Сделал
/etc/nat
iptables -t nat -A PREROUTING -i eth1 ! -d 192.168.1.0/24 -p tcp -m multiport --dport 80,8080 -j REDIRECT --to-port 3128
поменял /etc/squid3/squid.conf
...
acl adminpc src 192.168.1.103
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 443 # https
http_access deny !Safe_ports
http_access allow adminpc
http_access deny all
...
https такое чувство что работает без лагов. Даже никаких тормозов не заметил.
sudo cat /etc/dnsmasq.conf | grep dhcp-option
# any dhcp-options. If you use Windows clients and Samba, there
#dhcp-option=3,1.2.3.4
#dhcp-option=option:router,1.2.3.4
#dhcp-option=3
#dhcp-option=option:ntp-server,192.168.0.4,10.10.0.5
#dhcp-option=42,0.0.0.0
#dhcp-option=40,welly
#dhcp-option=23,50
#dhcp-option=27,1
#dhcp-option=128,e4:45:74:68:00:00
#dhcp-option=129,NIC=eepro100
#dhcp-option = tag:red, option:ntp-server, 192.168.1.1
#dhcp-option=19,0 # option ip-forwarding off
#dhcp-option=44,0.0.0.0 # set netbios-over-TCP/IP nameserver(s) aka WINS server(s)
#dhcp-option=45,0.0.0.0 # netbios datagram distribution server
#dhcp-option=46,8 # netbios node type
#dhcp-option=option:domain-search,eng.apple.com,marketing.apple.com
#dhcp-option=121,192.168.1.0/24,1.2.3.4,10.0.0.0/8,5.6.7.8
#dhcp-option=vendor:PXEClient,1,0.0.0.0
#dhcp-option=vendor:MSFT,2,1i
#dhcp-option=vendor:Etherboot,60,"Etherboot"
# to use dhcp-option-force here.
#dhcp-option-force=208,f1:00:74:7e
#dhcp-option-force=209,configs/common
#dhcp-option-force=210,/tftpboot/pxelinux/files/
#dhcp-option-force=211,30i
#dhcp-option=encap:175, 1, 5b # priority code
#dhcp-option=encap:175, 176, 1b # no-proxydhcp
#dhcp-option=encap:175, 177, string # bus-id
#dhcp-option=encap:175, 189, 1b # BIOS drive code
#dhcp-option=encap:175, 190, user # iSCSI username
#dhcp-option=encap:175, 191, pass # iSCSI password
iptables-save
# Generated by iptables-save v1.4.12 on Tue Feb 18 15:42:53 2014
*nat
:PREROUTING ACCEPT [480:36097]
:INPUT ACCEPT [180:11028]
:OUTPUT ACCEPT [68:4229]
:POSTROUTING ACCEPT [68:4229]
-A PREROUTING ! -d 192.168.1.0/24 -i eth1 -p tcp -m multiport --dports 80,8080 -j REDIRECT --to-ports 3128
-A POSTROUTING -s 192.168.1.0/24 -o eth0 -j MASQUERADE
COMMIT
# Completed on Tue Feb 18 15:42:53 2014
# Generated by iptables-save v1.4.12 on Tue Feb 18 15:42:53 2014
*filter
:INPUT ACCEPT [37268:39651234]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [40394:39695292]
-A INPUT -i lo -j ACCEPT
-A INPUT -s 192.168.1.0/24 -i eth1 -p tcp -m tcp --dport 80 -j ACCEPT
-A INPUT -s 192.168.1.0/24 -i eth1 -p tcp -m tcp --dport 22 -j ACCEPT
-A FORWARD -i eth1 -o eth0 -j ACCEPT
-A FORWARD -i eth0 -m state --state RELATED,ESTABLISHED -j ACCEPT
-A FORWARD -i eth0 -o eth1 -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -d 192.168.1.0/24 -o eth1 -p tcp -m tcp --sport 80 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
-A OUTPUT -d 192.168.1.0/24 -o eth1 -p tcp -m tcp --sport 22 -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
COMMIT
# Completed on Tue Feb 18 15:42:53 2014
Попробовал еще на 5ти сайтах https все отлично работает, а http затуп