ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

pfSense+Squid ืขื ืกื™ื ื•ืŸ https + ื›ื ื™ืกื” ื™ื—ื™ื“ื” (SSO) ืขื ืกื™ื ื•ืŸ ืงื‘ื•ืฆืช Active Directory

ืจืงืข ืงืฆืจ

ื”ื—ื‘ืจื” ื ื“ืจืฉื” ืœื”ื˜ืžื™ืข ืฉืจืช ืคืจื•ืงืกื™ ืขื ื™ื›ื•ืœืช ืœืกื ืŸ ื’ื™ืฉื” ืœืืชืจื™ื (ื›ื•ืœืœ https) ืœืคื™ ืงื‘ื•ืฆื•ืช ืž-AD, ื›ืš ืฉื”ืžืฉืชืžืฉื™ื ืœื ื™ื›ื ื™ืกื• ืกื™ืกืžืื•ืช ื ื•ืกืคื•ืช, ื•ื ื™ืชืŸ ื™ื”ื™ื” ืœื ื”ืœ ืื•ืชื ืžืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜. ืืคืœื™ืงืฆื™ื” ื˜ื•ื‘ื”, ืœื?

ื”ืชืฉื•ื‘ื” ื”ื ื›ื•ื ื” ืชื”ื™ื” ืœืงื ื•ืช ืคืชืจื•ื ื•ืช ื›ืžื• Kerio Control ืื• UserGate, ืื‘ืœ ื›ืžื• ืชืžื™ื“ ืื™ืŸ ื›ืกืฃ, ืื‘ืœ ื™ืฉ ืฆื•ืจืš.

ื–ื” ื”ืžืงื•ื ืฉื‘ื• ื”ื“ื™ื•ื ื•ืŸ ื”ื™ืฉืŸ ื•ื”ื˜ื•ื‘ ื‘ื ืœื”ืฆื™ืœ, ืื‘ืœ ืฉื•ื‘ - ืื™ืคื” ืื ื™ ื™ื›ื•ืœ ืœื”ืฉื™ื’ ืžืžืฉืง ืื™ื ื˜ืจื ื˜? SAMS2? ืžื™ื•ืฉืŸ ืžื‘ื—ื™ื ื” ืžื•ืกืจื™ืช. ื–ื” ื”ืžืงื•ื ืฉื‘ื• pfSense ื‘ืื” ืœื”ืฆื™ืœ.

ืชื™ืื•ืจ

ืžืืžืจ ื–ื” ื™ืชืืจ ื›ื™ืฆื“ ืœื”ื’ื“ื™ืจ ืืช ืฉืจืช ื”-proxy Squid.
Kerberos ื™ืฉืžืฉ ืœื”ืจืฉืืช ืžืฉืชืžืฉื™ื.
SquidGuard ื™ืฉืžืฉ ืœืกื™ื ื•ืŸ ืœืคื™ ืงื‘ื•ืฆื•ืช ื“ื•ืžื™ื™ื ื™ื.

ืžืขืจื›ื•ืช ื ื™ื˜ื•ืจ Lightsquid, sqstat ื•-pfSense ืคื ื™ืžื™ื•ืช ื™ืฉืžืฉื• ืœื ื™ื˜ื•ืจ.
ื–ื” ื’ื ื™ืคืชื•ืจ ื‘ืขื™ื” ื ืคื•ืฆื” ื”ืงืฉื•ืจื” ื‘ื”ื›ื ืกืช ื˜ื›ื ื•ืœื•ื’ื™ื™ืช ื›ื ื™ืกื” ื™ื—ื™ื“ื” (SSO), ื›ืœื•ืžืจ ื™ื™ืฉื•ืžื™ื ืฉืžื ืกื™ื ืœื’ืœื•ืฉ ื‘ืื™ื ื˜ืจื ื˜ ืžืชื—ืช ืœื—ืฉื‘ื•ืŸ ื”ืžืฆืคืŸ ืขื ื—ืฉื‘ื•ืŸ ื”ืžืขืจื›ืช ืฉืœื”ื.

