Re: [squid-users] URL filtering on HTTPS (transparently)

From: Chris Robertson <crobertson_at_gci.net>
Date: Wed, 13 Aug 2008 13:45:08 -0800

Niladri Mukherjee wrote:
> We are doing the same by the following.
>
> 1. At squid.conf :
> acl Banned_URLs url_regex -i "/etc/squid/banned_urls.txt"
>

For what it's worth you could change this to a dstdomain ACL, like...

acl BannedURLs dstdomain "/etc/squid/banned_urls.txt

>
> http_access allow FullTime_DnlUpl !Banned_URLs
>
>
> 2. At The file /etc/squid/banned_urls.txt :
> www.xxxxx.com:443
>
>

The file should then have a content more along the lines of...

www.xxxxx.com

...or if you want to match all of xxxxx.com you could use...

.xxxxx.com

Why would you make this change? Regular expression matching is
computationally expensive and should be avoided when possible.

> Thankx,
>
> Niladri Mukherjee
>
> IT Deptt.,
> M.N.Dastur & Company (P) Ltd., 3rd Floor,
> Kolkata, West Bengal.
> Ph: 91 33 22250500/5420, Ext: 580
> Fax: 91 33 22251422

Chris
Received on Wed Aug 13 2008 - 21:45:15 MDT

This archive was generated by hypermail 2.2.0 : Thu Aug 14 2008 - 12:00:03 MDT