Selasa, Desember 02, 2014

Blok https dengan squid



#nano /etc/network/interfaces
            auto eth0
            iface eth0 inet static
                        address 192.168.20.100
                        netmask 255.255.255.0
                        gateway 192.168.20.1
                        network 192.168.20.0
            auto eth1
            iface eth1 inet static
                        address 192.168.100.1
                        netmask 255.255.255.192
                        network 192.168.100.0
#/etc/init.d/networking restart

pasang kabel dari server ke switch internet ping 192.168.20.1
#nano /etc/resolv.conf
            nameserver 192.168.20.1
            nameserver 8.8.8.8
#nano /etc/rc.local
            iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
            iptables -t nat -A PREROUTING -s 192.168.100.0/26 -p tcp --dport 80 -j REDIRECT --to-port 3128
            iptables -A INPUT -p tcp -s 192.168.100.0/26 --dport 443 -j DROP
#nano /etc/sysctl.conf
            hapus tanda pagar #net.ipv4.ip_fordward=1 menjadi (net.ipv4.ip_fordward=1) tanpa buka/tutup kurung
#apt-cdrom add
#apt-get -y install squid
#cd /etc/squid
#nano squid.conf
                        ctrl w http_port 3128
                                    http_port 3128 tambahkan transparent
                        ctrl w insert your
                                    acl ayub src 192.168.100.0/26
                                    http_access allow ayub
                        ctrl w acl connect
                                    acl blokirsitus url_regex "/etc/squid/blokirsitus.txt"
                                    http_access deny blokirsitus
                        ctrl w cache_mgr {hapus tanda pagar (#) pada cache_mgr}
                                    cache_mgr Ayub_wahyudin@smnkn1lelea.sch.id
                                    visible_hostname www.smkn1lelea.sch.id
   #nano blokirsitus.txt
                        http://www.google.com
                        https://mail.len.co.id
#/etc/init.d/squid restart
#reboot

0 komentar:

Posting Komentar

Ayub Wahyudin. Diberdayakan oleh Blogger.

Label