ืžืชื›ื•ื ื ื™ื ืœื”ืชืงื ืช ืกืงื•ื•ื™ื“

pfSense ื™ื™ืœืงื— ื›ื‘ืกื™ืก, ื”ื•ืจืื•ืช ื”ืชืงื ื”.

ื‘ืชื•ื›ื• ืื ื• ืžืืจื’ื ื™ื ืื™ืžื•ืช ืขืœ ื—ื•ืžืช ื”ืืฉ ืขืฆืžื” ื‘ืืžืฆืขื•ืช ื—ืฉื‘ื•ื ื•ืช ื“ื•ืžื™ื™ืŸ. ื”ื•ืจืื•ืช.

ื—ืฉื•ื‘ ืžืื•ื“!

ืœืคื ื™ ืฉืชืชื—ื™ืœ ืœื”ืชืงื™ืŸ ืืช Squid, ืขืœื™ืš ืœื”ื’ื“ื™ืจ ืืช ืฉืจืช ื”-DNS ื‘-pfsense, ืœืขืฉื•ืช ืขื‘ื•ืจื• ืจืฉื•ืžืช A ื•ืจืฉื•ืžืช PTR ื‘ืฉืจืช ื”-DNS ืฉืœื ื•, ื•ืœื”ื’ื“ื™ืจ ืืช NTP ื›ืš ืฉื”ืฉืขื” ืœื ืชื”ื™ื” ืฉื•ื ื” ืžื”ืฉืขื” ื‘ื‘ืงืจ ื”ืชื—ื•ื.

ื•ื‘ืจืฉืช ืฉืœืš, ืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœืžืžืฉืง ื”-WAN ืฉืœ pfSense ืœืขื‘ื•ืจ ืœืื™ื ื˜ืจื ื˜, ื•ืœืžืฉืชืžืฉื™ื ื‘ืจืฉืช ื”ืžืงื•ืžื™ืช ืœื”ืชื—ื‘ืจ ืœืžืžืฉืง ื”-LAN, ื›ื•ืœืœ ื‘ื™ืฆื™ืื•ืช 7445 ื•-3128 (ื‘ืžืงืจื” ืฉืœื™ 8080).

ื”ื›ืœ ืžื•ื›ืŸ? ื”ืื ื—ื™ื‘ื•ืจ LDAP ื ื•ืฆืจ ืขื ื”ื“ื•ืžื™ื™ืŸ ืœื”ืจืฉืื” ื‘-pfSense ื•ื”ืฉืขื” ืžืกื•ื ื›ืจื ืช? ื’ื“ื•ืœ. ื–ื” ื”ื–ืžืŸ ืœื”ืชื—ื™ืœ ืืช ื”ืชื”ืœื™ืš ื”ืขื™ืงืจื™.

ื”ืชืงื ื” ื•ื”ื’ื“ืจื” ืžืจืืฉ

Squid, SquidGuard ื•-LightSquid ื™ื•ืชืงื ื• ืžืžื ื”ืœ ื”ื—ื‘ื™ืœื•ืช ืฉืœ pfSense ื‘ืงื˜ืข "ืžื ื”ืœ ืžืขืจื›ืช / ื—ื‘ื™ืœื•ืช".

ืœืื—ืจ ื”ืชืงื ื” ืžื•ืฆืœื—ืช, ืขื‘ื•ืจ ืืœ "ืฉื™ืจื•ืชื™ื / ืฉืจืช ืคืจื•ืงืกื™ Squid /" ื•ืงื•ื“ื ื›ืœ, ื‘ืœืฉื•ื ื™ืช ืžื˜ืžื•ืŸ ืžืงื•ืžื™, ืชื’ื“ื™ืจ ืฉืžื™ืจื” ื‘ืžื˜ืžื•ืŸ, ื”ื’ื“ืจืชื™ ื”ื›ืœ ืœ-0, ื›ื™ ืื ื™ ืœื ืจื•ืื” ื˜ืขื ื‘ืื—ืกื•ืŸ ืืชืจื™ื ื‘ืžื˜ืžื•ืŸ, ื“ืคื“ืคื ื™ื ืขื•ืฉื™ื ืขื‘ื•ื“ื” ืžืฆื•ื™ื ืช ืขื ื–ื”. ืœืื—ืจ ื”ื”ื’ื“ืจื”, ืœื—ืฅ ืขืœ ื›ืคืชื•ืจ "ืฉืžื•ืจ" ื‘ืชื—ืชื™ืช ื”ืžืกืš ื•ื–ื” ื™ื™ืชืŸ ืœื ื• ืืช ื”ื”ื–ื“ืžื ื•ืช ืœื‘ืฆืข ื”ื’ื“ืจื•ืช ืคืจื•ืงืกื™ ื‘ืกื™ืกื™ื•ืช.

