squid.conf## Recommended minimum configuration:## Example rule allowing access from your local networks.# Adapt to list your (internal) IP networks from where browsing# should be allowedacl localnet src 10.0.0.0/8 # RFC1918 possible internal networkacl localnet src 0.0.0.0/0.0.0.0 # RFC1918 possible internal network#acl localnet src 172.16.0.0/12 # RFC1918 possible internal network#acl localnet src 192.168.0.0/16 # RFC1918 possible internal network#acl localnet src fc00::/7 # RFC 4193 local private network range#acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machinesacl SSL_ports port 443acl Safe_ports port 80 # httpacl Safe_ports port 21 # ftpacl Safe_ports port 443 # httpsacl Safe_ports port 70 # gopheracl Safe_ports port 210 # waisacl Safe_ports port 1025-65535 # unregistered portsacl Safe_ports port 280 # http-mgmtacl Safe_ports port 488 # gss-httpacl Safe_ports port 591 # filemakeracl Safe_ports port 777 # multiling httpacl CONNECT method CONNECTauth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/passwd_squidauth_param basic children 20auth_param basic realm Light co Squid auth_param basic credentialsttl 5 hours #认证的持续时间#acl ops-light proxy_auth REQUIRED acl auth_users proxy_auth ops-lightauth_param basic casesensitive offvisible_hostname Light-co.Squid.org## Recommended minimum Access Permission configuration:## Deny requests to certain unsafe portshttp_access deny !Safe_ports# Deny CONNECT to other than secure SSL portshttp_access deny CONNECT !SSL_ports# Only allow cachemgr access from localhosthttp_access allow localhost managerhttp_access deny manager# We strongly recommend the following be uncommented to protect innocent# web applications running on the proxy server who think the only# one who can access services on "localhost" is a local user#http_access deny to_localhost## INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS## Example rule allowing access from your local networks.# Adapt localnet in the ACL section to list your (internal) IP networks# from where browsing should be allowedhttp_access allow localnet#http_access allow ops-lighthttp_access allow auth_usershttp_access allow localhost# And finally deny all other access to this proxyhttp_access deny all# Squid normally listens to port 3128#http_port 3128http_port 9128# Uncomment and adjust the following to add a disk cache directory.#cache_dir ufs /var/spool/squid 100 16 256# Leave coredumps in the first cache dircoredump_dir /var/spool/squid## Add any of your own refresh_pattern entries above these.#refresh_pattern ^ftp: 1440 20% 10080refresh_pattern ^gopher: 1440 0% 1440refresh_pattern -i (/cgi-bin/|\?) 0 0% 0refresh_pattern . 0 20% 4320 passwd_squid ops-light:$apr1$pYiupR/9$8RN8oJW17hANmqWf5CO6.1