{"id":74613,"date":"2020-03-18T20:43:03","date_gmt":"2020-03-18T17:43:03","guid":{"rendered":"https:\/\/prohoster.info\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej"},"modified":"2026-05-20T21:31:10","modified_gmt":"2026-05-20T19:31:10","slug":"besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej","status":"publish","type":"post","link":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej","title":{"rendered":"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/03\/229c5f1df948da65810db95ef2b4d2a2.png\" alt=\"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit\" \/><\/p>\n<p>pfSense+Squid me filtrimin https + Teknologjia e hyrjes s\u00eb vetme (SSO) me filtrimin sipas grupeve t\u00eb Active Directory<\/p>\n<h4>Nj\u00eb p\u00ebrmbledhje e shkurt\u00ebr<\/h4>\n<p>N\u00eb kompani u shfaq nevoja p\u00ebr t\u00eb implementuar nj\u00eb server proxy me mund\u00ebsi filtrimi t\u00eb qasjes n\u00eb faqe (p\u00ebrfshir\u00eb https) sipas grupeve nga AD, n\u00eb m\u00ebnyr\u00eb q\u00eb p\u00ebrdoruesit t\u00eb mos ken\u00eb nevoj\u00eb t\u00eb fusin asnj\u00eb fjal\u00ebkalim shtes\u00eb, nd\u00ebrsa administrimi t\u00eb mund t\u00eb b\u00ebhet nga nd\u00ebrfaqja n\u00eb internet. Nj\u00eb k\u00ebrkes\u00eb e mir\u00eb, apo jo?<\/p>\n<p>Zgjidhja e duhur do t\u00eb ishte t\u00eb blije zgjidhje si Kerio Control ose UserGate, por si gjithmon\u00eb parat\u00eb nuk mjaftojn\u00eb, nd\u00ebrsa nevoja \u00ebsht\u00eb e madhe.<\/p>\n<p>K\u00ebtu vjen n\u00eb ndihm\u00eb Squid-i i njohur, por p\u00ebrs\u00ebri \u2014 ku ta gjejm\u00eb nd\u00ebrfaqen n\u00eb internet? SAMS2? \u00cbsht\u00eb moralsh\u00ebm i vjetruar. K\u00ebtu vjen n\u00eb ndihm\u00eb pfSense.<\/p>\n<h4>P\u00ebrshkrimi<\/h4>\n<p>N\u00eb k\u00ebt\u00eb artikull do t\u00eb p\u00ebrshkruhet m\u00ebnyra e konfigurimit t\u00eb serverit proxy Squid.<br \/>\nP\u00ebr autorizimin e p\u00ebrdoruesve do t\u00eb p\u00ebrdoret Kerberos.<br \/>\nP\u00ebr filtrimin sipas grupeve t\u00eb domainit do t\u00eb p\u00ebrdoret SquidGuard.<\/p>\n<p>P\u00ebr monitorim do t\u00eb p\u00ebrdoren Lightsquid, sqstat dhe sistemet e brendshme t\u00eb monitorimit t\u00eb pfSense.<br \/>\nGjithashtu do t\u00eb zgjidhet nj\u00eb problem i zakonsh\u00ebm i lidhur me implementimin e teknologjis\u00eb s\u00eb hyrjes s\u00eb vetme (SSO), e cila p\u00ebrfshin aplikacionet q\u00eb p\u00ebrpiqen t\u00eb hyjn\u00eb n\u00eb internet me llogarin\u00eb e tyre sistemore.<br \/>\n<a rel=\"nofollow\" name=\"habracut\"><\/a><\/p>\n<h4>P\u00ebrgatitja p\u00ebr instalimin e Squid<\/h4>\n<p>Do t\u00eb merret si baz\u00eb pfSense, <a href=\"https:\/\/docs.netgate.com\/pfsense\/en\/latest\/install\/installing-pfsense.html\" rel=\"nofollow\">Udh\u00ebzimi p\u00ebr instalimin.<\/a><\/p>\n<p>Brenda t\u00eb cilit ne organizojm\u00eb autentifikimin n\u00eb vet\u00eb firewall-in me llogarit\u00eb e domainit. <a href=\"https:\/\/techexpert.tips\/sq\/pfsense-sq\/autentifikimi-pfsense-ldap-ne-active-directory\/\" rel=\"nofollow\">Udh\u00ebzimi.<\/a><\/p>\n<p>Shum\u00eb e r\u00ebnd\u00ebsishme!