{"id":797,"date":"2014-04-15T08:40:02","date_gmt":"2014-04-15T11:40:02","guid":{"rendered":"http:\/\/www.viazap.com.br\/?p=797"},"modified":"2014-04-15T08:40:31","modified_gmt":"2014-04-15T11:40:31","slug":"proxy-squid-com-squidguard-controle-de-banda-e-autenticacao-ntlm-no-samba-4-centos-6-5-64-bits-minimal","status":"publish","type":"post","link":"https:\/\/blog.clusterweb.com.br\/?p=797","title":{"rendered":"Proxy Squid com SquidGuard + Controle de Banda e Autentica\u00e7\u00e3o NTLM no Samba 4 (CentOS 6.5 &#8211; 64 bits Minimal)"},"content":{"rendered":"<table width=\"100%\" border=\"0\" cellspacing=\"3\" cellpadding=\"3\">\n<tbody>\n<tr>\n<td colspan=\"2\"><b>Configura\u00e7\u00f5es iniciais<\/b><\/p>\n<div>Instalando reposit\u00f3rios:<strong># rpm -Uvh http:\/\/fedora.uib.no\/epel\/6\/i386\/epel-release-6-8.noarch.rpm<br \/>\n# yum clean all<br \/>\n# yum -y update<\/strong><\/p>\n<p>Desativando o Firewall e o SELinux:<\/p>\n<p><strong># chkconfig iptables off<br \/>\n# chkconfig ip6tables off<br \/>\n# setenforce 0<\/strong><\/p>\n<p># vi \/etc\/selinux\/config<br \/>\n<sub>\u00a0selinux=disabled\u00a0<\/sub><\/p>\n<p>Instalando depend\u00eancias e pacotes necess\u00e1rios:<\/p>\n<p><strong># yum -y install flex bison squid squidGuard samba samba-client samba-common samba-winbind pam_krb5 bind-utils httpd<\/strong><\/p>\n<p>Ajustando a inicializa\u00e7\u00e3o dos programas:<\/p>\n<p><strong># chkconfig httpd on<br \/>\n# chkconfig squid on<br \/>\n# chkconfig smb on<br \/>\n# chkconfig nmb on<br \/>\n# chkconfig winbind on<\/strong><\/p>\n<p>Ajustando resolu\u00e7\u00e3o de nomes:<\/p>\n<p>Obs.: fa\u00e7a primeiro um backup do arquivo original:<\/p>\n<p><strong># cp -Rfa \/etc\/resolv.conf{,.bkp}<\/strong><\/p>\n<p># vi \/etc\/resolv.conf<br \/>\n<sub>\u00a0search\u00a0dominio.local<br \/>\nnameserver\u00a0192.168.100.11\u00a0\u00a0#\u00a0IP\u00a0DO\u00a0SERVIDOR\u00a0AD\u00a0OU\u00a0SAMBA\u00a04\u00a0<\/sub><\/p>\n<p>Executando testes:<\/p>\n<p><strong># nslookup dominio.local<\/strong><br \/>\n<sub>\u00a0Server:\u00a0192.168.100.11<br \/>\nAddress:\u00a0192.168.100.11#53<\/sub><\/p>\n<p>Name:\u00a0\u00a0\u00a0dominio.local<br \/>\nAddress:\u00a0192.168.100.11<\/p>\n<p>Ajustando a hora:<\/p>\n<p><strong># yum -y install ntpdate<br \/>\n# ntpdate -u ntp.usp.br<\/strong>\u00a0\u00a0\u00a0\u00a0# Se tiver NTP da rede local aponte para o IP\/nome dele<!