Squid 3.1 на Centos 6.3

T
На сайте с 27.09.2011
Offline
23
2532

Через браузер не впускает на Squid, пишет ошибка 130.

ОС Centos 6.3 x64, версия Squid 3.1


Конфиг /etc/squid/squid.conf такой:

acl CONNECT method CONNECT

acl ipv4_all src all

acl one port 3001

acl two port 3002

http_access allow all

http_access allow one

http_access allow two

http_port 88.88.88.88:3001

http_port 99.99.99.99:3002

tcp_outgoing_address 88.88.88.88 one

tcp_outgoing_address 99.99.99.99 two

request_header_access X-Forwarded-For deny all

request_header_access Via deny all

request_header_access Cache-Control deny all

refresh_pattern ^ftp: 1440 20% 10080

refresh_pattern ^gopher: 1440 0% 1440

refresh_pattern -i (/cgi-bin/|\?) 0 0% 0

refresh_pattern . 0 20% 4320

Порты 3001,3002 открыты.

Что я делаю не так?

Romka_Kharkov
На сайте с 08.04.2009
Offline
485
#1

Что есть Ошибка 130 ?

(net:ERR_PROXY_CONNECTION_FAILED) ?

Какая задача стоит перед squid ? что в логах?

Есть около 15.000 ipv4 !!! (http://onyx.net.ua/price.php#ipv4) Качественный хостинг с 2005 года - лучшее клиентам! (http://onyx.net.ua/)
T
На сайте с 27.09.2011
Offline
23
#2
Romka_Kharkov:
Что есть Ошибка 130 ?
(net:ERR_PROXY_CONNECTION_FAILED) ?

Какая задача стоит перед squid ? что в логах?

Ошибка 130 (net::ERR_PROXY_CONNECTION_FAILED): Сбой при подключении к прокси-серверу

Цель: анонимный прокси с аутентификацией, с двумя ip

Последние логи /var/log/squid/cache.log:

2013/03/11 18:30:10| Shutting down...

2013/03/11 18:30:10| basic/auth_basic.cc(97) done: Basic authentication Shutdown.

2013/03/11 18:30:10| Closing unlinkd pipe on FD 23

2013/03/11 18:30:10| storeDirWriteCleanLogs: Starting...

2013/03/11 18:30:10| Finished. Wrote 0 entries.

2013/03/11 18:30:10| Took 0.00 seconds ( 0.00 entries/sec).

CPU Usage: 0.044 seconds = 0.025 user + 0.019 sys

Maximum Resident Size: 40848 KB

Page faults with physical i/o: 0

Memory usage for squid via mallinfo():

total space in arena: 3328 KB

Ordinary blocks: 3230 KB 6 blks

Small blocks: 0 KB 6 blks

Holding blocks: 1096 KB 4 blks

Free Small blocks: 0 KB

Free Ordinary blocks: 97 KB

Total in use: 4326 KB 130%

Total free: 97 KB 3%

2013/03/11 18:30:10| Open FD UNSTARTED 7 DNS Socket IPv6

2013/03/11 18:30:10| Open FD UNSTARTED 8 DNS Socket IPv4

2013/03/11 18:30:10| Open FD UNSTARTED 9 ncsa_auth #1

2013/03/11 18:30:10| Open FD UNSTARTED 11 ncsa_auth #2

2013/03/11 18:30:10| Open FD UNSTARTED 13 ncsa_auth #3

2013/03/11 18:30:10| Open FD UNSTARTED 15 ncsa_auth #4

2013/03/11 18:30:10| Open FD UNSTARTED 17 ncsa_auth #5

2013/03/11 18:30:10| Squid Cache (Version 3.1.10): Exiting normally.

2013/03/11 18:30:10| Starting Squid Cache version 3.1.10 for x86_64-redhat-linux-gnu...

2013/03/11 18:30:10| Process ID 21845

2013/03/11 18:30:10| With 1024 file descriptors available

2013/03/11 18:30:10| Initializing IP Cache...

2013/03/11 18:30:10| DNS Socket created at [::], FD 7

2013/03/11 18:30:10| DNS Socket created at 0.0.0.0, FD 8

2013/03/11 18:30:10| Adding nameserver 8.8.8.8 from /etc/resolv.conf

2013/03/11 18:30:10| Adding nameserver 88.88.88.1 from /etc/resolv.conf

2013/03/11 18:30:10| helperOpenServers: Starting 5/5 'ncsa_auth' processes

2013/03/11 18:30:10| User-Agent logging is disabled.

2013/03/11 18:30:10| Referer logging is disabled.

2013/03/11 18:30:11| Unlinkd pipe opened on FD 23

2013/03/11 18:30:11| Local cache digest enabled; rebuild/rewrite every 3600/3600 sec

2013/03/11 18:30:11| Store logging disabled

2013/03/11 18:30:11| Swap maxSize 0 + 262144 KB, estimated 20164 objects

2013/03/11 18:30:11| Target number of buckets: 1008

2013/03/11 18:30:11| Using 8192 Store buckets

2013/03/11 18:30:11| Max Mem size: 262144 KB

2013/03/11 18:30:11| Max Swap size: 0 KB

2013/03/11 18:30:11| Using Least Load store dir selection

2013/03/11 18:30:11| Current Directory is /

2013/03/11 18:30:11| Loaded Icons.

