pfsense</id>
		<title>Pfsense</title>
		<link rel="alternate" type="text/html" href="http://ca.wiki.guifi.net/wiki/Pfsense"/>
				<updated>2014-03-14T06:38:16Z</updated>
		
		<summary type="html">&lt;p&gt;Bellera: Es crea la pàgina amb «Fòrum en castellà de pfSense, http://forum.pfsense.org/index.php/board,10.0.html  Administrat per www.bellera.cat/josep/consultes».&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Fòrum en castellà de pfSense, http://forum.pfsense.org/index.php/board,10.0.html&lt;br /&gt;
&lt;br /&gt;
Administrat per www.bellera.cat/josep/consultes&lt;/div&gt;</summary>
		<author><name>Bellera</name></author>	</entry>

	</feed>