--more--><\/p>\n<h1>Configurando Kerberos<\/h1>\n<p>Fazer backup do arquivo de configura\u00e7\u00e3o:<\/p>\n<p><strong># cp -Rfa \/etc\/krb5.conf{,.bkp}<br \/>\n# rm -rf \/etc\/krb5.conf<br \/>\n# vi \/etc\/krb5.conf<\/strong><\/p>\n<div>[libdefaults]<br \/>\ndefault_realm = dominio.local<br \/>\nkrb4_config = \/etc\/krb.conf<br \/>\nkrb4_realms = \/etc\/krb.realms<br \/>\nkdc_timesync = 1<br \/>\nccache_type = 4<br \/>\nforwardable = true<br \/>\nproxiable = true<br \/>\nv4_instance_resolve = false<br \/>\nv4_name_convert = {<br \/>\nhost = {<br \/>\nrcmd = host<br \/>\nftp = ftp<br \/>\n}<br \/>\nplain = {<br \/>\nsomething = something-else<br \/>\n}<br \/>\n}<br \/>\nfcc-mit-ticketflags = true[realms]<br \/>\ndominio.local = {<br \/>\nkdc = 192.168.100.11<br \/>\nadmin_server = 192.168.100.11:749<br \/>\ndefault_server = 192.168.100.11<br \/>\n}<\/p>\n<p>[domain_realm]<br \/>\n.dominio.local=dominio.local<br \/>\ndominio.local=dominio.local<\/p>\n<p>[login]<br \/>\nkrb4_convert = true<br \/>\nkrb4_get_tickets = false<\/p>\n<p>[kdc]<br \/>\nprofile = \/etc\/krb5kdc\/kdc.conf<\/p>\n<p>[appdefaults]<br \/>\npam = {<br \/>\ndebug = false<br \/>\nticket_lifetime = 36000<br \/>\nrenew_lifetime = 36000<br \/>\nforwardable = true<br \/>\nkrb4_convert = false<br \/>\n}<\/p>\n<p>[logging]<br \/>\ndefault = file:\/var\/log\/krb5libs.log<br \/>\nkdc = file:\/var\/log\/krb5kdc.log<br \/>\nadmin_server = file:\/var\/log\/kadmind.log<\/p>\n<\/div>\n<p>Para que n\u00e3o ocorra erros no Samba:<\/p>\n<p><strong># vi \/etc\/security\/limits.conf<\/strong><\/p>\n<p>Insira as informa\u00e7\u00f5es abaixo no final do arquivo:<\/p>\n<div>root hard nofile 131072<br \/>\nroot soft nofile 65536<br \/>\nmioutente hard nofile 32768<br \/>\nmioutente soft nofile 16384<\/div>\n<h1>Ajustando Samba<\/h1>\n<p>Backup do arquivo de configura\u00e7\u00e3o:<\/p>\n<p><strong># cp -Rfa \/etc\/samba\/smb.conf{,.bkp}<br \/>\n# rm -rf \/etc\/samba\/smb.conf<br \/>\n# vi \/etc\/samba\/smb.conf<\/strong><\/p>\n<div>[global]<br \/>\nworkgroup = DOMINIO<br \/>\nrealm = DOMINIO.LOCAL<br \/>\nnetbios name = CentOS<br \/>\nserver string = Servidor Proxy CentOS<br \/>\nsecurity = ADS<br \/>\nauth methods = winbind<br \/>\npassword server = 192.168.100.11 # IP DO SAMBA 4<br \/>\nsocket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192<br \/>\nload printers = No<br \/>\nprintcap name = cups<br \/>\ndisable spoolss = Yes<br \/>\nlocal master = No<br \/>\ndomain master = Yes<br \/>\nidmap uid = 10000-30000<br \/>\nidmap gid = 10000-30000<br \/>\nwinbind cache time = 15<br \/>\nwinbind enum users = Yes<br \/>\nwinbind enum groups = Yes<br \/>\nwinbind use default domain = Yes<\/div>\n<p>Fa\u00e7a um backup do arquivo\u00a0<span>\/etc\/nsswitch.conf<\/span>:<\/p>\n<p><strong># cp \/etc\/nsswitch.conf{,.bkp}<\/strong><\/p>\n<p>Ajustar conforme arquivo abaixo:<\/p>\n<p><strong># vi \/etc\/nsswitch.conf<\/strong><\/p>\n<div>[&#8230;]<br \/>\npasswd: files winbind<br \/>\nshadow: files<br \/>\ngroup: files winbind<br \/>\n[&#8230;]<\/div>\n<p>Ajustando privil\u00e9gios:<\/p>\n<p><strong># gpasswd -a squid wbpriv<\/strong><\/p>\n<p>Iniciando servi\u00e7os:<\/p>\n<p><strong># \/etc\/init.d\/nmb start<br \/>\n# \/etc\/init.d\/smb start<br \/>\n# \/etc\/init.d\/winbind start<\/strong><\/p>\n<p>Ingressando o servidor no dom\u00ednio:<\/p>\n<p><strong># net ads join dominio.local -U administrador<\/strong><br \/>\n<sub>\u00a0Enter\u00a0administrador&#8217;s\u00a0password:\u00a0[A\u00a0SENHA\u00a0DO\u00a0ADMINISTRADOR\u00a0DO\u00a0SAMBA\u00a04]<br \/>\nUsing\u00a0short\u00a0domain\u00a0name\u00a0&#8212;\u00a0DOMINIO<br \/>\nJoined\u00a0&#8216;CENTOS&#8217;\u00a0to\u00a0realm\u00a0&#8216;DOMINIO.LOCAL&#8217;\u00a0<\/sub><\/p>\n<p>Reinicie os servi\u00e7os<\/p>\n<p><strong># \/etc\/init.d\/smb restart<br \/>\n# \/etc\/init.d\/nmb restart<br \/>\n# \/etc\/init.d\/winbind restart<\/strong><\/p>\n<p>Verifique a comunica\u00e7\u00e3o:<\/p>\n<p><strong># wbinfo -t<\/strong><br \/>\n<sub>\u00a0checking\u00a0the\u00a0trust\u00a0secret\u00a0for\u00a0domain\u00a0DOMINIO\u00a0via\u00a0RPC\u00a0calls\u00a0succeeded\u00a0<\/sub><\/p>\n<p><strong># wbinfo -u<\/strong><br \/>\n<sub>\u00a0administrator<br \/>\njohnny<br \/>\nkrbtgt<br \/>\nguest\u00a0<\/sub><\/p>\n<p><strong># wbinfo -g<\/strong><br \/>\n<sub>\u00a0allowed\u00a0rodc\u00a0password\u00a0replication\u00a0group<br \/>\nenterprise\u00a0read-only\u00a0domain\u00a0controllers<br \/>\ndenied\u00a0rodc\u00a0password\u00a0replication\u00a0group<br \/>\nread-only\u00a0domain\u00a0controllers<br \/>\ngroup\u00a0policy\u00a0creator\u00a0owners<br \/>\nras\u00a0and\u00a0ias\u00a0servers<br \/>\ndomain\u00a0controllers<br \/>\nenterprise\u00a0admins<br \/>\ndomain\u00a0computers<br \/>\ncert\u00a0publishers<br \/>\ndnsupdateproxy<br \/>\ndomain\u00a0admins<br \/>\ndomain\u00a0guests<br \/>\nschema\u00a0admins<br \/>\ndomain\u00a0users<br \/>\ndnsadmins<br \/>\ninternet-ti<br \/>\ninternet-comercial<br \/>\ninternet-diretoria\u00a0<\/sub><\/p>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\"><b>Configurando o Squid<\/b><\/p>\n<div>Backup do arquivo de configura\u00e7\u00e3o:<strong># cp -Rfa \/etc\/squid\/squid.conf{,.bkp}<br \/>\n# rm -rf \/etc\/squid\/squid.conf<br \/>\n# vi \/etc\/squid\/squid.conf<\/strong><\/p>\n<div>http_port 3128<br \/>\nmaximum_object_size 4096 KB<br \/>\nminimum_object_size 0 KB<br \/>\nmaximum_object_size_in_memory 64 KB<br \/>\ncache_mem 60 MB<br \/>\npipeline_prefetch on<br \/>\nfqdncache_size 1024refresh_pattern ^ftp:\u00a0\u00a0\u00a0\u00a0\u00a0 1440\u00a0\u00a020%\u00a0\u00a0 10080<br \/>\nrefresh_pattern ^gopher:\u00a0\u00a0\u00a0\u00a01440\u00a0\u00a00%\u00a0\u00a0\u00a01440<br \/>\nrefresh_pattern -i (\/cgi-bin\/|\\?) 