[c5c522c] | 1 | # WELCOME TO SQUID 2 |
---|
| 2 | # ------------------ |
---|
| 3 | # |
---|
| 4 | # This is the Syn-3 Squid configuration file. You may wish |
---|
| 5 | # to look at the Squid home page (http://www.squid-cache.org/) |
---|
| 6 | # for the FAQ and other documentation. |
---|
| 7 | |
---|
| 8 | # NETWORK OPTIONS |
---|
| 9 | # ----------------------------------------------------------------------------- |
---|
| 10 | |
---|
| 11 | # TAG: http_port |
---|
| 12 | #Default: |
---|
| 13 | http_port 3128 |
---|
| 14 | http_port 3129 transparent |
---|
| 15 | |
---|
| 16 | # TAG: https_port |
---|
| 17 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 18 | # --enable-ssl option |
---|
| 19 | #Default: |
---|
| 20 | # none |
---|
| 21 | |
---|
| 22 | # TAG: ssl_unclean_shutdown |
---|
| 23 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 24 | # --enable-ssl option |
---|
| 25 | #Default: |
---|
| 26 | # ssl_unclean_shutdown off |
---|
| 27 | |
---|
| 28 | # TAG: icp_port |
---|
| 29 | #Default: |
---|
| 30 | # icp_port 3130 |
---|
| 31 | |
---|
| 32 | # TAG: htcp_port |
---|
| 33 | #Default: |
---|
| 34 | # htcp_port 4827 |
---|
| 35 | |
---|
| 36 | # TAG: mcast_groups |
---|
| 37 | #Default: |
---|
| 38 | # none |
---|
| 39 | |
---|
| 40 | # TAG: udp_incoming_address |
---|
| 41 | # TAG: udp_outgoing_address |
---|
| 42 | #Default: |
---|
| 43 | # udp_incoming_address 0.0.0.0 |
---|
| 44 | # udp_outgoing_address 255.255.255.255 |
---|
| 45 | |
---|
| 46 | |
---|
| 47 | # OPTIONS WHICH AFFECT THE NEIGHBOR SELECTION ALGORITHM |
---|
| 48 | # ----------------------------------------------------------------------------- |
---|
| 49 | |
---|
| 50 | # TAG: cache_peer |
---|
| 51 | #Default: |
---|
| 52 | # none |
---|
| 53 | |
---|
| 54 | # TAG: cache_peer_domain |
---|
| 55 | #Default: |
---|
| 56 | # none |
---|
| 57 | |
---|
| 58 | # TAG: neighbor_type_domain |
---|
| 59 | #Default: |
---|
| 60 | # none |
---|
| 61 | |
---|
| 62 | # TAG: icp_query_timeout (msec) |
---|
| 63 | #Default: |
---|
| 64 | # icp_query_timeout 0 |
---|
| 65 | |
---|
| 66 | # TAG: maximum_icp_query_timeout (msec) |
---|
| 67 | #Default: |
---|
| 68 | # maximum_icp_query_timeout 2000 |
---|
| 69 | |
---|
| 70 | # TAG: mcast_icp_query_timeout (msec) |
---|
| 71 | #Default: |
---|
| 72 | # mcast_icp_query_timeout 2000 |
---|
| 73 | |
---|
| 74 | # TAG: dead_peer_timeout (seconds) |
---|
| 75 | #Default: |
---|
| 76 | # dead_peer_timeout 10 seconds |
---|
| 77 | |
---|
| 78 | # TAG: hierarchy_stoplist |
---|
| 79 | hierarchy_stoplist cgi-bin ? |
---|
| 80 | |
---|
| 81 | # TAG: no_cache |
---|
| 82 | acl QUERY urlpath_regex cgi-bin \? |
---|
| 83 | no_cache deny QUERY |
---|
| 84 | |
---|
| 85 | |
---|
| 86 | # OPTIONS WHICH AFFECT THE CACHE SIZE |
---|
| 87 | # ----------------------------------------------------------------------------- |
---|
| 88 | |
---|
| 89 | # TAG: cache_mem (bytes) |
---|
| 90 | #Default: |
---|
| 91 | cache_mem 32 MB |
---|
| 92 | |
---|
| 93 | # TAG: cache_swap_low (percent, 0-100) |
---|
| 94 | # TAG: cache_swap_high (percent, 0-100) |
---|
| 95 | #Default: |
---|
| 96 | # cache_swap_low 90 |
---|
| 97 | # cache_swap_high 95 |
---|
| 98 | |
---|
| 99 | # TAG: maximum_object_size (bytes) |
---|
| 100 | #Default: |
---|
| 101 | maximum_object_size 4096 KB |
---|
| 102 | |
---|
| 103 | # TAG: minimum_object_size (bytes) |
---|
| 104 | #Default: |
---|
| 105 | # minimum_object_size 0 KB |
---|
| 106 | |
---|
| 107 | # TAG: maximum_object_size_in_memory (bytes) |
---|
| 108 | #Default: |
---|
| 109 | # maximum_object_size_in_memory 8 KB |
---|
| 110 | |
---|
| 111 | # TAG: ipcache_size (number of entries) |
---|
| 112 | # TAG: ipcache_low (percent) |
---|
| 113 | # TAG: ipcache_high (percent) |
---|
| 114 | # The size, low-, and high-water marks for the IP cache. |
---|
| 115 | # |
---|
| 116 | #Default: |
---|
| 117 | # ipcache_size 1024 |
---|
| 118 | # ipcache_low 90 |
---|
| 119 | # ipcache_high 95 |
---|
| 120 | |
---|
| 121 | # TAG: fqdncache_size (number of entries) |
---|
| 122 | #Default: |
---|
| 123 | # fqdncache_size 1024 |
