Authored by chunhua.zhang

Add new file

#
# Recommended minimum configuration:
#
# Example rule allowing access from your local networks.
# Adapt to list your (internal) IP networks from where browsing
# should be allowed
acl localnet src 10.0.0.0/8 # RFC1918 possible internal network
acl localnet src 172.16.0.0/12 # RFC1918 possible internal network
acl localnet src 192.168.0.0/16 # RFC1918 possible internal network
acl localnet src fc00::/7 # RFC 4193 local private network range
acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
acl ip1 src 218.94.75.50
acl ip2 src 218.94.75.58
acl ip3 src 123.56.138.21
acl ip4 src 123.57.153.187
acl ip5 src 123.56.238.71
acl ip6 src 54.222.135.182
acl ip7 src 123.206.51.23
acl ip10 src 54.222.146.59
acl ip11 src 54.222.0.0/16
acl manager proto cache_object
#redirect_program /Data/local/squid-3.5.19/bin/proxy.py
#redirect_children 10
http_access allow ip1
http_access allow ip2
http_access allow ip3
http_access allow ip4
http_access allow ip5
http_access allow ip6
http_access allow ip7
http_access allow ip10
http_access allow ip11
cache_replacement_policy lru
cache_mem 1024 MB
cache_effective_user nobody
cache_effective_group nobody
maximum_object_size 4096 KB
maximum_object_size_in_memory 512 KB
reply_body_max_size 5116 KB
minimum_object_size 1 bytes
client_persistent_connections on
server_persistent_connections on
persistent_request_timeout 60 seconds
request_timeout 240 seconds
client_lifetime 240 seconds
connect_timeout 240 seconds
read_timeout 240 seconds
pconn_timeout 60 seconds
refresh_pattern -i \.gif$ 1440 90% 129600 reload-into-ims
refresh_pattern -i \.swf$ 1440 90% 129600 reload-into-ims
refresh_pattern -i \.jpg$ 1440 90% 129600 reload-into-ims
refresh_pattern -i \.png$ 1440 90% 129600 reload-into-ims
refresh_pattern -i \.bmp$ 1440 90% 129600 reload-into-ims
refresh_pattern -i \.js$ 120 90% 600 reload-into-ims
refresh_pattern -i \.css$ 120 90% 600 reload-into-ims
#
# Recommended minimum Access Permission configuration:
#
# Deny requests to certain unsafe ports
http_access deny !Safe_ports
# Deny CONNECT to other than secure SSL ports
http_access deny CONNECT !SSL_ports
# Only allow cachemgr access from localhost
#http_access allow localhost manager
#http_access deny manager
http_access allow manager
# We strongly recommend the following be uncommented to protect innocent
# web applications running on the proxy server who think the only
# one who can access services on "localhost" is a local user
#http_access deny to_localhost
#
# INSERT YOUR OWN RULE(S) HERE TO ALLOW ACCESS FROM YOUR CLIENTS
#
# Example rule allowing access from your local networks.
# Adapt localnet in the ACL section to list your (internal) IP networks
# from where browsing should be allowed
http_access allow localnet
http_access allow localhost
# And finally deny all other access to this proxy
http_access deny all
#http_access allow all
# Squid normally listens to port 3128
http_port 8091
# Uncomment and adjust the following to add a disk cache directory.
cache_dir ufs /Data/local/squid-3.5.19/var/cache/squid 4096 10 10
# Leave coredumps in the first cache dir
coredump_dir /Data/local/squid-3.5.19/var/cache/squid
#
# Add any of your own refresh_pattern entries above these.
#
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern . 0 20% 4320
... ...