ื”ื”ื’ื“ืจื•ืช ื”ืขื™ืงืจื™ื•ืช ื”ืŸ ื›ื“ืœืงืžืŸ:

ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

ื™ืฆื™ืืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื™ื 3128, ืื‘ืœ ืื ื™ ืžืขื“ื™ืฃ ืœื”ืฉืชืžืฉ ื‘-8080.

ื”ืคืจืžื˜ืจื™ื ืฉื ื‘ื—ืจื• ื‘ืœืฉื•ื ื™ืช ืžืžืฉืง ืคืจื•ืงืกื™ ืงื•ื‘ืขื™ื ื‘ืื™ืœื• ืžืžืฉืงื™ื ืฉืจืช ื”-proxy ืฉืœื ื• ื™ืงืฉื™ื‘. ืžื›ื™ื•ื•ืŸ ืฉื—ื•ืžืช ืืฉ ื–ื• ื‘ื ื•ื™ื” ื‘ืฆื•ืจื” ื›ื–ื• ืฉื”ื™ื ื ืจืื™ืช ื‘ืื™ื ื˜ืจื ื˜ ื›ืžืžืฉืง WAN, ืœืžืจื•ืช ืฉ-LAN ื•-WAN ื™ื›ื•ืœื™ื ืœื”ื™ื•ืช ื‘ืื•ืชื” ืจืฉืช ืžืฉื ื” ืžืงื•ืžื™ืช, ืื ื™ ืžืžืœื™ืฅ ืœื”ืฉืชืžืฉ ื‘-LAN ืขื‘ื•ืจ ื”-proxy.

ื™ืฉ ืฆื•ืจืš ื‘-Loopback ื›ื“ื™ ืฉ-sqstat ื™ืคืขืœ.

ืœืžื˜ื” ืชืžืฆืื• ืืช ื”ื’ื“ืจื•ืช ื”-proxy ื”ืฉืงื•ืฃ (ืฉืงื•ืฃ) ื•ื›ืŸ ืžืกื ืŸ SSL, ืื‘ืœ ืื ื—ื ื• ืœื ืฆืจื™ื›ื™ื ืื•ืชื, ื”-proxy ืฉืœื ื• ืœื ื™ื”ื™ื” ืฉืงื•ืฃ, ื•ืœืกื™ื ื•ืŸ https ืœื ื ื—ืœื™ืฃ ืืช ื”ืื™ืฉื•ืจ (ื™ืฉ ืœื ื• ืชื–ืจื™ื ืžืกืžื›ื™ื, ื‘ื ืง ืœืงื•ื—ื•ืช ื•ื›ื•'), ื‘ื•ืื• ื ืกืชื›ืœ ืจืง ืขืœ ืœื—ื™ืฆืช ื”ื™ื“.

ื‘ืฉืœื‘ ื–ื”, ืขืœื™ื ื• ืœืขื‘ื•ืจ ืœื‘ืงืจ ื”ืชื—ื•ื ืฉืœื ื•, ืœื™ืฆื•ืจ ื‘ื• ื—ืฉื‘ื•ืŸ ืื™ืžื•ืช (ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื’ื ื‘ื–ื” ืฉื”ื•ื’ื“ืจ ืœืื™ืžื•ืช ื‘-pfSense ืขืฆืžื•). ื”ื ื” ื’ื•ืจื ื—ืฉื•ื‘ ืžืื•ื“ - ืื ืืชื” ืžืชื›ื•ื•ืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืฆืคื ื” AES128 ืื• AES256 - ืกืžืŸ ืืช ื”ืชื™ื‘ื•ืช ื”ืžืชืื™ืžื•ืช ื‘ื”ื’ื“ืจื•ืช ื”ื—ืฉื‘ื•ืŸ ืฉืœืš.