---|
| 124 | |
---|
| 125 | # TAG: cache_replacement_policy |
---|
| 126 | #Default: |
---|
| 127 | # cache_replacement_policy lru |
---|
| 128 | |
---|
| 129 | # TAG: memory_replacement_policy |
---|
| 130 | #Default: |
---|
| 131 | # memory_replacement_policy lru |
---|
| 132 | |
---|
| 133 | |
---|
| 134 | # LOGFILE PATHNAMES AND CACHE DIRECTORIES |
---|
| 135 | # ----------------------------------------------------------------------------- |
---|
| 136 | |
---|
| 137 | # TAG: cache_dir |
---|
| 138 | cache_dir ufs /home/system/proxy/cache 2048 16 256 |
---|
| 139 | |
---|
| 140 | # TAG: cache_access_log |
---|
| 141 | access_log /var/log/squid/access.log |
---|
| 142 | |
---|
| 143 | # TAG: cache_log |
---|
| 144 | cache_log none |
---|
| 145 | |
---|
| 146 | # TAG: cache_store_log |
---|
| 147 | cache_store_log none |
---|
| 148 | |
---|
| 149 | # TAG: cache_swap_log |
---|
| 150 | #Default: |
---|
| 151 | # none |
---|
| 152 | |
---|
| 153 | # TAG: emulate_httpd_log on|off |
---|
| 154 | #Default: |
---|
| 155 | # emulate_httpd_log off |
---|
| 156 | |
---|
| 157 | # TAG: log_ip_on_direct on|off |
---|
| 158 | #Default: |
---|
| 159 | # log_ip_on_direct on |
---|
| 160 | |
---|
| 161 | # TAG: mime_table |
---|
| 162 | #Default: |
---|
| 163 | # mime_table /etc/mime.conf |
---|
| 164 | |
---|
| 165 | # TAG: log_mime_hdrs on|off |
---|
| 166 | #Default: |
---|
| 167 | # log_mime_hdrs off |
---|
| 168 | |
---|
| 169 | # TAG: useragent_log |
---|
| 170 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 171 | # --enable-useragent-log option |
---|
| 172 | #Default: |
---|
| 173 | # none |
---|
| 174 | |
---|
| 175 | # TAG: referer_log |
---|
| 176 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 177 | # --enable-referer-log option |
---|
| 178 | #Default: |
---|
| 179 | # none |
---|
| 180 | |
---|
| 181 | # TAG: pid_filename |
---|
| 182 | pid_filename /var/run/squid.pid |
---|
| 183 | |
---|
| 184 | # TAG: debug_options |
---|
| 185 | #Default: |
---|
| 186 | # debug_options ALL,1 |
---|
| 187 | |
---|
| 188 | # TAG: log_fqdn on|off |
---|
| 189 | #Default: |
---|
| 190 | # log_fqdn off |
---|
| 191 | |
---|
| 192 | # TAG: client_netmask |
---|
| 193 | #Default: |
---|
| 194 | # client_netmask 255.255.255.255 |
---|
| 195 | |
---|
| 196 | |
---|
| 197 | # OPTIONS FOR EXTERNAL SUPPORT PROGRAMS |
---|
| 198 | # ----------------------------------------------------------------------------- |
---|
| 199 | |
---|
| 200 | # TAG: ftp_user |
---|
| 201 | #Default: |
---|
| 202 | # ftp_user Squid@ |
---|
| 203 | |
---|
| 204 | # TAG: ftp_list_width |
---|
| 205 | #Default: |
---|
| 206 | # ftp_list_width 32 |
---|
| 207 | |
---|
| 208 | # TAG: ftp_passive |
---|
| 209 | #Default: |
---|
| 210 | # ftp_passive on |
---|
| 211 | |
---|
| 212 | # TAG: ftp_sanitycheck |
---|
| 213 | #Default: |
---|
| 214 | # ftp_sanitycheck on |
---|
| 215 | |
---|
| 216 | # TAG: ftp_telnet_protocol |
---|
| 217 | #Default: |
---|
| 218 | # ftp_telnet_protocol on |
---|
| 219 | |
---|
| 220 | # TAG: cache_dns_program |
---|
| 221 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 222 | # --disable-internal-dns option |
---|
| 223 | #Default: |
---|
| 224 | # cache_dns_program /usr/bin/dnsserver |
---|
| 225 | |
---|
| 226 | # TAG: dns_children |
---|
| 227 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 228 | # --disable-internal-dns option |
---|
| 229 | #Default: |
---|
| 230 | # dns_children 5 |
---|
| 231 | |
---|
| 232 | # TAG: dns_retransmit_interval |
---|
| 233 | #Default: |
---|
| 234 | # dns_retransmit_interval 5 seconds |
---|
| 235 | |
---|
| 236 | # TAG: dns_timeout |
---|
| 237 | #Default: |
---|
| 238 | # dns_timeout 2 minutes |
---|
| 239 | |
---|
| 240 | # TAG: dns_defnames on|off |
---|
| 241 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 242 | # --disable-internal-dns option |
---|
| 243 | #Default: |
---|
| 244 | # dns_defnames off |
---|
| 245 | |
---|
| 246 | # TAG: dns_nameservers |
---|
| 247 | #Default: |
---|
| 248 | # none |
---|
| 249 | |
---|
| 250 | # TAG: hosts_file |
---|
| 251 | hosts_file /etc/hosts |
