Цитата: Скайп и аську все-таки лучше пускать через НАТ.
что даст огромнейшую дыру в безопасности, отклоняем.
Цитата: Покажи весь конфиг, логи режика и access.log на момент подключения skype.
=== squid.conf ===
access_log /var/log/squid/access.log squid
acl QUERY urlpath_regex cgi-bin \?
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern . 0 20% 4320
acl all src 0.0.0.0/0.0.0.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 483 563 15100
acl Safe_ports port 80
acl Safe_ports port 21
acl Safe_ports port 443 483 563
acl Safe_ports port 70
acl Safe_ports port 1025-65535
acl CONNECT method CONNECT
acl 4dk dstdomain .4dk.ru
acl eset dstdomain .eset.com
acl lgn dstdomain .lgn.ru
acl apple dstdomain .apple.com
acl itunes dstdomain .itunes.com
acl edgesuite dstdomain .edgesuite.com
acl mosnalog dstdomain .mosnalog.ru
acl Skype_UA browser ^skype^
no_cache deny QUERY
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow 4dk
http_access allow eset
http_access allow lgn
http_access allow apple
http_access allow itunes
http_access allow edgesuite
http_access allow mosnalog
http_reply_access allow all
icp_access allow all
icon_directory /usr/local/etc/squid/icons
error_directory /usr/local/etc/squid/errors/Russian-1251
http_port 192.168.0.1:3128
cache_dir ufs /var/spool/squid 41920 16 256
cache_effective_group squid
cache_effective_user squid
url_rewrite_program /usr/local/rejik/redirector /usr/local/rejik/redirector.conf
url_rewrite_children 100
url_rewrite_access allow !Skype_UA
auth_param ntlm program /usr/local/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm children 70
http_access allow CONNECT Skype_UA all
acl AuthorizedUsers proxy_auth REQUIRED
http_access allow all AuthorizedUsers
http_access deny all
=== squid.conf ===
=== redirecdor.log ===
2009-06-22 17:41:14 IP: 192.168.2.21 test_ii 76.101.26.238:443 (pcre rule#: 1)
2009-06-22 17:41:40 IP: 192.168.2.21 test_ii 64.234.215.96:443 (pcre rule#: 1)
2009-06-22 17:42:08 IP: 192.168.2.21 test_ii 204.14.159.203:443 (pcre rule#: 1)
2009-06-22 17:42:33 IP: 192.168.2.21 test_ii 72.222.181.67:443 (pcre rule#: 1)
2009-06-22 17:42:34 IP: 192.168.2.21 test_ii 65.184.202.188:443 (pcre rule#: 1)
=== redirector.log ===
=== access.log ===
1245678128.017 903 192.168.2.21 TCP_DENIED/407 1847 CONNECT 204.14.159.203:443 - NONE/- text/html
1245678128.123 6 192.168.2.21 TCP_MISS/404 0 CONNECT 204.14.159.203:443 test_ii DIRECT/- -
1245678153.712 31 192.168.2.21 TCP_DENIED/407 1844 CONNECT 72.222.181.67:443 - NONE/- text/html
1245678153.814 16 192.168.2.21 TCP_MISS/404 0 CONNECT 72.222.181.67:443 test_ii DIRECT/- -
1245678154.426 17 192.168.2.21 TCP_DENIED/407 1847 CONNECT 65.184.202.188:443 - NONE/- text/html
1245678154.528 41 192.168.2.21 TCP_MISS/404 0 CONNECT 65.184.202.188:443 test_ii DIRECT/- -
=== access.log ===
возникают смутные сомнения, что со строкой типа браузера меня, мягко говоря, накололи ?
если так, то что народ может предложить ?