ืื ื”ื“ื•ืžื™ื™ืŸ ืฉืœืš ื”ื•ื ื™ืขืจ ืžื•ืจื›ื‘ ืžืื•ื“ ืขื ืžืกืคืจ ืจื‘ ืฉืœ ืกืคืจื™ื•ืช ืื• ืฉื”ื“ื•ืžื™ื™ืŸ ืฉืœืš ื”ื•ื .local, ืื– ื–ื” ืืคืฉืจื™, ืื‘ืœ ืœื ื‘ื˜ื•ื—, ืฉืชืฆื˜ืจืš ืœื”ืฉืชืžืฉ ื‘ืกื™ืกืžื” ืคืฉื•ื˜ื” ืœื—ืฉื‘ื•ืŸ ื–ื”, ื”ื‘ืื’ ื™ื“ื•ืข, ืื‘ืœ ื–ื” ืื•ืœื™ ืคืฉื•ื˜ ืœื ื™ืขื‘ื•ื“ ืขื ืกื™ืกืžื” ืžื•ืจื›ื‘ืช, ืืชื” ืฆืจื™ืš ืœื‘ื“ื•ืง ืžืงืจื” ืžืกื•ื™ื.

ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

ืœืื—ืจ ืžื›ืŸ, ืื ื• ื™ื•ืฆืจื™ื ืงื•ื‘ืฅ ืžืคืชื— ืขื‘ื•ืจ kerberos, ืคื•ืชื—ื™ื ืฉื•ืจืช ืคืงื•ื“ื” ืขื ื–ื›ื•ื™ื•ืช ืžื ื”ืœ ื‘ื‘ืงืจ ื”ืชื—ื•ื ื•ืžื–ื™ืŸ:

# ktpass -princ HTTP/[email protected] -mapuser pfsense -pass 3EYldza1sR -crypto {DES-CBC-CRC|DES-CBC-MD5|RC4-HMAC-NT|AES256-SHA1|AES128-SHA1|All} -ptype KRB5_NT_PRINCIPAL -out C:keytabsPROXY.keytab

ื”ื™ื›ืŸ ืฉืื ื• ืžืฆื™ื™ื ื™ื ืืช ื”-FQDN pfSense ืฉืœื ื•, ื”ืงืคื™ื“ื• ืœื›ื‘ื“ ืืช ื”ืžืงืจื”, ื”ื–ื™ื ื• ืืช ื—ืฉื‘ื•ืŸ ื”ื“ื•ืžื™ื™ืŸ ืฉืœื ื• ื•ื”ืกื™ืกืžื” ืฉืœื• ื‘ืคืจืžื˜ืจ mapuser, ื•ื‘ืงืจื™ืคื˜ื• ืื ื• ื‘ื•ื—ืจื™ื ื‘ืฉื™ื˜ืช ื”ื”ืฆืคื ื”, ื”ืฉืชืžืฉืชื™ ื‘-rc4 ืœืขื‘ื•ื“ื” ื•ื‘ืฉื“ื” -out ื ื‘ื—ืจ ื”ื™ื›ืŸ ืื ื• ื™ืฉืœื— ืืช ืงื•ื‘ืฅ ื”ืžืคืชื— ื”ืžื•ื’ืžืจ ืฉืœื ื•.
ืœืื—ืจ ื™ืฆื™ืจืช ืงื•ื‘ืฅ ื”ืžืคืชื— ื‘ื”ืฆืœื—ื”, ื ืฉืœื— ืื•ืชื• ืœ-pfSense ืฉืœื ื•, ื”ืฉืชืžืฉืชื™ ื‘-Far ื‘ืฉื‘ื™ืœ ื–ื”, ืื‘ืœ ืืชื” ื™ื›ื•ืœ ื’ื ืœืขืฉื•ืช ื–ืืช ื’ื ืขื ืคืงื•ื“ื•ืช ื•ื’ื ืขื ืžืจืง ืื• ื“ืจืš ืžืžืฉืง ื”ืื™ื ื˜ืจื ื˜ ืฉืœ pfSense ื‘ืกืขื™ืฃ "ืฉื•ืจืช ืคืงื•ื“ื•ืช ืื‘ื—ื•ืŸ".