---|
| 252 | |
---|
| 253 | # TAG: diskd_program |
---|
| 254 | #Default: |
---|
| 255 | # diskd_program /usr/bin/diskd |
---|
| 256 | |
---|
| 257 | # TAG: unlinkd_program |
---|
| 258 | #Default: |
---|
| 259 | # unlinkd_program /usr/bin/unlinkd |
---|
| 260 | |
---|
| 261 | # TAG: pinger_program |
---|
| 262 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 263 | # --enable-icmp option |
---|
| 264 | #Default: |
---|
| 265 | # pinger_program /usr/bin/pinger |
---|
| 266 | |
---|
| 267 | # TAG: redirect_program |
---|
| 268 | #Default: |
---|
| 269 | # none |
---|
| 270 | |
---|
| 271 | # TAG: redirect_children |
---|
| 272 | #Default: |
---|
| 273 | # redirect_children 5 |
---|
| 274 | |
---|
| 275 | # TAG: redirect_rewrites_host_header |
---|
| 276 | #Default: |
---|
| 277 | # redirect_rewrites_host_header on |
---|
| 278 | |
---|
| 279 | # TAG: redirector_access |
---|
| 280 | #Default: |
---|
| 281 | # none |
---|
| 282 | |
---|
| 283 | # TAG: auth_param |
---|
| 284 | |
---|
| 285 | |
---|
| 286 | #auth_param ntlm program /usr/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp |
---|
| 287 | #auth_param ntlm children 5 |
---|
| 288 | auth_param basic program /usr/bin/squid_ldap_auth -v 3 -u uid -b "ou=Users,dc=syn-3" -h ldap-master |
---|
| 289 | auth_param basic children 5 |
---|
| 290 | auth_param basic realm Squid proxy-caching web server |
---|
| 291 | auth_param basic credentialsttl 2 hours |
---|
| 292 | auth_param basic casesensitive off |
---|
| 293 | |
---|
| 294 | |
---|
| 295 | |
---|
| 296 | # TAG: authenticate_cache_garbage_interval |
---|
| 297 | #Default: |
---|
| 298 | authenticate_cache_garbage_interval 1 minute |
---|
| 299 | |
---|
| 300 | # TAG: authenticate_ttl |
---|
| 301 | #Default: |
---|
| 302 | authenticate_ttl 1 minute |
---|
| 303 | |
---|
| 304 | # TAG: authenticate_ip_ttl |
---|
| 305 | #Default: |
---|
| 306 | # authenticate_ip_ttl 0 seconds |
---|
| 307 | |
---|
| 308 | # TAG: external_acl_type |
---|
| 309 | #Default: |
---|
| 310 | # none |
---|
| 311 | external_acl_type ldap_group ttl=300 %LOGIN /usr/bin/squid_ldap_group -b "ou=Groups,dc=syn-3" -h ldap-master -f "(&(memberuid=%v)(cn=%a))" |
---|
| 312 | external_acl_type wbinfo_group %LOGIN /usr/bin/wbinfo_group.pl |
---|
| 313 | |
---|
| 314 | # OPTIONS FOR TUNING THE CACHE |
---|
| 315 | # ----------------------------------------------------------------------------- |
---|
| 316 | |
---|
| 317 | # TAG: wais_relay_host |
---|
| 318 | # TAG: wais_relay_port |
---|
| 319 | # Relay WAIS request to host (1st arg) at port (2 arg). |
---|
| 320 | # |
---|
| 321 | #Default: |
---|
| 322 | # wais_relay_port 0 |
---|
| 323 | |
---|
| 324 | # TAG: request_header_max_size (KB) |
---|
| 325 | #Default: |
---|
| 326 | # request_header_max_size 20 KB |
---|
| 327 | |
---|
| 328 | # TAG: request_body_max_size (KB) |
---|
| 329 | #Default: |
---|
| 330 | # request_body_max_size 0 KB |
---|
| 331 | |
---|
| 332 | # TAG: refresh_pattern |
---|
| 333 | #Suggested default: |
---|
| 334 | refresh_pattern ^ftp: 1440 20% 10080 |
---|
| 335 | refresh_pattern ^gopher: 1440 0% 1440 |
---|
| 336 | refresh_pattern . 0 20% 4320 |
---|
| 337 | |
---|
| 338 | # TAG: quick_abort_min (KB) |
---|
| 339 | # TAG: quick_abort_max (KB) |
---|
| 340 | # TAG: quick_abort_pct (percent) |
---|
| 341 | #Default: |
---|
| 342 | # quick_abort_min 16 KB |
---|
| 343 | # quick_abort_max 16 KB |
---|
| 344 | # quick_abort_pct 95 |
---|
| 345 | |
---|
| 346 | # TAG: negative_ttl time-units |
---|
| 347 | #Default: |
---|
| 348 | # negative_ttl 5 minutes |
---|
| 349 | |
---|
| 350 | # TAG: positive_dns_ttl time-units |
---|
| 351 | #Default: |
---|
| 352 | # positive_dns_ttl 6 hours |
---|
| 353 | |
---|
| 354 | # TAG: negative_dns_ttl time-units |
---|
| 355 | #Default: |
---|
| 356 | # negative_dns_ttl 1 minute |
---|
| 357 | |
---|
| 358 | # TAG: range_offset_limit (bytes) |
---|
| 359 | #Default: |
---|
| 360 | # range_offset_limit 0 KB |
---|
| 361 | |
---|
| 362 | |
---|
| 363 | # TIMEOUTS |
---|
| 364 | # ----------------------------------------------------------------------------- |