<\/p>\n<p>Para fillimit t\u00eb instalimit t\u00eb Squid, \u00ebsht\u00eb e nevojshme t\u00eb konfiguroni DNS <a href=\"https:\/\/prohoster.info\/sq\/server\/dts-los-angeles\/\">server\u00eb<\/a> n\u00eb pfsense, t\u00eb b\u00ebni nj\u00eb regjistrim A dhe regjistrime PTR n\u00eb serverin ton\u00eb DNS dhe t\u00eb konfiguroni NTP n\u00eb m\u00ebnyr\u00eb q\u00eb koha t\u00eb mos jet\u00eb e ndryshme nga koha n\u00eb kontrolluesin e domainit.<\/p>\n<p>Dhe n\u00eb rrjetin tuaj t\u00eb ofroni mund\u00ebsin\u00eb q\u00eb nd\u00ebrfaqja WAN e pfSense t\u00eb dal\u00eb n\u00eb internet, nd\u00ebrsa p\u00ebrdoruesit n\u00eb rrjetin lokal t\u00eb lidhen n\u00eb nd\u00ebrfaqen LAN, p\u00ebrfshir\u00eb portin 7445 dhe 3128 (n\u00eb rastin tim 8080).<\/p>\n<p>A \u00ebsht\u00eb gjith\u00e7ka gati? \u00cbsht\u00eb vendosur lidhja me domainin p\u00ebr autorizimin n\u00eb pfSense dhe koha \u00ebsht\u00eb sinkronizuar? Shk\u00eblqyesh\u00ebm. \u00cbsht\u00eb koha t\u00eb fillojm\u00eb procesin kryesor.<\/p>\n<h4>Instalimi dhe konfigurimi fillestar<\/h4>\n<p>Do t\u00eb instalojm\u00eb Squid, SquidGuard dhe LightSquid nga menaxheri i paketave t\u00eb pfSense n\u00eb seksionin \"Sistemi \/ Menaxheri i Paketave\".<\/p>\n<p>Pasi p\u00ebrfundimit t\u00eb suksessh\u00ebm t\u00eb instalimit, kalojm\u00eb n\u00eb \u00abSh\u00ebrbimet\/Squid Proxy server\/\u00bb dhe n\u00eb radh\u00eb t\u00eb par\u00eb n\u00eb sked\u00ebn Local Cache stakojm\u00eb cachingun. Un\u00eb e vendosa gjith\u00e7ka n\u00eb 0, pasi nuk shoh ndonj\u00eb kuptim t\u00eb ve\u00e7ant\u00eb p\u00ebr t\u00eb cache-uar faqet, me k\u00ebt\u00eb jan\u00eb t\u00eb mjaftuesh\u00ebm edhe shfletuesit. Pas konfigurimit, klikojm\u00eb butonin \u00abRuaj\u00bb n\u00eb fund t\u00eb ekranit dhe kjo do t\u00eb na jap\u00eb mund\u00ebsin\u00eb p\u00ebr t\u00eb b\u00ebr\u00eb konfigurimet e nevojshme t\u00eb proxy-t.<\/p>\n<p>Konfigurimet kryesore i sjellim n\u00eb k\u00ebt\u00eb form\u00eb:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/03\/b3333c720db87625c76ea56d194295ff.png\" alt=\"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit\" \/><\/p>\n<p>Porti\u9ed8\u8ba4 3128, por un\u00eb preferoj t\u00eb p\u00ebrdor 8080.<\/p>\n<p>Parametrat e zgjedhur n\u00eb sked\u00ebn Proxy Interface p\u00ebrcaktojn\u00eb se cilat nd\u00ebrfaqe do t\u00eb p\u00ebrgjoj\u00eb proxy-i yn\u00eb. <a href=\"https:\/\/prohoster.info\/sq\/server\/\">server<\/a>. Duke qen\u00eb se ky firewall \u00ebsht\u00eb nd\u00ebrtuar n\u00eb at\u00eb m\u00ebnyr\u00eb q\u00eb internetin e shikon p\u00ebrmes nd\u00ebrfaqes WAN, edhe kur LAN dhe WAN mund t\u00eb jen\u00eb n\u00eb t\u00eb nj\u00ebjt\u00ebn n\u00ebnsistem lokale, rekomandoj q\u00eb p\u00ebr proxy-in t\u00eb p\u00ebrdoret pik\u00ebrisht LAN.<\/p>\n<p>Loopback \u00ebsht\u00eb e nevojshme p\u00ebr funksionimin e sqstat.<\/p>\n<p>M\u00eb posht\u00eb do t\u00eb gjeni konfigurimet p\u00ebr Transparent (proxy t\u00eb transparenc\u00ebs), si dhe SSL Filter, por ato nuk na nevojiten, proxy yn\u00eb do t\u00eb jet\u00eb jo transparent, dhe p\u00ebr filtrimin https nuk do t\u00eb merren me z\u00ebvend\u00ebsimin e certifikat\u00ebs (n\u00eb fund t\u00eb fundit kemi qarkullim dokumentesh, banka-klient\u00eb etj), por thjesht do t\u00eb shohim p\u00ebrshpejtimin.