View previous topic :: View next topic |
Author |
Message |
Gentoo Bob Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/405374037448ef4fa36002.jpg)
Joined: 12 Feb 2006 Posts: 129 Location: Sitting behind a PC in Indiana
|
Posted: Wed Jun 28, 2006 11:54 am Post subject: Squid from the outside |
|
|
Hey, I just installed squid on my system and I have pretty much left my squid.conf file default. I can access squid from my small network at home but when I'm outside my network I cannot. I am however hitting the proxy because I get the page displayed that I'm trying to reach "www.yahoo.com" but I don't have permission, access denied. So I know my ports are open and etc, and its not a networking issue. I think it is something in my config file and these acl's and I cant figure out what. The squid.conf file is so huge I know I'm missing something. Help anyone? _________________ AMD 64 X2 4400+ on ECS nForce4
2GB DDR, 250GB SATA, GeForce 5500FX 256MB DDR2 PCI-E
---and----
Dell Inspiron E1505 Laptop
Intel Centrino Duo, 2GB RAM, 80GB SATA HDD, Intel3490 ABG Wireless,CDRW |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
nevynxxx Veteran
![Veteran Veteran](/images/ranks/rank_rect_5_vet.gif)
Joined: 12 Nov 2003 Posts: 1123 Location: Manchester - UK
|
Posted: Wed Jun 28, 2006 12:36 pm Post subject: |
|
|
Off the top of my head I would agree that it is the acls, I think squid, by default limits access to the local subnet.
Open the squid file, and search for acl.
Most of the conf file is a very verbose description of the options, reading that is better in my experiance than any other docuemntation. _________________ My Public Key
Wanted: Instructor in the art of Bowyery |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Gentoo Bob Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/405374037448ef4fa36002.jpg)
Joined: 12 Feb 2006 Posts: 129 Location: Sitting behind a PC in Indiana
|
Posted: Wed Jun 28, 2006 3:01 pm Post subject: huh |
|
|
That really doesn't help me. I need more info on that. Where in the ACL's do I need make a change or add? and if I do need to add? Thats that problem I'm having. I want users from the outside to use the proxy and I can't. _________________ AMD 64 X2 4400+ on ECS nForce4
2GB DDR, 250GB SATA, GeForce 5500FX 256MB DDR2 PCI-E
---and----
Dell Inspiron E1505 Laptop
Intel Centrino Duo, 2GB RAM, 80GB SATA HDD, Intel3490 ABG Wireless,CDRW |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
nevynxxx Veteran
![Veteran Veteran](/images/ranks/rank_rect_5_vet.gif)
Joined: 12 Nov 2003 Posts: 1123 Location: Manchester - UK
|
Posted: Wed Jun 28, 2006 3:24 pm Post subject: |
|
|
There will be acls that deinfe the subnets that are allowed access.
Have you done as I said? Have you looked at the docs on the squid-cache website? These are the first two places to look.
If you are not willing to read, people are not willing to help.
The comments in the squid file make this just about as clear as it is possible to be, if you don't understand them, are you in a position to be opening this service to the world?
I don't mean to be harsh, and I don't mean to sound unhelpful, but when it comes to giveing the world access to your computer, the short answer is "Don't", the long answer is "Only if you really, really, know what you are doing, and have a really good reason to." _________________ My Public Key
Wanted: Instructor in the art of Bowyery |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Gentoo Bob Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/405374037448ef4fa36002.jpg)
Joined: 12 Feb 2006 Posts: 129 Location: Sitting behind a PC in Indiana
|
Posted: Wed Jun 28, 2006 3:45 pm Post subject: got it |
|
|
Hey I figured it out. Yes I read. I'm always reading. It was just a little confusing. I didnt really mean to give public access, just was having trouble saying the right words. Like I said, its a two part process...first define the ACL and then give it access with the HTTP_access syntax. That was what I was missing. It wasnt clear in documentations. Luckily i figured it out. Thanks for trying to help! _________________ AMD 64 X2 4400+ on ECS nForce4
2GB DDR, 250GB SATA, GeForce 5500FX 256MB DDR2 PCI-E
---and----
Dell Inspiron E1505 Laptop
Intel Centrino Duo, 2GB RAM, 80GB SATA HDD, Intel3490 ABG Wireless,CDRW |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
think4urs11 Bodhisattva
![Bodhisattva Bodhisattva](/images/ranks/rank-bodhisattva.gif)
![](images/avatars/8534934054bad29b51e5fa.jpg)
Joined: 25 Jun 2003 Posts: 6659 Location: above the cloud
|
Posted: Wed Jun 28, 2006 6:05 pm Post subject: |
|
|
hopefully you did narrow down the ip addresses to be allowed to access/use your squid as tight as possible.
Otherwise you will end up on various open proxy, maybe even spam lists (last depending on e.g. if you allow CONNECT outbound on port 25) _________________ Nothing is secure / Security is always a trade-off with usability / Do not assume anything / Trust no-one, nothing / Paranoia is your friend / Think for yourself |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
Gentoo Bob Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/405374037448ef4fa36002.jpg)
Joined: 12 Feb 2006 Posts: 129 Location: Sitting behind a PC in Indiana
|
Posted: Thu Jun 29, 2006 2:54 pm Post subject: you didnt read |
|
|
I sure did buddy! By the way Diane Keaton is HOT!!! _________________ AMD 64 X2 4400+ on ECS nForce4
2GB DDR, 250GB SATA, GeForce 5500FX 256MB DDR2 PCI-E
---and----
Dell Inspiron E1505 Laptop
Intel Centrino Duo, 2GB RAM, 80GB SATA HDD, Intel3490 ABG Wireless,CDRW |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|