---|
| 365 | |
---|
| 366 | # TAG: forward_timeout time-units |
---|
| 367 | #Default: |
---|
| 368 | # forward_timeout 4 minutes |
---|
| 369 | |
---|
| 370 | # TAG: connect_timeout time-units |
---|
| 371 | #Default: |
---|
| 372 | # connect_timeout 1 minute |
---|
| 373 | |
---|
| 374 | # TAG: peer_connect_timeout time-units |
---|
| 375 | #Default: |
---|
| 376 | # peer_connect_timeout 30 seconds |
---|
| 377 | |
---|
| 378 | # TAG: read_timeout time-units |
---|
| 379 | #Default: |
---|
| 380 | # read_timeout 15 minutes |
---|
| 381 | |
---|
| 382 | # TAG: request_timeout |
---|
| 383 | #Default: |
---|
| 384 | # request_timeout 5 minutes |
---|
| 385 | |
---|
| 386 | # TAG: persistent_request_timeout |
---|
| 387 | #Default: |
---|
| 388 | # persistent_request_timeout 1 minute |
---|
| 389 | |
---|
| 390 | # TAG: client_lifetime time-units |
---|
| 391 | #Default: |
---|
| 392 | # client_lifetime 1 day |
---|
| 393 | |
---|
| 394 | # TAG: half_closed_clients |
---|
| 395 | #Default: |
---|
| 396 | # half_closed_clients on |
---|
| 397 | |
---|
| 398 | # TAG: pconn_timeout |
---|
| 399 | #Default: |
---|
| 400 | # pconn_timeout 120 seconds |
---|
| 401 | |
---|
| 402 | # TAG: ident_timeout |
---|
| 403 | #Default: |
---|
| 404 | # ident_timeout 10 seconds |
---|
| 405 | |
---|
| 406 | # TAG: shutdown_lifetime time-units |
---|
| 407 | #Default: |
---|
| 408 | shutdown_lifetime 1 seconds |
---|
| 409 | |
---|
| 410 | |
---|
| 411 | # ACCESS CONTROLS |
---|
| 412 | acl syn3SourceList_private_adressen src "/home/system/proxy/filterlists/SourceList_private_adressen" |
---|
| 413 | acl syn3SourceList_All src "/home/system/proxy/filterlists/SourceList_All" |
---|
| 414 | acl syn3PortList_SSL_Ports port "/home/system/proxy/filterlists/PortList_SSL_Ports" |
---|
| 415 | acl syn3DestList_to_localhost dst "/home/system/proxy/filterlists/DestList_to_localhost" |
---|
| 416 | acl syn3SourceList_localhost src "/home/system/proxy/filterlists/SourceList_localhost" |
---|
| 417 | acl syn3PortList_Safe_ports port "/home/system/proxy/filterlists/PortList_Safe_ports" |
---|
| 418 | acl syn3domainIP_Default url_regex "/home/system/proxy/filterlists/domainIP_Default" |
---|
| 419 | acl syn3Group_Internet external ldap_group Internet |
---|
| 420 | acl syn3ReqPro_Management_protocol proto "/home/system/proxy/filterlists/ReqPro_Management_protocol" |
---|
| 421 | acl syn3ReqHead_CONNECT method "/home/system/proxy/filterlists/ReqHead_CONNECT" |
---|
| 422 | |
---|
| 423 | # TAG: http_access |
---|
| 424 | http_access deny syn3ReqPro_Management_protocol |
---|
| 425 | http_access deny !syn3PortList_Safe_ports |
---|
| 426 | http_access deny !syn3PortList_SSL_Ports syn3ReqHead_CONNECT |
---|
| 427 | http_access deny syn3DestList_to_localhost |
---|
| 428 | http_access allow syn3SourceList_localhost |
---|
| 429 | http_access deny !syn3SourceList_private_adressen |
---|
| 430 | http_access allow syn3SourceList_All |
---|
| 431 | #syn3default_rules |
---|
| 432 | |
---|
| 433 | # TAG: http_reply_access |
---|
| 434 | #Default: |
---|
| 435 | # http_reply_access allow all |
---|
| 436 | # |
---|
| 437 | #Recommended minimum configuration: |
---|
| 438 | # Insert your own rules here. |
---|
| 439 | # and finally allow by default |
---|
| 440 | http_reply_access allow syn3SourceList_All |
---|
| 441 | |
---|
| 442 | # TAG: icp_access |
---|
| 443 | #Default: |
---|
| 444 | # icp_access deny all |
---|
| 445 | # |
---|
| 446 | #Allow ICP queries from everyone |
---|
| 447 | icp_access allow syn3SourceList_All |
---|
| 448 | |
---|
| 449 | # TAG: miss_access |
---|
| 450 | #Default setting: |
---|
| 451 | miss_access allow syn3SourceList_All |
---|
| 452 | |
---|
| 453 | # TAG: follow_x_forwarded_for |
---|
| 454 | follow_x_forwarded_for allow syn3SourceList_localhost |
---|
| 455 | |
---|
| 456 | |
---|
| 457 | # TAG: cache_peer_access |
---|
| 458 | #Default: |
---|
| 459 | # none |
---|
| 460 | |
---|
| 461 | # TAG: ident_lookup_access |
---|
| 462 | #Default: |
---|
| 463 | ident_lookup_access deny syn3SourceList_All |
---|
| 464 | |
---|