ื›ืขืช ื ื•ื›ืœ ืœืขืจื•ืš/ืœื™ืฆื•ืจ /etc/krb5.conf

ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

ื›ืืฉืจ /etc/krb5.keytab ื”ื•ื ืงื•ื‘ืฅ ื”ืžืคืชื— ืฉื™ืฆืจื ื•.

ื”ืงืคื™ื“ื• ืœื‘ื“ื•ืง ืืช ืคืขื•ืœืช ื”-kerberos ื‘ืืžืฆืขื•ืช kinit, ืื ื–ื” ืœื ืขื•ื‘ื“, ืื™ืŸ ื˜ืขื ืœื”ืžืฉื™ืš ืœืงืจื•ื.

ื”ื’ื“ืจืช ืื™ืžื•ืช ื“ื™ื•ื ื•ืŸ ื•ืจืฉื™ืžืช ื’ื™ืฉื” ืœืœื ืื™ืžื•ืช

ืœืื—ืจ ืฉื”ื’ื“ืจื ื• ืืช ื”-kerberos ื‘ื”ืฆืœื—ื”, ื ืฆืžื™ื“ ืื•ืชื• ืœื“ื™ื•ื ื•ืŸ ืฉืœื ื•.

ืœืฉื ื›ืš, ืขื‘ื•ืจ ืืœ ServicesSquid Proxy Server ื•ื‘ื”ื’ื“ืจื•ืช ื”ืจืืฉื™ื•ืช ืจื“ื• ืขื“ ืœืžื˜ื” ืžืื•ื“, ืฉื ื ืžืฆื ืืช ื”ื›ืคืชื•ืจ "ื”ื’ื“ืจื•ืช ืžืชืงื“ืžื•ืช".

ื‘ืฉื“ื” ืืคืฉืจื•ื™ื•ืช ืžื•ืชืืžื•ืช ืื™ืฉื™ืช (ืœืคื ื™ ืื™ืžื•ืช), ื”ื–ืŸ:

#ะฅะตะปะฟะตั€ั‹
auth_param negotiate program /usr/local/libexec/squid/negotiate_kerberos_auth -s GSS_C_NO_NAME -k /usr/local/etc/squid/squid.keytab -t none
auth_param negotiate children 1000
auth_param negotiate keep_alive on
#ะกะฟะธัะบะธ ะดะพัั‚ัƒะฟะฐ
acl auth proxy_auth REQUIRED
acl nonauth dstdomain "/etc/squid/nonauth.txt" 
#ะ ะฐะทั€ะตัˆะตะฝะธั 
http_access allow nonauth 
http_access deny !auth
http_access allow auth

ืื™ืคื” auth_param negotiate program /usr/local/libexec/squid/negotiate_kerberos_auth - ื‘ื•ื—ืจ ืืช ืขื•ื–ืจ ื”ืื™ืžื•ืช kerberos ืฉืื ื• ืฆืจื™ื›ื™ื.

ืžืคืชื— -s ืขื ืžืฉืžืขื•ืช GSS_C_NO_NAME - ืžื’ื“ื™ืจ ืืช ื”ืฉื™ืžื•ืฉ ื‘ื›ืœ ื—ืฉื‘ื•ืŸ ืžืงื•ื‘ืฅ ื”ืžืคืชื—.

ืžืคืชื— -k ืขื ืžืฉืžืขื•ืช /usr/local/etc/squid/squid.keytab - ืงื•ื‘ืข ืœื”ืฉืชืžืฉ ื‘ืงื•ื‘ืฅ keytab ื”ืกืคืฆื™ืคื™ ื”ื–ื”. ื‘ืžืงืจื” ืฉืœื™, ื–ื” ืื•ืชื• ืงื•ื‘ืฅ keytab ืฉื™ืฆืจื ื•, ืื•ืชื• ื”ืขืชืงืชื™ ืœืกืคืจื™ื™ืช /usr/local/etc/squid/ ื•ืฉื™ื ื™ืชื™ ืœื•, ื›ื™ ื”ื“ื™ื•ื ื•ืŸ ืœื ืจืฆื” ืœื”ื™ื•ืช ื—ื‘ืจ ืขื ื”ืกืคืจื™ื™ื” ื”ื–ื•, ื›ื ืจืื” ืฉืœื ื”ื™ื• ืžืกืคื™ืง ื–ื›ื•ื™ื•ืช.