<\/p>\n<p>N\u00eb k\u00ebt\u00eb faz\u00eb, na nevojitet t\u00eb kalojm\u00eb n\u00eb kontrolerin ton\u00eb t\u00eb domenit, t\u00eb krijojm\u00eb n\u00eb t\u00eb nj\u00eb llogari p\u00ebr autentifikim (mund t\u00eb p\u00ebrdorim edhe at\u00eb q\u00eb kemi konfiguruar p\u00ebr autentifikim n\u00eb vet\u00eb pfSense). Nj\u00eb faktor shum\u00eb i r\u00ebnd\u00ebsish\u00ebm \u2014 n\u00ebse planifikoni t\u00eb p\u00ebrdorni enkriptimin AES128 ose AES256 \u2014 vendosni kutit\u00eb p\u00ebrkat\u00ebse n\u00eb konfigurimet e llogaris\u00eb.<\/p>\n<p>N\u00eb rast se domeni juaj p\u00ebrb\u00ebn nj\u00eb pyll t\u00eb nd\u00ebrlikuar me nj\u00eb num\u00ebr t\u00eb madh katalogesh ose domeni juaj \u00ebsht\u00eb .local, at\u00ebher\u00eb N\u00cb DISA RASTE, por jo gjithmon\u00eb, mund t\u2019ju duhet t\u00eb p\u00ebrdorni p\u00ebr k\u00ebt\u00eb llogari nj\u00eb fjal\u00ebkalim t\u00eb thjesht\u00eb, nj\u00eb bug i njohur, por me nj\u00eb fjal\u00ebkalim t\u00eb komplikuar mund t\u00eb mos funksionoj\u00eb, duhet t\u00eb kontrolloni p\u00ebr rastin konkret.<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/03\/d93a4a825a83de3e0c94cde9c1017411.png\" alt=\"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit\" \/><\/p>\n<p>Pas k\u00ebsaj, formojm\u00eb skedarin e \u00e7el\u00ebsave p\u00ebr Kerberos, n\u00eb kontrolerin e domenit hapim komand\u00ebn me t\u00eb drejtat e adminit dhe shkruajm\u00eb:<\/p>\n<pre><code class=\"plaintext\"># ktpass -princ HTTP\/pfsense.domain.local@DOMAIN.LOCAL -mapuser pfsense -pass 3EYldza1sR -crypto {DES-CBC-CRC|DES-CBC-MD5|RC4-HMAC-NT|AES256-SHA1|AES128-SHA1|All} -ptype KRB5_NT_PRINCIPAL -out C:keytabsPROXY.keytab<\/code><\/pre>\n<p>K\u00ebtu n\u00ebnvizojm\u00eb FQDN e pfSense, duke respektuar regjistrin, n\u00eb parametrin mapuser themi llogarin\u00eb ton\u00eb t\u00eb domenit dhe fjal\u00ebkalimin e saj, nd\u00ebrsa n\u00eb crypto zgjedhim m\u00ebnyr\u00ebn e enkriptimit, un\u00eb p\u00ebrdora rc4 p\u00ebr pun\u00eb dhe n\u00eb fush\u00ebn -out zgjedhim se ku do ta d\u00ebrgojm\u00eb skedarin ton\u00eb t\u00eb gatsh\u00ebm t\u00eb \u00e7el\u00ebsave.<br \/>\nPas krijimit t\u00eb suksessh\u00ebm t\u00eb skedarit t\u00eb \u00e7elqeve, ne do ta d\u00ebrgojm\u00eb at\u00eb n\u00eb pfSense ton\u00eb, un\u00eb e p\u00ebrdora Far p\u00ebr k\u00ebt\u00eb, por gjithashtu mund ta b\u00ebni k\u00ebt\u00eb me komanda ose p\u00ebrmes putty ose p\u00ebrmes nd\u00ebrfaqes s\u00eb web-it t\u00eb pfSense n\u00eb seksionin \"DiagnostikimiKonsola e komandave\".<\/p>\n<p>Tani ne mund t\u00eb redaktojm\u00eb krijojm\u00eb \/etc\/krb5.conf<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/03\/0fb3830c14d216afa05ac45e3aec66e4.png\" alt=\"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit\" \/><\/p>\n<p>ku \/etc\/krb5.keytab \u00ebsht\u00eb skedari i \u00e7elqeve q\u00eb kemi krijuar.<\/p>\n<p>Sigurohuni t\u00eb kontrolloni funksionimin e Kerberos me kinit, n\u00ebse nuk punon \u2014 nuk ka kuptim t\u00eb lexoni m\u00eb tej.