0\u00a0\u00a0 0%\u00a0\u00a0\u00a00<br \/>\nrefresh_pattern .\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 0\u00a0\u00a0\u00a0 20%\u00a0\u00a0 4320<\/p>\n<p>cache_swap_low 90<br \/>\ncache_swap_high 95<\/p>\n<p>access_log \/var\/log\/squid\/access.log squid<br \/>\ncache_log \/var\/log\/squid\/cache.log<br \/>\ncache_store_log \/var\/log\/squid\/store.log<br \/>\ncache_dir ufs \/var\/spool\/squid 100 16 256<\/p>\n<p>logfile_rotate 10<br \/>\nhosts_file \/etc\/hosts<\/p>\n<p>acl SSL_ports port 443<br \/>\nacl Safe_ports port 80\u00a0\u00a0\u00a0\u00a0\u00a0# http<br \/>\nacl Safe_ports port 21\u00a0\u00a0\u00a0\u00a0\u00a0# ftp<br \/>\nacl Safe_ports port 443\u00a0\u00a0\u00a0\u00a0\u00a0# https<br \/>\nacl Safe_ports port 70\u00a0\u00a0\u00a0\u00a0\u00a0# gopher<br \/>\nacl Safe_ports port 210\u00a0\u00a0\u00a0\u00a0\u00a0# wais<br \/>\nacl Safe_ports port 1025-65535\u00a0# unregistered ports<br \/>\nacl Safe_ports port 280\u00a0\u00a0\u00a0\u00a0\u00a0# http-mgmt<br \/>\nacl Safe_ports port 488\u00a0\u00a0\u00a0\u00a0\u00a0# gss-http<br \/>\nacl Safe_ports port 591\u00a0\u00a0\u00a0\u00a0\u00a0# filemaker<br \/>\nacl Safe_ports port 777\u00a0\u00a0\u00a0\u00a0\u00a0# multiling http<br \/>\nacl CONNECT method CONNECT<\/p>\n<p>acl localhost src 127.0.0.1\/32<br \/>\nhttp_access allow localhost<\/p>\n<p>http_access deny !Safe_ports<\/p>\n<p>http_access deny CONNECT !SSL_ports<\/p>\n<p>acl NOCACHE url_regex &#8220;\/etc\/squid\/regras\/nocache.lst&#8221; \\?<br \/>\nno_cache deny NOCACHE<\/p>\n<p>auth_param ntlm program \/usr\/bin\/ntlm_auth &#8211;helper-protocol=squid-2.5-ntlmssp<br \/>\nauth_param ntlm children 30<\/p>\n<p>auth_param basic program \/usr\/bin\/ntlm_auth &#8211;helper-protocol=squid-2.5-basic<br \/>\nauth_param basic children 5<br \/>\nauth_param basic realm Squid proxy server<br \/>\nauth_param basic credentialsttl 2 hours<\/p>\n<p>acl autenticados proxy_auth REQUIRED<\/p>\n<p>redirect_program \/usr\/bin\/squidGuard -c \/etc\/squid\/squidGuard.conf<br \/>\nredirect_children 10<\/p>\n<p>http_access allow autenticados<br \/>\nhttp_access deny all<br \/>\nhttp_reply_access allow all<br \/>\nicp_access allow all<br \/>\nmiss_access allow all<\/p>\n<p>visible_hostname proxyauth.palacio.local<br \/>\nerror_directory \/usr\/share\/squid\/errors\/pt-br<\/p>\n<p>cache_effective_user squid<br \/>\ncoredump_dir \/var\/spool\/squid<\/p>\n<p>########\u00a0CONTROLE DE BANDA ############<br \/>\nacl Acesso_Rapido url_regex -i \\.