ืžืคืชื— -t ืขื ืžืฉืžืขื•ืช - ืœื ืืฃ ืื—ื“ - ืžืฉื‘ื™ืช ื‘ืงืฉื•ืช ืžื—ื–ื•ืจื™ื•ืช ืœื‘ืงืจ ื”ืชื—ื•ื, ืžื” ืฉืžืคื—ื™ืช ืžืื•ื“ ืืช ื”ืขื•ืžืก ืขืœื™ื• ืื ื™ืฉ ืœืš ื™ื•ืชืจ ืž-50 ืžืฉืชืžืฉื™ื.
ืœืžืฉืš ื”ื‘ื“ื™ืงื”, ื ื™ืชืŸ ื’ื ืœื”ื•ืกื™ืฃ ืืช ืžืงืฉ -d - ื›ืœื•ืžืจ ืื‘ื—ื•ืŸ, ื™ื•ืžื ื™ื ื ื•ืกืคื™ื ื™ื•ืฆื’ื•.
auth_param negotiate children 1000 - ืงื•ื‘ืข ื›ืžื” ืชื”ืœื™ื›ื™ ื”ืจืฉืื” ื‘ื• ื–ืžื ื™ืช ื ื™ืชืŸ ืœื”ืคืขื™ืœ
auth_param negotiate keep_alive on - ืื™ื ื• ืžืืคืฉืจ ืœื ืชืง ืืช ื”ืงืฉืจ ื‘ืžื”ืœืš ื”ืกืงืจื™ื ืฉืœ ืฉืจืฉืจืช ื”ื”ืจืฉืื•ืช
acl auth proxy_auth ื ื“ืจืฉ - ื™ื•ืฆืจ ื•ื“ื•ืจืฉ ืจืฉื™ืžืช ื‘ืงืจืช ื’ื™ืฉื” ื”ื›ื•ืœืœืช ืžืฉืชืžืฉื™ื ืฉืขื‘ืจื• ื”ืจืฉืื”
acl nonauth dstdomain "/etc/squid/nonauth.txt" - ืื ื• ืžื•ื“ื™ืขื™ื ืœื“ื™ื•ื ื•ืŸ ืขืœ ืจืฉื™ืžืช ื”ื’ื™ืฉื” nonauth, ื”ืžื›ื™ืœื” ืชื—ื•ืžื™ ื™ืขื“, ืฉืืœื™ื”ื ืชืžื™ื“ ืชืชืืคืฉืจ ื’ื™ืฉื” ืœื›ื•ืœื. ืื ื—ื ื• ื™ื•ืฆืจื™ื ืืช ื”ืงื•ื‘ืฅ ืขืฆืžื•, ื•ื‘ืชื•ื›ื• ืื ื—ื ื• ืžื›ื ื™ืกื™ื ื“ื•ืžื™ื™ื ื™ื ื‘ืคื•ืจืžื˜