<\/p>\n<h4>Konfigurimi i autentifikimit t\u00eb Squid dhe list\u00ebs s\u00eb aksesit pa autentifikim<\/h4>\n<p>Pasi t\u00eb kemi konfiguruar me sukses Kerberos, do ta lidhim at\u00eb me Squid-in ton\u00eb.<\/p>\n<p>P\u00ebr k\u00ebt\u00eb, shkoni te Sh\u00ebrbimetSquid Proxy Server dhe n\u00eb cil\u00ebsimet kryesore zbrisni posht\u00eb, aty do t\u00eb gjejm\u00eb butonin \"Cil\u00ebsimet e avancuara\".<\/p>\n<p>N\u00eb fush\u00ebn e Opsioneve t\u00eb Personalizuara (Para Autentifikimit) do t\u00eb shkruajm\u00eb:<\/p>\n<pre><code class=\"perl\">#\u0425\u0435\u043b\u043f\u0435\u0440\u044b\nauth_param negotiate program \/usr\/local\/libexec\/squid\/negotiate_kerberos_auth -s GSS_C_NO_NAME -k \/usr\/local\/etc\/squid\/squid.keytab -t none\nauth_param negotiate children 1000\nauth_param negotiate keep_alive on\n#\u0421\u043f\u0438\u0441\u043a\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0430\nacl auth proxy_auth REQUIRED\nacl nonauth dstdomain \"\/etc\/squid\/nonauth.txt\" \n#\u0420\u0430\u0437\u0440\u0435\u0448\u0435\u043d\u0438\u044f \nhttp_access allow nonauth \nhttp_access deny !auth\nhttp_access allow auth<\/code><\/pre>\n<p>ku <i>auth_param negotiate program \/usr\/local\/libexec\/squid\/negotiate_kerberos_auth<\/i> \u2014 zgjedh helparin e nevojsh\u00ebm p\u00ebr autentifikimin Kerberos.<\/p>\n<p>\u00c7el\u00ebsi <i>-s<\/i> me vler\u00ebn <i>GSS_C_NO_NAME<\/i> \u2014 p\u00ebrcakton p\u00ebrdorimin e \u00e7do llogarie nga skedari i \u00e7elqeve.<\/p>\n<p>\u00c7el\u00ebsi <i>-k<\/i> me vler\u00ebn <i>\/usr\/local\/etc\/squid\/squid.keytab<\/i> \u2014 p\u00ebrcakton p\u00ebrdorimin e k\u00ebtij skedari keytab. N\u00eb rastin tim, ky \u00ebsht\u00eb po ai skedar keytab i formuar prej nesh, q\u00eb e kam kopjuar n\u00eb direktorin\u00eb \/usr\/local\/etc\/squid\/ dhe e kam rinomuar, sepse me at\u00eb direktor fejk skuid nuk donte t\u00eb bashk\u00ebpunonte, duket se i mungonte leja.<\/p>\n<p>\u00c7el\u00ebsi <i>-t<\/i> me vler\u00ebn <i>-t none<\/i> \u2014 ndalon k\u00ebrkesat ciklike ndaj kontrolluesit t\u00eb domenit, \u00e7ka ndihmon duke ulur ngarkes\u00ebn mbi t\u00eb n\u00ebse keni m\u00eb shum\u00eb se 50 p\u00ebrdorues.<br \/>\nP\u00ebr koh\u00ebn e testimit gjithashtu mund t\u00eb shtoni \u00e7el\u00ebsin -d \u2014 do t\u00eb thot\u00eb diagnostikim, m\u00eb shum\u00eb logje do t\u00eb shfaqen.<br \/>\n<i>auth_param negotiate children 1000<\/i> \u2014 p\u00ebrcakton sa procese t\u00eb autorizimit mund t\u00eb jen\u00eb n\u00eb funksion s\u00eb bashku<br \/>\n<i>auth_param negotiate keep_alive on<\/i> \u2014 nuk lejon q\u00eb lidhja t\u00eb nd\u00ebrpritet gjat\u00eb anketimit t\u00eb zinxhirit t\u00eb autorizimit<br \/>\n<i>acl auth proxy_auth REQUIRED<\/i> \u2014 krijon dhe k\u00ebrkon nj\u00eb list\u00eb kontrolli t\u00eb aksesit, duke p\u00ebrfshir\u00eb p\u00ebrdoruesit q\u00eb kan\u00eb kaluar autorizimin<br \/>\n<i>acl nonauth dstdomain \u00ab\/etc\/squid\/nonauth.txt\u00bb<\/i> \u2014 i njoftojm\u00eb Skuidit p\u00ebr list\u00ebn e aksesit