Доброго времени суток Господа!
Образовалась интересная проблема:
В логе squid3 постоянно висит ERROR: No forward-proxy ports configured.
И особо оно бы и не торкало, если бы не перестали работать expressionlist в guarde(тупо не создает .db) и url_regex в squid.
domainlist, urllist - работают исключительно.
iptables-save:
*nat
:PREROUTING ACCEPT [49896:3765587]
:INPUT ACCEPT [7563:452621]
:OUTPUT ACCEPT [6594:409673]
:POSTROUTING ACCEPT [6594:409673]
-A PREROUTING ! -d 10.0.0.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j DNAT --to-destination 10.0.0.1:3128
-A POSTROUTING -s 10.0.0.0/24 -o eth0 -j MASQUERADE
COMMIT
# Completed on Fri May 15 10:19:06 2015
# Generated by iptables-save v1.4.21 on Fri May 15 10:19:06 2015
*filter
:INPUT ACCEPT [220447:221120273]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [296775:233729173]
-A INPUT -i lo -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j REJECT --reject-with icmp-port-unreachable
squid.conf
acl localnet src 10.0.0.0/24 # RFC1918 possible internal network
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
acl special_client src 10.0.0.2
acl special_url url_regex ^http://www.vk.com ^http://vk.com ^http://www.vkontakte.ru ^http://vkontakte.ru
http_access deny special_client special_url
http_access allow localnet
always_direct allow all
http_port 10.0.0.1:3128 intercept
http_port 127.0.0.1:3129 intercept
cache_mem 2 GB
maximum_object_size_in_memory 4 MB
cache_dir ufs /var/spool/squid3 4096 36 256
access_log /var/log/squid3/access.log squid
logfile_rotate 31
coredump_dir /var/spool/squid3
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320
cache_effective_user proxy
cache deny all
error_directory /usr/share/squid3/errors/Russian-1251
dns_nameservers 192.168.1.1
memory_pools on
memory_pools_limit 1024 MB
redirector_bypass on
url_rewrite_program /usr/bin/squidGuard -c /etc/squidguard/squidGuard.conf
url_rewrite_children 7
Всю голову уже сломал и что только не пробовал! SOS!!!