Sign inSign up

numenor23/squid

By numenor23

•Updated about 1 year ago

Debian bullseye build of squid with basic auth support

Image
Networking
Security
0

973

numenor23/squid repository overview

⁠Built on debian bullseye, with added apache2-utils to enable basic auth.

⁠Auth file path is

/etc/squid/auth

⁠Post install from console add your user. Add your own squid.conf as well.

⁠You can create a password file using htpasswd:

htpasswd -c /etc/squid/auth/users squiduser

⁠use -c the first time to create the file, but remove when adding subsequent users

⁠Example squid.conf

#Basic auth
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/auth/users
auth_param basic realm Squid Proxy
acl authenticated proxy_auth REQUIRED
http_access allow authenticated

#Match IP's as sources
acl src-10.3.1.114-tools src 10.3.1.114
acl src-10.3.1.146-portainer src 10.3.1.146
acl src-10.0.0.0_8-dockerlans src 10.0.0.0/8

#Define destination domains/IPs
acl dst-ifconfig.co dstdomain ifconfig.co
acl dst-192.168.68.11-orange dst 192.168.68.11
acl dst-192.168.68.0_22-hostlan dst 192.168.68.0/22
acl dst-192.168.68.10-pihole dst 192.168.68.10

#Define ports
acl port-9001 myport 9001

#Allow access rules, note some authenticated, using the src, dst objects we defined above
http_access allow src-10.3.1.114-tools dst-192.168.68.10-pihole
http_access allow authenticated src-10.3.1.114-tools dst-192.168.68.11-orange port-9001
http_access allow authenticated src-10.3.1.146-portainer dst-192.168.68.11-orange port-9001
http_access deny src-10.0.0.0_8-dockerlans dst-192.168.68.0_22-hostlan
http_access allow authenticated src-10.0.0.0_8-dockerlans dst-ifconfig.co
http_access deny all

#Squid default port
http_port 3128

Tag summary

Content type

Image

Digest

sha256:228d14b8e…

Size

96.2 MB

Last updated

about 1 year ago

docker pull numenor23/squid