nonauth e cila p\u00ebrmban domenet e destinacionit, t\u00eb cilave gjithmon\u00eb do t'u lejohet akses p\u00ebr t\u00eb gjith\u00eb. Skedari vet\u00eb krijohet dhe brenda tij shkruajm\u00eb domenet n\u00eb formatin<\/p>\n<pre><code class=\"perl\">.whatsapp.com\n.whatsapp.net<\/code><\/pre>\n<p>Whatsapp nuk \u00ebsht\u00eb p\u00ebr t\u00eb qeshur si shembull \u2014 ai \u00ebsht\u00eb shum\u00eb i ndjesh\u00ebm ndaj proxy-ve me autentifikim dhe nuk do t\u00eb funksionoj\u00eb n\u00ebse nuk lejohet para autentifikimit.<br \/>\n<i>http_access allow nonauth<\/i> \u2014 lejojm\u00eb aksesin p\u00ebr k\u00ebt\u00eb list\u00eb t\u00eb gjith\u00eb<br \/>\n<i>http_access deny !auth<\/i> \u2014 ndalojm\u00eb aksesin p\u00ebr p\u00ebrdoruesit e paautorizuar n\u00eb faqet e tjera<br \/>\n<i>http_access allow auth<\/i> \u2014 lejojm\u00eb qasje p\u00ebrdoruesve t\u00eb autorizuar.<br \/>\nTani, skuidi \u00ebsht\u00eb i konfiguruar, tani \u00ebsht\u00eb koha p\u00ebr t\u00eb filluar filtrimin sipas grupeve.<\/p>\n<h4>Konfigurimi i SquidGuard<\/h4>\n<p>Kalojm\u00eb n\u00eb Sh\u00ebrbimet SquidGuard Proxy Filter.<\/p>\n<p>N\u00eb Mund\u00ebsit\u00eb LDAP, vendosim t\u00eb dh\u00ebnat e llogaris\u00eb son\u00eb, e cila p\u00ebrdoret p\u00ebr autentifikimin Kerberos, por n\u00eb formatin e m\u00ebposht\u00ebm:<\/p>\n<pre><code class=\"perl\">CN=pfsense,OU=service-accounts,DC=domain,DC=local<\/code><\/pre>\n<p>N\u00ebse ka hap\u00ebsira ose simbole jo-latine, kjo rekord duhet t\u00eb vendoset n\u00eb thonj\u00ebza t\u00eb nj\u00ebfishta ose t\u00eb dyfishta:<\/p>\n<pre><code class=\"perl\">'CN=sg,OU=service-accounts,DC=domain,DC=local'\n\"CN=sg,OU=service-accounts,DC=domain,DC=local\"<\/code><\/pre>\n<p>M\u00eb pas, sigurohuni q\u00eb t\u00eb vendosni k\u00ebto kutia kontrolli:<\/p>\n<p><img decoding=\"async\" style=\"display: block; margin: 0 auto;\" src=\"\/wp-content\/uploads\/2020\/03\/162ca3f3b6d0977c8ac73f20b640f67c.png\" alt=\"Proxy falas p\u00ebr biznes me autorizim t\u00eb domenit\" \/><\/p>\n<p>P\u00ebr t\u00eb prer\u00eb DOMAINin e panevojsh\u00ebm pfsense <a class=\"user_link\" href=\"https:\/\/habr.com\/ru\/users\/domain\/\" rel=\"nofollow\">DOMAIN<\/a>.LOCAL p\u00ebr t\u00eb cilat t\u00ebr\u00eb sistemi \u00ebsht\u00eb shum\u00eb i ndjesh\u00ebm.<\/p>\n<p>Tani kalojm\u00eb n\u00eb Acl Grupi dhe lidhi grupet tona t\u00eb dominimit t\u00eb aksesit, un\u00eb p\u00ebrdor emra t\u00eb thjesht\u00eb si group_0, group_1 dhe k\u00ebshtu deri n\u00eb 3, ku 3 - akses vet\u00ebm n\u00eb list\u00ebn e bardh\u00eb, nd\u00ebrsa 0 - mund t\u00eb b\u00ebsh gjith\u00e7ka.<\/p>\n<p>Grupet lidhen si m\u00eb posht\u00eb:<\/p>\n<pre><code class=\"perl\">ldapusersearch ldap:\/\/dc.domain.local:3268\/DC=DOMAIN,DC=LOCAL?sAMAccountName?sub?(&amp;(sAMAccountName=%s)(memberOf=CN=group_0,OU=squid,OU=service-groups,DC=DOMAIN,DC=LOCAL))<\/code><\/pre>\n<p>ruajm\u00eb grupin tone, kalojm\u00eb n\u00eb Koha, atje krijova nj\u00eb interval t\u00eb vet\u00ebm q\u00eb do t\u00eb thot\u00eb t\u00eb punosh gjithmon\u00eb, tani kalojm\u00eb n\u00eb Kategorit\u00eb e Objektivave dhe krijojm\u00eb lista sipas d\u00ebshir\u00ebs son\u00eb, pas krijimit t\u00eb listave kthehemi n\u00eb grupet tona dhe brenda grupit, me butona zgjedhim kush mund t\u00eb shkoj\u00eb, e kush nuk mund.