| 465 | # TAG: tcp_outgoing_tos |
---|
| 466 | #Default: |
---|
| 467 | # none |
---|
| 468 | |
---|
| 469 | # TAG: tcp_outgoing_address |
---|
| 470 | #Default: |
---|
| 471 | # none |
---|
| 472 | |
---|
| 473 | # TAG: reply_header_max_size (KB) |
---|
| 474 | #Default: |
---|
| 475 | # reply_header_max_size 20 KB |
---|
| 476 | |
---|
| 477 | # TAG: reply_body_max_size bytes allow|deny acl acl... |
---|
| 478 | #Default: |
---|
| 479 | reply_body_max_size 0 allow syn3SourceList_All |
---|
| 480 | |
---|
| 481 | |
---|
| 482 | # ADMINISTRATIVE PARAMETERS |
---|
| 483 | # ----------------------------------------------------------------------------- |
---|
| 484 | |
---|
| 485 | # TAG: cache_mgr |
---|
| 486 | #Default: |
---|
| 487 | # cache_mgr webmaster |
---|
| 488 | |
---|
| 489 | # TAG: cache_effective_user |
---|
| 490 | #Default: |
---|
| 491 | cache_effective_user nobody |
---|
| 492 | |
---|
| 493 | # TAG: cache_effective_group |
---|
| 494 | #Default: |
---|
| 495 | cache_effective_group nogroup |
---|
| 496 | |
---|
| 497 | # TAG: visible_hostname |
---|
| 498 | #Default: |
---|
| 499 | # none |
---|
| 500 | |
---|
| 501 | # TAG: unique_hostname |
---|
| 502 | #Default: |
---|
| 503 | # none |
---|
| 504 | |
---|
| 505 | # TAG: hostname_aliases |
---|
| 506 | #Default: |
---|
| 507 | # none |
---|
| 508 | |
---|
| 509 | |
---|
| 510 | # OPTIONS FOR THE CACHE REGISTRATION SERVICE |
---|
| 511 | # ----------------------------------------------------------------------------- |
---|
| 512 | |
---|
| 513 | # TAG: announce_period |
---|
| 514 | #Default: |
---|
| 515 | # announce_period 0 |
---|
| 516 | # |
---|
| 517 | #To enable announcing your cache, just uncomment the line below. |
---|
| 518 | #announce_period 1 day |
---|
| 519 | |
---|
| 520 | # TAG: announce_host |
---|
| 521 | # TAG: announce_file |
---|
| 522 | # TAG: announce_port |
---|
| 523 | #Default: |
---|
| 524 | # announce_host tracker.ircache.net |
---|
| 525 | # announce_port 3131 |
---|
| 526 | |
---|
| 527 | |
---|
| 528 | # HTTPD-ACCELERATOR OPTIONS |
---|
| 529 | # ----------------------------------------------------------------------------- |
---|
| 530 | |
---|
| 531 | # TAG: httpd_accel_host |
---|
| 532 | # TAG: httpd_accel_port |
---|
| 533 | #Default: |
---|
| 534 | # httpd_accel_port 80 |
---|
| 535 | |
---|
| 536 | # TAG: httpd_accel_single_host on|off |
---|
| 537 | #Default: |
---|
| 538 | # httpd_accel_single_host off |
---|
| 539 | |
---|
| 540 | # TAG: httpd_accel_with_proxy on|off |
---|
| 541 | #Default: |
---|
| 542 | # httpd_accel_with_proxy off |
---|
| 543 | |
---|
| 544 | # TAG: httpd_accel_uses_host_header on|off |
---|
| 545 | #Default: |
---|
| 546 | # httpd_accel_uses_host_header off |
---|
| 547 | |
---|
| 548 | |
---|
| 549 | # MISCELLANEOUS |
---|
| 550 | # ----------------------------------------------------------------------------- |
---|
| 551 | |
---|
| 552 | # TAG: dns_testnames |
---|
| 553 | #Default: |
---|
| 554 | # dns_testnames netscape.com internic.net nlanr.net microsoft.com |
---|
| 555 | |
---|
| 556 | # TAG: logfile_rotate |
---|
| 557 | #Default: |
---|
| 558 | # logfile_rotate 10 |
---|
| 559 | |
---|
| 560 | # TAG: append_domain |
---|
| 561 | #Default: |
---|
| 562 | # none |
---|
| 563 | |
---|
| 564 | # TAG: tcp_recv_bufsize (bytes) |
---|
| 565 | #Default: |
---|
| 566 | # tcp_recv_bufsize 0 bytes |
---|
| 567 | |
---|
| 568 | # TAG: err_html_text |
---|
| 569 | #Default: |
---|
| 570 | # none |
---|
| 571 | |
---|
| 572 | # TAG: deny_info |
---|
| 573 | #Default: |
---|
| 574 | # none |
---|
| 575 | |
---|
| 576 | # TAG: memory_pools on|off |
---|
| 577 | #Default: |
---|
| 578 | # memory_pools on |
---|
| 579 | |
---|
| 580 | # TAG: memory_pools_limit (bytes) |
---|
| 581 | #Default: |
---|
| 582 | # memory_pools_limit 5 MB |
---|
| 583 | |
---|
| 584 | # TAG: forwarded_for on|off |
---|
| 585 | #Default: |
---|
| 586 | # forwarded_for on |
---|
| 587 | |
---|
| 588 | # TAG: log_icp_queries on|off |
---|
| 589 | #Default: |
---|
| 590 | # log_icp_queries on |
---|
| 591 | |
---|
| 592 | # TAG: icp_hit_stale on|off |
---|