(aspx?|css|jsp?|[js]?html?|rss|php|xml|txt|gif|jpe?g|png)$<br \/>\nacl Banda_Livre arp &#8220;\/etc\/squid\/acls\/Banda_Livre.lst&#8221;<\/p>\n<p>delay_pools 2<br \/>\ndelay_class 1 2<br \/>\ndelay_parameters 1 -1\/-1 -1\/-1 -1\/-1<br \/>\ndelay_access 1 allow Banda_Livre<\/p>\n<p>delay_class 2 2<br \/>\ndelay_parameters 2 614400\/614400\u00a061920\/619200\u00a0# Navegar a 60k<br \/>\ndelay_access 2 allow rede_local !Acesso_Rapido<\/p>\n<\/div>\n<p>Criando a pasta de cache:<\/p>\n<p><strong># mkdir \/etc\/squid\/cache<br \/>\n# mkdir -p \/etc\/squid\/cache\/1<br \/>\n# chown squid:squid -R \/etc\/squid\/cache\/<br \/>\n# service squid start<\/strong><\/p>\n<p>Inicializa\u00e7\u00e3o autom\u00e1tica do Squid:<\/p>\n<p><strong># chkconfig squid on<\/strong><\/p>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td colspan=\"2\"><b>Configurando o SquidGuard<\/b><\/p>\n<div><strong># vi \/etc\/squid\/squidGuard.conf<\/strong><\/p>\n<div># Diretorio das Listas de Bloqueiodbhome \/var\/squidGuard\/db<br \/>\nlogdir \/var\/log\/squidGuard<\/p>\n<p># Autenticacao LDAP<\/p>\n<p>ldapbinddn\u00a0\u00a0 cn=squid,ou=INTERNET,dc=palacio,dc=local<br \/>\nldapbindpass\u00a0 password<br \/>\nldapcachetime\u00a060<\/p>\n<p># Grupos de Bloqueio<\/p>\n<p>src ACESSOLIVRE {<br \/>\nldapusersearch ldap:\/\/192.168.100.11:3268\/dc=palacio,dc=local?sAMAccountName?sub?(&amp;(sAMAccountName=%s)(memberOf=CN=ACESSOLIVRE%2cou=INTERNET%2cdc=palacio%2cdc=local))<br \/>\n}<\/p>\n<p>src ACESSOREDESSOCIAIS {<br \/>\nldapusersearch ldap:\/\/192.168.100.11:3268\/dc=palacio,dc=local?sAMAccountName?sub?(&amp;(sAMAccountName=%s)(memberOf=CN=ACESSOREDESSOCIAIS%2cou=INTERNET%2cdc=palacio%2cdc=local))<br \/>\n}<\/p>\n<p>src ACESSOVIDEOS {<br \/>\nldapusersearch ldap:\/\/192.168.100.11:3268\/dc=palacio,dc=local?sAMAccountName?sub?(&amp;(sAMAccountName=%s)(memberOf=CN=ACESSOVIDEOS%2cou=INTERNET%2cdc=palacio%2cdc=local))<br \/>\n}<\/p>\n<p>## Listas de Bloqueio ( Filtragem ) Usando duas listas Bigblaclist e Shallalist<\/p>\n<p># Big Blacklist<\/p>\n<p>dest porn {<br \/>\ndomainlist\u00a0\u00a0\u00a0blacklists\/porn\/domains<br \/>\nurllist\u00a0\u00a0\u00a0\u00a0 blacklists\/porn\/urls<br \/>\n#\u00a0\u00a0\u00a0 expessionlist\u00a0 blacklists\/porn\/expressions<br \/>\n}<\/p>\n<p>dest audio-video {<br \/>\ndomainlist\u00a0\u00a0\u00a0blacklists\/audio-video\/domains<br \/>\nurllist\u00a0\u00a0\u00a0\u00a0 blacklists\/audio-video\/urls<br \/>\n}<\/p>\n<p># Shallalist<\/p>\n<p>dest porn2 {<br \/>\ndomainlist\u00a0\u00a0\u00a0BL\/porn\/domains<br \/>\nurllist\u00a0\u00a0\u00a0\u00a0 BL\/porn\/urls<br \/>\n}<\/p>\n<p>dest socialnet {<br \/>\ndomainlist\u00a0\u00a0\u00a0BL\/socialnet\/domains<br \/>\nurllist\u00a0\u00a0\u00a0\u00a0 BL\/socialnet\/urls<br \/>\n}<\/p>\n<p># Controle de Acessos ( ACLs )<\/p>\n<p>acl\u00a0\u00a0 {<\/p>\n<p>ACESSOLIVRE\u00a0{<br \/>\npass !porn !porn2<br \/>\n}<\/p>\n<p>ACESSOREDESSOCIAIS\u00a0{<br \/>\npass socialnet !porn !porn2 !audio-video<br \/>\n}<\/p>\n<p>ACESSOVIDEOS {<br \/>\npass audio-video !porn !porn2 !socialnet<br \/>\n}<\/p>\n<p>default {<br \/>\npass !porn !porn2 !socialnet !audio-video<br \/>\nredirect http:\/\/192.168.100.16\/cgi-bin\/squidGuard-simple.cgi?clientaddr=%a&amp;clientname=%n&amp;clientuser=%i&amp;clientgroup=%s&amp;targetgroup=%t&amp;url=%u<br \/>\n}<br \/>\n}<\/p>\n<\/div>\n<p>Baixe as listas dentro do diret\u00f3rio\u00a0<span>\/var\/squidGuard\/db<\/span>, eu, particularmente, uso as duas listas abaixo:<\/p>\n<ul>\n<li>Shalla&#8217;s Blacklists ::\u00a0<a href=\"http:\/\/www.shallalist.de\/\">http:\/\/www.shallalist.de\/<\/a><\/li>\n<li>URLBlacklist ::\u00a0<a href=\"http:\/\/urlblacklist.com\/?sec=download\">http:\/\/urlblacklist.com\/?sec=download<\/a><\/li>\n<\/ul>\n<p>Descompacte:<\/p>\n<p><strong># tar -zxvf bigblacklist.tar.gz<br \/>\n# tar -zxvf shallalist.tar.gz<\/strong><\/p>\n<p>Criar os bancos:<\/p>\n<p><strong># squidGuard -b -u -C all<\/strong><\/p>\n<p>Monitorar os logs do SquidGuard:<\/p>\n<p><strong># tail -f \/var\/log\/squidGuard\/squidGuard.log<\/strong><\/p>\n<p>Ap\u00f3s completar o processo (que, dependendo da quantidade de listas, pode demorar um pouco), vamos dar as permiss\u00f5es devidas:<\/p>\n<p><strong># chown -R squid:squid \/var\/squidGuard\/db\/*<br \/>\n# find \/var\/squidGuard\/db -type f | xargs chmod 644<br \/>\n# find \/var\/squidGuard\/db -type d | xargs chmod 755<br \/>\n# squid -k reconfigure<\/strong><\/p>\n<p>Criando uma\u00a0<span>whitelist<\/span>\u00a0autorizando o acesso aos sites manualmente:<\/p>\n<p>Adicione uma nova ACL:<\/p>\n<p><strong># vi \/etc\/squid\/squidGuard.conf<\/strong><\/p>\n<div>dest white {<br \/>\ndomainlist white\/domains<br \/>\nurllist white\/urls<br \/>\n}default {<br \/>\npass white !porn !porn2 !socialnet !audio-video<br \/>\nredirect http:\/\/192.168.100.16\/cgi-bin\/squidGuard-simple.cgi?clientaddr=%a&amp;clientname=%n&amp;clientuser=%i&amp;clientgroup=%s&amp;targetgroup=%t&amp;url=%u<br \/>\n}<br \/>\n}<\/p>\n<\/div>\n<p>A ACL\u00a0<span>white<\/span>\u00a0ser\u00e1 lida primeiro e o acesso \u00e0s p\u00e1ginas especificadas no arquivo ser\u00e1 liberado.