Re: [squid-users] ACL compisition

From: Paolo Supino <paolo.supino_at_gmail.com>
Date: Fri, 17 Feb 2012 14:34:17 +0100

hi

  Yes I have a few http_access rules in my squid.conf (7 to be
precise), but I can't fold this ACL into the other ACLs I have (I
would have done it if I could).

TIA
Paolo

On Fri, Feb 17, 2012 at 9:55 AM, Matus UHLAR - fantomas
<uhlar_at_fantomas.sk> wrote:
> On 16.02.12 15:51, Paolo Supino wrote:
>>
>> I have the following scenario: I have a subnet that needs to get out
>> on the internet to 2 different subnets. To subnet1 it needs to be able
>> to access only in HTTP while to subnet2 it needs to be able to access
>> only in HTTPS. Is it possible to do the follwoing:
>>
>> acl source_subnet src 192.168.100.0/255.255.255.0
>> acl destination_subnet1 dst 172.16.0.0/255.255.0.0
>> acl destination_subnet2 dst 172.31.0.0/255.255.0.0
>> acl HTTP_PORT port 80
>> acl SSL_PORT port 443
>>
>> http_access allow source_subnet destination_subnet1 HTTP_PORT
>> http_access allow source_subnet destination_subnet2 SSL_PORT
>
>
> do you have any other http_access directives in the config?
>
> --
> Matus UHLAR - fantomas, uhlar@fantomas.sk ; http://www.fantomas.sk/
> Warning: I wish NOT to receive e-mail advertising to this address.
> Varovanie: na tuto adresu chcem NEDOSTAVAT akukolvek reklamnu postu.
> WinError #99999: Out of error messages.
Received on Fri Feb 17 2012 - 13:34:25 MST

This archive was generated by hypermail 2.2.0 : Sun Feb 19 2012 - 12:00:04 MST