| 593 | #Default: |
---|
| 594 | # icp_hit_stale off |
---|
| 595 | |
---|
| 596 | # TAG: minimum_direct_hops |
---|
| 597 | #Default: |
---|
| 598 | # minimum_direct_hops 4 |
---|
| 599 | |
---|
| 600 | # TAG: minimum_direct_rtt |
---|
| 601 | #Default: |
---|
| 602 | # minimum_direct_rtt 400 |
---|
| 603 | |
---|
| 604 | # TAG: cachemgr_passwd |
---|
| 605 | #Default: |
---|
| 606 | # none |
---|
| 607 | |
---|
| 608 | # TAG: store_avg_object_size (kbytes) |
---|
| 609 | #Default: |
---|
| 610 | # store_avg_object_size 13 KB |
---|
| 611 | |
---|
| 612 | # TAG: store_objects_per_bucket |
---|
| 613 | #Default: |
---|
| 614 | # store_objects_per_bucket 20 |
---|
| 615 | |
---|
| 616 | # TAG: client_db on|off |
---|
| 617 | #Default: |
---|
| 618 | # client_db on |
---|
| 619 | |
---|
| 620 | # TAG: netdb_low |
---|
| 621 | # TAG: netdb_high |
---|
| 622 | #Default: |
---|
| 623 | # netdb_low 900 |
---|
| 624 | # netdb_high 1000 |
---|
| 625 | |
---|
| 626 | # TAG: netdb_ping_period |
---|
| 627 | #Default: |
---|
| 628 | # netdb_ping_period 5 minutes |
---|
| 629 | |
---|
| 630 | # TAG: query_icmp on|off |
---|
| 631 | #Default: |
---|
| 632 | # query_icmp off |
---|
| 633 | |
---|
| 634 | # TAG: test_reachability on|off |
---|
| 635 | #Default: |
---|
| 636 | # test_reachability off |
---|
| 637 | |
---|
| 638 | # TAG: buffered_logs on|off |
---|
| 639 | #Default: |
---|
| 640 | # buffered_logs off |
---|
| 641 | |
---|
| 642 | # TAG: reload_into_ims on|off |
---|
| 643 | #Default: |
---|
| 644 | # reload_into_ims off |
---|
| 645 | |
---|
| 646 | # TAG: always_direct |
---|
| 647 | #Default: |
---|
| 648 | # none |
---|
| 649 | |
---|
| 650 | # TAG: never_direct |
---|
| 651 | #Default: |
---|
| 652 | # none |
---|
| 653 | |
---|
| 654 | # TAG: header_access |
---|
| 655 | # Usage: header_access header_name allow|deny [!]aclname ... |
---|
| 656 | # |
---|
| 657 | # WARNING: Doing this VIOLATES the HTTP standard. Enabling |
---|
| 658 | # this feature could make you liable for problems which it |
---|
| 659 | # causes. |
---|
| 660 | #Default: |
---|
| 661 | # none |
---|
| 662 | |
---|
| 663 | # TAG: header_replace |
---|
| 664 | # By default, headers are removed if denied. |
---|
| 665 | #Default: |
---|
| 666 | # none |
---|
| 667 | |
---|
| 668 | # TAG: icon_directory |
---|
| 669 | # Where the icons are stored. These are normally kept in |
---|
| 670 | #Default: |
---|
| 671 | # icon_directory /usr/share/icons |
---|
| 672 | |
---|
| 673 | # TAG: short_icon_urls |
---|
| 674 | #Default: |
---|
| 675 | # short_icon_urls off |
---|
| 676 | |
---|
| 677 | # TAG: error_directory |
---|
| 678 | #Default: |
---|
| 679 | # error_directory /usr/share/errors/English |
---|
| 680 | |
---|
| 681 | # TAG: maximum_single_addr_tries |
---|
| 682 | #Default: |
---|
| 683 | # maximum_single_addr_tries 1 |
---|
| 684 | |
---|
| 685 | # TAG: snmp_port |
---|
| 686 | #Default: |
---|
| 687 | # snmp_port 3401 |
---|
| 688 | |
---|
| 689 | # TAG: snmp_access |
---|
| 690 | #Example: |
---|
| 691 | # snmp_access allow snmppublic localhost |
---|
| 692 | # snmp_access deny all |
---|
| 693 | # |
---|
| 694 | #Default: |
---|
| 695 | # snmp_access deny all |
---|
| 696 | |
---|
| 697 | # TAG: snmp_incoming_address |
---|
| 698 | # TAG: snmp_outgoing_address |
---|
| 699 | #Default: |
---|
| 700 | # snmp_incoming_address 0.0.0.0 |
---|
| 701 | # snmp_outgoing_address 255.255.255.255 |
---|
| 702 | |
---|
| 703 | # TAG: as_whois_server |
---|
| 704 | #Default: |
---|
| 705 | # as_whois_server whois.ra.net |
---|
| 706 | # as_whois_server whois.ra.net |
---|
| 707 | |
---|
| 708 | # TAG: wccp_router |
---|
| 709 | # Use this option to define your WCCP ``home'' router for |
---|
| 710 | # Squid. Setting the 'wccp_router' to 0.0.0.0 (the default) |
---|
| 711 | # disables WCCP. |
---|
| 712 | # |
---|
| 713 | #Default: |
---|
| 714 | # wccp_router 0.0.0.0 |
---|
| 715 | |
---|
| 716 | # TAG: wccp_version |
---|
| 717 | #Default: |
---|
| 718 | # wccp_version 4 |
---|
| 719 | |
---|
| 720 | # TAG: wccp_incoming_address |
---|
| 721 | # TAG: wccp_outgoing_address |