<\/p>\n<h4>LightSquid dhe sqstat<\/h4>\n<p>N\u00ebse gjat\u00eb konfigurimit zgjodh\u00ebm loopback n\u00eb konfigurimin e skuid dhe hap\u00ebm mund\u00ebsin\u00eb p\u00ebr t\u00eb hyr\u00eb n\u00eb 7445 n\u00eb firewall si n\u00eb rrjetin ton\u00eb, ashtu edhe n\u00eb pfSense vet\u00eb, kur kalojm\u00eb n\u00eb Diagnostik\u00ebn Raportet e Proxy Squid, do t\u00eb jemi n\u00eb gjendje t\u00eb hapim leht\u00eb si sqstat ashtu edhe Lighsquid, p\u00ebr k\u00ebt\u00eb t\u00eb fundit do t\u00eb na nevojitet t\u00eb krijojm\u00eb nj\u00eb p\u00ebrdorues dhe fjal\u00ebkalim atje, dhe gjithashtu ka mund\u00ebsin\u00eb t\u00eb zgjedhim dizajnin.<\/p>\n<h4>P\u00ebrfundimi<\/h4>\n<p>pfSense \u00ebsht\u00eb nj\u00eb mjet shum\u00eb i fuqish\u00ebm, i cili mund t\u00eb b\u00ebj\u00eb shum\u00eb gj\u00ebra\u2014nga prokimin e trafikut deri te kontrolli i aksesit t\u00eb p\u00ebrdoruesve n\u00eb internet. Kjo \u00ebsht\u00eb vet\u00ebm nj\u00eb pjes\u00eb e funksionalitetit t\u00eb tij, megjithat\u00eb n\u00eb nj\u00eb kompani me 500 makina, kjo zgjidhi problemin dhe ndihmoi n\u00eb kursimin e para nga blerja e proksi.<\/p>\n<p>Shpresoj q\u00eb ky artikull t\u00eb ndihmoj\u00eb dik\u00eb t\u00eb zgjidh\u00eb nj\u00eb detyr\u00eb mjaft aktuale p\u00ebr nd\u00ebrmarrjet e mesme dhe t\u00eb m\u00ebdha.<\/p>\n<p>Burimi: <a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/post\/492684\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>pfSense+Squid \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439 https + \u0422\u0435\u0445\u043d\u043e\u043b\u043e\u0433\u0438\u044f \u0435\u0434\u0438\u043d\u043e\u0433\u043e \u0432\u0445\u043e\u0434\u0430 (SSO) \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439 \u043f\u043e \u0433\u0440\u0443\u043f\u043f\u0430\u043c Active Directory \u041a\u0440\u0430\u0442\u043a\u0430\u044f \u043f\u0440\u0435\u0434\u044b\u0441\u0442\u043e\u0440\u0438\u044f \u041d\u0430 \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u044f\u0442\u0438\u0438 \u0432\u043e\u0437\u043d\u0438\u043a\u043b\u0430 \u043d\u0435\u043e\u0431\u0445\u043e\u0434\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u043e \u0432\u043d\u0435\u0434\u0440\u0435\u043d\u0438\u0438 \u043f\u0440\u043e\u043a\u0441\u0438-\u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0441 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u044c \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0430 \u043a \u0441\u0430\u0439\u0442\u0430\u043c(\u0432 \u0442\u043e\u043c \u0447\u0438\u0441\u043b\u0435 https) \u043f\u043e \u0433\u0440\u0443\u043f\u043f\u0430\u043c \u0438\u0437 AD, \u0447\u0442\u043e\u0431\u044b \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0438 \u043d\u0435 \u0432\u0432\u043e\u0434\u0438\u043b\u0438 \u043d\u0438\u043a\u0430\u043a\u0438\u0445 \u0434\u043e\u043f\u043e\u043b\u043d\u0438\u0442\u0435\u043b\u044c\u043d\u044b\u0445 \u043f\u0430\u0440\u043e\u043b\u0435\u0439, \u0430 \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043c\u043e\u0436\u043d\u043e \u0431\u044b\u043b\u043e \u0441 \u0432\u0435\u0431 \u0438\u043d\u0442\u0435\u0440\u0444\u0435\u0439\u0441\u0430. \u041d\u0435\u043f\u043b\u043e\u0445\u0430\u044f \u0437\u0430\u044f\u0432\u043e\u0447\u043a\u0430, \u043d\u0435 \u043f\u0440\u0430\u0432\u0434\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":74614,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-74613","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"pfSense+Squid \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"sq_AL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0411\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u043a\u0441\u0438-\u0441\u0435\u0440\u0432\u0435\u0440 \u0434\u043b\u044f \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u044f\u0442\u0438\u044f \u0441 \u0434\u043e\u043c\u0435\u043d\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0435\u0439 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"pfSense+Squid \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-03-18T17:43:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-05-20T19:31:10+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Server proxy falas p\u00ebr nd\u00ebrmarrje me autorizim t\u00eb domenit | ProHoster","description":"pfSense+Squid me filtrimin.","canonical_url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"sq_AL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0411\u0435\u0441\u043f\u043b\u0430\u0442\u043d\u044b\u0439 \u043f\u0440\u043e\u043a\u0441\u0438-\u0441\u0435\u0440\u0432\u0435\u0440 \u0434\u043b\u044f \u043f\u0440\u0435\u0434\u043f\u0440\u0438\u044f\u0442\u0438\u044f \u0441 \u0434\u043e\u043c\u0435\u043d\u043d\u043e\u0439 \u0430\u0432\u0442\u043e\u0440\u0438\u0437\u0430\u0446\u0438\u0435\u0439 | ProHoster","og:description":"pfSense+Squid \u0441 \u0444\u0438\u043b\u044c\u0442\u0440\u0430\u0446\u0438\u0435\u0439.","og:url":"https:\/\/prohoster.info\/sq\/blog\/administrirovanie\/besplatnyj-proksi-server-dlya-predpriyatiya-s-domennoj-avtorizacziej","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-03-18T17:43:03+00:00","article:modified_time":"2026-05-20T19:31:10+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"74613","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 18:11:25","updated":"2022-09-28 14:47:46","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74613","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/comments?post=74613"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74613\/revisions"}],"predecessor-version":[{"id":181598,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/posts\/74613\/revisions\/181598"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media\/74614"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/media?parent=74613"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/categories?post=74613"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/sq\/wp-json\/wp\/v2\/tags?post=74613"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}