2013/03/11 18:30:11| Accepting HTTP connections at 88.88.88.88:3001, FD 24.

2013/03/11 18:30:11| Accepting HTTP connections at 99.99.99.99:3002, FD 25.

2013/03/11 18:30:11| HTCP Disabled.

2013/03/11 18:30:11| Squid plugin modules loaded: 0

2013/03/11 18:30:11| Adaptation support is off.

2013/03/11 18:30:11| Ready to serve requests.

2013/03/11 18:30:12| storeLateRelease: released 0 objects

Конфиг на данный момент такой /etc/squid/squid.conf:

acl all src all

acl one port 3001

acl two port 3002

acl CONNECT method CONNECT

http_access allow all

http_access allow one

http_access allow two

http_port 88.88.88.88:3001

http_port 99.99.99.99:3002

tcp_outgoing_address 88.88.88.88 one

tcp_outgoing_address 99.99.99.99 two

auth_param basic program /usr/lib64/squid/ncsa_auth /etc/squid/squid_passwd

auth_param basic children 5

auth_param basic realm Squid proxy-caching web server

auth_param basic credentialsttl 2 hours

acl ncsaauth proxy_auth REQUIRED

http_access allow ncsaauth

request_header_access X-Forwarded-For deny all

request_header_access Via deny all

request_header_access Cache-Control deny all

Я так понимаю, проблема где-то с acl???

Andreyka
На сайте с 19.02.2005
Offline
822
#3

Не тот лог/не полный

Не стоит плодить сущности без необходимости
T
На сайте с 27.09.2011
Offline
23
#4
Andreyka:
Не тот лог/не полный

/var/log/squid/access.log пустой.

/var/log/squid/squid.out

squid: ERROR: No running copy

squid: ERROR: No running copy

2013/03/11 12:10:05| WARNING: (B) '::/0' is a subnetwork of (A) '::/0'

2013/03/11 12:10:05| WARNING: because of this '::/0' is ignored to keep splay tree searching predictable

2013/03/11 12:10:05| WARNING: You should probably remove '::/0' from the ACL named 'all'

2013/03/11 12:10:37| WARNING: (B) '::/0' is a subnetwork of (A) '::/0'

2013/03/11 12:10:37| WARNING: because of this '::/0' is ignored to keep splay tree searching predictable

2013/03/11 12:10:37| WARNING: You should probably remove '::/0' from the ACL named 'all'

2013/03/11 13:21:52| cache_cf.cc(364) parseOneConfigFile: squid.conf:57 unrecognized: 'l'

WARNING: auth_param basic program /usr/lib/squid/ncsa_auth: (2) No such file or directory

2013/03/11 16:49:15| basic/auth_basic.cc(348) parse: unrecognised basic auth scheme parameter 'childred'

2013/03/11 17:01:15| basic/auth_basic.cc(348) parse: unrecognised basic auth scheme parameter 'childred'

2013/03/11 17:01:21| basic/auth_basic.cc(348) parse: unrecognised basic auth scheme parameter 'childred'

2013/03/11 17:03:49| basic/auth_basic.cc(348) parse: unrecognised basic auth scheme parameter 'childred'

2013/03/11 17:03:54| basic/auth_basic.cc(348) parse: unrecognised basic auth scheme parameter 'childred'

2013/03/11 17:24:04| aclIpParseIpData: Bad host/IP: 'all_ipv4' in 'all_ipv4', flags=0 : (-2) Name or service not known

FATAL: Bungled squid.conf line 1: acl all src all_ipv4

Squid Cache (Version 3.1.10): Terminated abnormally.

CPU Usage: 0.008 seconds = 0.003 user + 0.005 sys

Maximum Resident Size: 22832 KB

Page faults with physical i/o: 0

2013/03/11 18:24:07| cache_cf.cc(364) parseOneConfigFile: squid.conf:1 unrecognized: 'httpd_accel_with_proxy'

2013/03/11 18:24:45| cache_cf.cc(364) parseOneConfigFile: squid.conf:30 unrecognized: 'httpd_accel_with_proxy'

2013/03/11 18:28:11| ERROR: '0/0' needs to be replaced by the term 'all'.

2013/03/11 18:28:11| SECURITY NOTICE: Overriding config setting. Using 'all' instead.

squid: ERROR: No running copy

Все эти ошибки исправлены.

Andreyka
На сайте с 19.02.2005
Offline
822
#5

Включте максимальный уровень логов/дебаг

T
На сайте с 27.09.2011
Offline
23
#6
Andreyka:
Включте максимальный уровень логов/дебаг

Включил:

cache_access_log /var/log/squid/access.log

cache_store_log /var/log/squid/store.log

Они пустые, какие именно логи нужны?

Меня больше интересует вопрос по acl и http_access.

нужно чтобы на ip 88.88.88.88:3001 и 99.99.99.99:3002 могли подключиться с любого места, пройдя аутентификацию. Но по всей видимости где-то нарушена логика с acl и http_access, т.к. на прокси не впускает?

Авторизуйтесь или зарегистрируйтесь, чтобы оставить комментарий