---|
| 722 | #Default: |
---|
| 723 | # wccp_incoming_address 0.0.0.0 |
---|
| 724 | # wccp_outgoing_address 255.255.255.255 |
---|
| 725 | |
---|
| 726 | |
---|
| 727 | # DELAY POOL PARAMETERS (all require DELAY_POOLS compilation option) |
---|
| 728 | # ----------------------------------------------------------------------------- |
---|
| 729 | |
---|
| 730 | # TAG: delay_pools |
---|
| 731 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 732 | # --enable-delay-pools option |
---|
| 733 | #Default: |
---|
| 734 | # delay_pools 0 |
---|
| 735 | |
---|
| 736 | # TAG: delay_class |
---|
| 737 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 738 | # --enable-delay-pools option |
---|
| 739 | #Default: |
---|
| 740 | # none |
---|
| 741 | |
---|
| 742 | # TAG: delay_access |
---|
| 743 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 744 | # --enable-delay-pools option |
---|
| 745 | #Default: |
---|
| 746 | # none |
---|
| 747 | |
---|
| 748 | # TAG: delay_parameters |
---|
| 749 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 750 | # --enable-delay-pools option |
---|
| 751 | #delay_parameters pool aggregate |
---|
| 752 | #delay_parameters pool aggregate individual |
---|
| 753 | #delay_parameters pool aggregate network individual |
---|
| 754 | #delay_parameters 1 -1/-1 8000/8000 |
---|
| 755 | #delay_parameters 2 32000/32000 8000/8000 600/8000 |
---|
| 756 | #Default: |
---|
| 757 | # none |
---|
| 758 | |
---|
| 759 | # TAG: delay_initial_bucket_level (percent, 0-100) |
---|
| 760 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 761 | # --enable-delay-pools option |
---|
| 762 | #Default: |
---|
| 763 | # delay_initial_bucket_level 50 |
---|
| 764 | |
---|
| 765 | # TAG: incoming_icp_average |
---|
| 766 | # TAG: incoming_http_average |
---|
| 767 | # TAG: incoming_dns_average |
---|
| 768 | # TAG: min_icp_poll_cnt |
---|
| 769 | # TAG: min_dns_poll_cnt |
---|
| 770 | # TAG: min_http_poll_cnt |
---|
| 771 | # Heavy voodoo here. I can't even believe you are reading this. |
---|
| 772 | # Are you crazy? Don't even think about adjusting these unless |
---|
| 773 | # you understand the algorithms in comm_select.c first! |
---|
| 774 | # |
---|
| 775 | #Default: |
---|
| 776 | # incoming_icp_average 6 |
---|
| 777 | # incoming_http_average 4 |
---|
| 778 | # incoming_dns_average 4 |
---|
| 779 | # min_icp_poll_cnt 8 |
---|
| 780 | # min_dns_poll_cnt 8 |
---|
| 781 | # min_http_poll_cnt 8 |
---|
| 782 | |
---|
| 783 | # TAG: max_open_disk_fds |
---|
| 784 | #Default: |
---|
| 785 | # max_open_disk_fds 0 |
---|
| 786 | |
---|
| 787 | # TAG: offline_mode |
---|
| 788 | #Default: |
---|
| 789 | # offline_mode off |
---|
| 790 | |
---|
| 791 | # TAG: uri_whitespace |
---|
| 792 | #Default: |
---|
| 793 | # uri_whitespace strip |
---|
| 794 | |
---|
| 795 | # TAG: broken_posts |
---|
| 796 | #Default: |
---|
| 797 | # none |
---|
| 798 | |
---|
| 799 | # TAG: mcast_miss_addr |
---|
| 800 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 801 | # -DMULTICAST_MISS_STREAM option |
---|
| 802 | #Default: |
---|
| 803 | # mcast_miss_addr 255.255.255.255 |
---|
| 804 | |
---|
| 805 | # TAG: mcast_miss_ttl |
---|
| 806 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 807 | # -DMULTICAST_MISS_TTL option |
---|
| 808 | #Default: |
---|
| 809 | # mcast_miss_ttl 16 |
---|
| 810 | |
---|
| 811 | # TAG: mcast_miss_port |
---|
| 812 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 813 | # -DMULTICAST_MISS_STREAM option |
---|
| 814 | #Default: |
---|
| 815 | # mcast_miss_port 3135 |
---|
| 816 | |
---|
| 817 | # TAG: mcast_miss_encode_key |
---|
| 818 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 819 | # -DMULTICAST_MISS_STREAM option |
---|
| 820 | #Default: |
---|
| 821 | # mcast_miss_encode_key XXXXXXXXXXXXXXXX |
---|
| 822 | |
---|
| 823 | # TAG: nonhierarchical_direct |
---|
| 824 | #Default: |
---|
| 825 | # nonhierarchical_direct on |
---|
| 826 | |
---|
| 827 | # TAG: prefer_direct |
---|
| 828 | #Default: |
---|
| 829 | # prefer_direct off |
---|
| 830 | |
---|
| 831 | # TAG: strip_query_terms |
---|