.whatsapp.com
.whatsapp.net

ื•ื•ืื˜ืกืืค ืœื ืœืฉื•ื•ื ืžืฉืžืฉ ื›ื“ื•ื’ืžื” - ื–ื” ืžืื•ื“ ื‘ืจืจืŸ ืœื’ื‘ื™ ื”-proxy ืขื ืื™ืžื•ืช ื•ืœื ื™ืขื‘ื•ื“ ืื ื–ื” ืœื ืžื•ืชืจ ืœืคื ื™ ื”ืื™ืžื•ืช.
http_access ืืคืฉืจ nonauth - ืืคืฉืจ ื’ื™ืฉื” ืœืจืฉื™ืžื” ื–ื• ืœื›ื•ืœื
http_access ื“ื—ื™ื™ืช !auth - ืื ื• ืื•ืกืจื™ื ื’ื™ืฉื” ืœืžืฉืชืžืฉื™ื ืœื ืžื•ืจืฉื™ื ืœืืชืจื™ื ืื—ืจื™ื
http_access ืืคืฉืจ ืื™ืฉื•ืจ - ืืคืฉืจ ื’ื™ืฉื” ืœืžืฉืชืžืฉื™ื ืžื•ืจืฉื™ื.
ื–ื”ื•, ื”ื“ื™ื•ื ื•ืŸ ืขืฆืžื• ืžื•ื’ื“ืจ, ืขื›ืฉื™ื• ื”ื’ื™ืข ื”ื–ืžืŸ ืœื”ืชื—ื™ืœ ืœืกื ืŸ ืœืคื™ ืงื‘ื•ืฆื•ืช.

ื”ื’ื“ืจืช SquidGuard

ืขื‘ื•ืจ ืืœ ServicesSquidGuard Proxy Filter.

ื‘-LDAP Options ืื ื• ืžื›ื ื™ืกื™ื ืืช ื”ื ืชื•ื ื™ื ืฉืœ ื”ื—ืฉื‘ื•ืŸ ืฉืœื ื• ื”ืžืฉืžืฉื™ื ืœืื™ืžื•ืช kerberos, ืืš ื‘ืคื•ืจืžื˜ ื”ื‘ื:

CN=pfsense,OU=service-accounts,DC=domain,DC=local

ืื ื™ืฉ ืจื•ื•ื—ื™ื ืื• ืชื•ื•ื™ื ืฉืื™ื ื ืœื˜ื™ื ื™ื™ื, ื›ืœ ื”ืขืจืš ื”ื–ื” ืฆืจื™ืš ืœื”ื™ื•ืช ืžื•ืงืฃ ื‘ืžื™ืจื›ืื•ืช ื‘ื•ื“ื“ื•ืช ืื• ื›ืคื•ืœื•ืช:

'CN=sg,OU=service-accounts,DC=domain,DC=local'
"CN=sg,OU=service-accounts,DC=domain,DC=local"

ืœืื—ืจ ืžื›ืŸ, ื”ืงืคื“ ืœืกืžืŸ ืืช ื”ืชื™ื‘ื•ืช ื”ื‘ืื•ืช:

ืฉืจืช ืคืจื•ืงืกื™ ื—ื™ื ื ืœืืจื’ื•ื ื™ื ืขื ื”ืจืฉืืช ื“ื•ืžื™ื™ืŸ

ื›ื“ื™ ืœื ืชืง DOMAINpfsense ืžื™ื•ืชืจ DOMAIN.LOCAL ืฉื›ืœ ื”ืžืขืจื›ืช ืจื’ื™ืฉื” ืืœื™ื• ืžืื•ื“.

ืขื›ืฉื™ื• ืื ื—ื ื• ื”ื•ืœื›ื™ื ืœ-Group Acl ื•ืžื—ื™ื™ื‘ื™ื ืืช ืงื‘ื•ืฆื•ืช ื”ื’ื™ืฉื” ืœื“ื•ืžื™ื™ืŸ ืฉืœื ื•, ืื ื™ ืžืฉืชืžืฉ ื‘ืฉืžื•ืช ืคืฉื•ื˜ื™ื ื›ืžื• group_0, group_1 ื•ื›ื•' ืขื“ 3, ื›ืืฉืจ 3 ื”ื•ื ื’ื™ืฉื” ืจืง ืœืจืฉื™ืžื” ื”ืœื‘ื ื”, ื•-0 - ื”ื›ืœ ืืคืฉืจื™.