<\/p>\n<p>Criar a pasta e os arquivos:<\/p>\n<p><strong># mkdir \/var\/lib\/squidguard\/db\/white<br \/>\n# touch \/var\/lib\/squidguard\/db\/white\/domains<br \/>\n# touch \/var\/lib\/squidguard\/db\/white\/urls<\/strong><\/p>\n<p>Onde:<\/p>\n<ul>\n<li>Arquivo\u00a0<span>domains<\/span>\u00a0para dom\u00ednios liberados por completo. Exemplo: &#8220;google.com.br&#8221;.<\/li>\n<li>Arquivo\u00a0<span>urls<\/span>\u00a0para p\u00e1ginas. Exemplo: &#8220;vivaolinux.com.br\/contribuir\/artigo\/&#8221;, sempre um por linha.<\/li>\n<\/ul>\n<p>Obs.: em qualquer altera\u00e7\u00e3o feita nos arquivos\u00a0<span>dbs<\/span>, se faz necess\u00e1rio atualizar a convers\u00e3o das listas e reiniciar o Squid:<\/p>\n<p><strong># chown -R squid:squid \/var\/squidGuard\/db\/*<br \/>\n# find \/var\/squidGuard\/db -type f | xargs chmod 644<br \/>\n# find \/var\/squidGuard\/db -type d | xargs chmod 755<br \/>\n# squidGuard -b -u -C all<br \/>\n# squid -k reconfigure<\/strong><\/p>\n<\/div>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n","protected":false},"excerpt":{"rendered":"<p>Configura\u00e7\u00f5es iniciais Instalando reposit\u00f3rios:# rpm -Uvh http:\/\/fedora.uib.no\/epel\/6\/i386\/epel-release-6-8.noarch.rpm # yum clean all # yum -y update Desativando o Firewall e o SELinux: # chkconfig iptables off # chkconfig ip6tables off # setenforce 0 # vi \/etc\/selinux\/config \u00a0selinux=disabled\u00a0 Instalando depend\u00eancias e pacotes necess\u00e1rios: # yum -y install flex bison squid squidGuard samba samba-client samba-common samba-winbind pam_krb5 bind-utils [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"var(--ast-global-color-4)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[455,1,42,51,68,271,111],"tags":[535,98,536,537,539,538,87,86],"class_list":["post-797","post","type-post","status-publish","format-standard","hentry","category-apache2","category-viazap","category-leitura-recomendada","category-linux-linuxrs","category-redes-2","category-seguranca-2","category-squid-2","tag-com-squidguard","tag-controle","tag-de-banda","tag-e-autenticacao","tag-no-samba-4","tag-ntlm","tag-proxy-2","tag-squid"],"_links":{"self":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/797","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=797"}],"version-history":[{"count":2,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/797\/revisions"}],"predecessor-version":[{"id":799,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=\/wp\/v2\/posts\/797\/revisions\/799"}],"wp:attachment":[{"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=797"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=797"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.clusterweb.com.br\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=797"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}