| 832 | # By default, Squid strips query terms from requested URLs before |
---|
| 833 | # logging. This protects your user's privacy. |
---|
| 834 | # |
---|
| 835 | #Default: |
---|
| 836 | # strip_query_terms on |
---|
| 837 | |
---|
| 838 | # TAG: coredump_dir |
---|
| 839 | #Default: |
---|
| 840 | # coredump_dir none |
---|
| 841 | # |
---|
| 842 | # Leave coredumps in the first cache dir |
---|
| 843 | coredump_dir /var/cache |
---|
| 844 | |
---|
| 845 | # TAG: redirector_bypass |
---|
| 846 | #Default: |
---|
| 847 | # redirector_bypass off |
---|
| 848 | |
---|
| 849 | # TAG: ignore_unknown_nameservers |
---|
| 850 | #Default: |
---|
| 851 | # ignore_unknown_nameservers on |
---|
| 852 | |
---|
| 853 | # TAG: digest_generation |
---|
| 854 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 855 | # --enable-cache-digests option |
---|
| 856 | #Default: |
---|
| 857 | # digest_generation on |
---|
| 858 | |
---|
| 859 | # TAG: digest_bits_per_entry |
---|
| 860 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 861 | # --enable-cache-digests option |
---|
| 862 | #Default: |
---|
| 863 | # digest_bits_per_entry 5 |
---|
| 864 | |
---|
| 865 | # TAG: digest_rebuild_period (seconds) |
---|
| 866 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 867 | # --enable-cache-digests option |
---|
| 868 | #Default: |
---|
| 869 | # digest_rebuild_period 1 hour |
---|
| 870 | |
---|
| 871 | # TAG: digest_rewrite_period (seconds) |
---|
| 872 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 873 | # --enable-cache-digests option |
---|
| 874 | #Default: |
---|
| 875 | # digest_rewrite_period 1 hour |
---|
| 876 | |
---|
| 877 | # TAG: digest_swapout_chunk_size (bytes) |
---|
| 878 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 879 | # --enable-cache-digests option |
---|
| 880 | #Default: |
---|
| 881 | # digest_swapout_chunk_size 4096 bytes |
---|
| 882 | |
---|
| 883 | # TAG: digest_rebuild_chunk_percentage (percent, 0-100) |
---|
| 884 | # Note: This option is only available if Squid is rebuilt with the |
---|
| 885 | # --enable-cache-digests option |
---|
| 886 | #Default: |
---|
| 887 | # digest_rebuild_chunk_percentage 10 |
---|
| 888 | |
---|
| 889 | # TAG: chroot |
---|
| 890 | #Default: |
---|
| 891 | # none |
---|
| 892 | |
---|
| 893 | # TAG: client_persistent_connections |
---|
| 894 | # TAG: server_persistent_connections |
---|
| 895 | #Default: |
---|
| 896 | # client_persistent_connections on |
---|
| 897 | # server_persistent_connections on |
---|
| 898 | |
---|
| 899 | # TAG: detect_broken_pconn |
---|
| 900 | #Default: |
---|
| 901 | # detect_broken_pconn off |
---|
| 902 | |
---|
| 903 | # TAG: balance_on_multiple_ip |
---|
| 904 | #Default: |
---|
| 905 | # balance_on_multiple_ip on |
---|
| 906 | |
---|
| 907 | # TAG: pipeline_prefetch |
---|
| 908 | #Default: |
---|
| 909 | # pipeline_prefetch off |
---|
| 910 | |
---|
| 911 | # TAG: extension_methods |
---|
| 912 | #Default: |
---|
| 913 | # none |
---|
| 914 | |
---|
| 915 | # TAG: request_entities |
---|
| 916 | #Default: |
---|
| 917 | # request_entities off |
---|
| 918 | |
---|
| 919 | # TAG: high_response_time_warning (msec) |
---|
| 920 | #Default: |
---|
| 921 | # high_response_time_warning 0 |
---|
| 922 | |
---|
| 923 | # TAG: high_page_fault_warning |
---|
| 924 | #Default: |
---|
| 925 | # high_page_fault_warning 0 |
---|
| 926 | |
---|
| 927 | # TAG: high_memory_warning |
---|
| 928 | #Default: |
---|
| 929 | # high_memory_warning 0 |
---|
| 930 | |
---|
| 931 | # TAG: store_dir_select_algorithm |
---|
| 932 | #Default: |
---|
| 933 | # store_dir_select_algorithm least-load |
---|
| 934 | |
---|
| 935 | # TAG: forward_log |
---|
| 936 | #Default: |
---|
| 937 | # none |
---|
| 938 | |
---|
| 939 | # TAG: ie_refresh on|off |
---|
| 940 | #Default: |
---|
| 941 | # ie_refresh off |
---|
| 942 | |
---|
| 943 | # TAG: vary_ignore_expire on|off |
---|
| 944 | #Default: |
---|
| 945 | # vary_ignore_expire off |
---|
| 946 | |
---|
| 947 | # TAG: sleep_after_fork (microseconds) |
---|
| 948 | #Default: |
---|
| 949 | # sleep_after_fork 0 |
---|