Re: [squid-users] Limitting particular group to specific sites (not working perfectly)

From: Amos Jeffries <squid3_at_treenet.co.nz>
Date: Thu, 26 Mar 2009 00:16:45 +1300

Truth Seeker wrote:
>
> In my squid.conf, i am trying to grant access ONLY to a set of predefined sites for a group of users (those who are member of limitedsurfers). They are not allowed to access any other thing from the Internet. The following is the acl which i created
>
> All my other rules are working perfectly...
>
> Squid Version: 2.6 Stable

Sigh. Thanks a lot for trying, but ... there are 21 different official
"2.6 stable" and quite a lot of semi-official patched "2.6 stable". All
of them obsolete.

Which one do you mean?

> OS: CentOS 5.2
>
> First from authentication rule;
> auth_param basic program /usr/lib/squid/pam_auth
> external_acl_type unix_group %LOGIN /usr/lib/squid/squid_unix_group
> acl limited_surfers_acl external unix_group limitedsurfers
>
>
> Then the particular acl;
> acl limited_sites dstdomain "/etc/squid/include-files/limited_site.squid"

> http_access allow limited_surfers_acl limited_sites

requires password THEN checks where user is going...

> http_access deny limited_surfers_acl

requires password and denies on success. !?!

do you have a '!' on the IP address line you says works perfectly?

> deny_info ERR_LIMITED_SURFERS limited_surfers_acl
>
>
> Now the situation is;
> It is perfectly granting access to the sited listed in the limited_site.squid file
>
> But when i try to access some other site, it will ask the username/password for 3 times (even when we give the correct username/pass) then only it is denying the request.
>
> Why it is happening so?
>
> I have almost the same kind of rule like this for a particular list of IP's instead of users. That is working perfect for allowing and denying.
>
> Can anybody help me in this case...
>
> Thanks in Advance...
>

Amos

-- 
Please be using
   Current Stable Squid 2.7.STABLE6 or 3.0.STABLE13
   Current Beta Squid 3.1.0.6
Received on Wed Mar 25 2009 - 11:16:51 MDT

This archive was generated by hypermail 2.2.0 : Wed Mar 25 2009 - 12:00:03 MDT