ื”ืงื‘ื•ืฆื•ืช ืžืงื•ืฉืจื•ืช ื‘ืื•ืคืŸ ื”ื‘ื:

ldapusersearch ldap://dc.domain.local:3268/DC=DOMAIN,DC=LOCAL?sAMAccountName?sub?(&(sAMAccountName=%s)(memberOf=CN=group_0%2cOU=squid%2cOU=service-groups%2cDC=DOMAIN%2cDC=LOCAL))

ืฉืžื•ืจ ืืช ื”ืงื‘ื•ืฆื” ืฉืœื ื•, ืขื‘ื•ืจ ืœื˜ื™ื™ืžืก, ืฉื ื™ืฆืจืชื™ ืคืขืจ ืื—ื“ ื›ืœื•ืžืจ ืชืžื™ื“ ืœืขื‘ื•ื“, ื›ืขืช ืขื‘ื•ืจ ืœืงื˜ื’ื•ืจื™ื•ืช ื™ืขื“ ื•ืœื™ืฆื•ืจ ืจืฉื™ืžื•ืช ืœืคื™ ืฉื™ืงื•ืœ ื“ืขืชื ื•, ืœืื—ืจ ื™ืฆื™ืจืช ื”ืจืฉื™ืžื•ืช ืื ื• ื—ื•ื–ืจื™ื ืœืงื‘ื•ืฆื•ืช ืฉืœื ื• ื•ื‘ืชื•ืš ื”ืงื‘ื•ืฆื” ืขื ื›ืคืชื•ืจื™ื ืื ื• ื‘ื•ื—ืจื™ื ืžื™ ื™ื›ื•ืœ ืœืœื›ืช ืื™ืคื”, ื•ืžื™ ืœื ื™ื›ื•ืœ ืื™ืคื”.

LightSquid ื•-sqstat

ืื ื‘ืžื”ืœืš ืชื”ืœื™ืš ื”ื”ื’ื“ืจื” ื‘ื—ืจื ื• ืœื•ืœืื” ื‘ื”ื’ื“ืจื•ืช squid ื•ืคืชื—ื ื• ืืช ื”ื™ื›ื•ืœืช ืœื’ืฉืช ืœ-7445 ื‘ื—ื•ืžืช ื”ืืฉ ื”ืŸ ื‘ืจืฉืช ืฉืœื ื• ื•ื”ืŸ ื‘-pfSense ืขืฆืžื”, ืื– ื›ืฉื ื›ื ืกื™ื ืœ-Squid Proxy Reports Diagnostics, ื ื•ื›ืœ ืœืคืชื•ื— ื‘ืงืœื•ืช ื’ื sqstat ื•ื’ื Lighsquid, ืขื‘ื•ืจ ื”ืื—ืจื•ืŸ ื ืฆื˜ืจืš ื‘ืื•ืชื• ืžืงื•ื, ืœื‘ื•ื ืขื ืฉื ืžืฉืชืžืฉ ื•ืกื™ืกืžื”, ื•ื™ืฉ ื’ื ื”ื–ื“ืžื ื•ืช ืœื‘ื—ื•ืจ ืขื™ืฆื•ื‘.

ื”ืฉืœืžื”

pfSense ื”ื•ื ื›ืœื™ ื—ื–ืง ืžืื•ื“ ืฉื™ื›ื•ืœ ืœืขืฉื•ืช ื”ืจื‘ื” ื“ื‘ืจื™ื - ื’ื ืคืจื•ืงืกื™ ืชืขื‘ื•ืจื” ื•ื’ื ืฉืœื™ื˜ื” ืขืœ ื’ื™ืฉืช ืžืฉืชืžืฉื™ื ืœืื™ื ื˜ืจื ื˜ ื”ื ืจืง ื—ืœืง ืงื˜ืŸ ืžื›ืœ ื”ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช, ืขื ื–ืืช, ื‘ืืจื’ื•ืŸ ืขื 500 ืžื›ื•ื ื•ืช, ื–ื” ืคืชืจ ืืช ื”ื‘ืขื™ื” ื•ื—ืกืš ื‘ ืงื ื™ื™ืช ืคืจื•ืงืกื™.

ืื ื™ ืžืงื•ื•ื” ืฉืžืืžืจ ื–ื” ื™ืขื–ื•ืจ ืœืžื™ืฉื”ื• ืœืคืชื•ืจ ื‘ืขื™ื” ืฉื”ื™ื ื“ื™ ืจืœื•ื•ื ื˜ื™ืช ืขื‘ื•ืจ ืืจื’ื•ื ื™ื ื‘ื™ื ื•ื ื™ื™ื ื•ื’ื“ื•ืœื™ื.

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”