[squid-users] Correct order of acl rules?

Walter H. Walter.H at mathemainzel.info
Fri Feb 6 20:06:57 UTC 2015


On 06.02.2015 20:38, Amos Jeffries wrote:
> On 7/02/2015 8:27 a.m., Amos Jeffries wrote:
>> On 7/02/2015 8:19 a.m., Walter H. wrote:
>>> the file blockurls-regex-acl.squid
>>> contains e.g.
>>> ^http:\/\/s[0-9]\.domain\.tld\/
>>>
>>> the file allowurls-regex-acl.squid
>>> contains e.g.
>>> ^http:\/\/s[1-2]+\.domain\.tld\/[a-z0-9\_\-\.]+\.gif
>>>
>>> the purpose should be, that only gif images of root directory of only
>>> the subdomains beginning with s1 or s2 of domain.tld should be allowed
> Also, NO that is not what your rules do. Take another look at all the
> sub-domains s[1-2]+ will match against...
>
> s1, s2,
> s11, s12, s21, s22,
> s111, s112, s121, s122, s211, s212, s221, s222,
> s1111 ...
> ...
>
>
of, course my mistake ...
>>> the following url is blocked
>>>
>>> http://s2443.domain.tld/ghfhfhf.gif
>>>
>>> why?
>> "4" != "\."
>>
thats right ...

should the following be allowed or blocked?
http://s1.domain.tld/file.gif
http://s2.domain.tld/file.gif

I'd say the must be allowed ...

Greetings,
Walter

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 5971 bytes
Desc: S/MIME Cryptographic Signature
URL: <http://lists.squid-cache.org/pipermail/squid-users/attachments/20150206/39ab245c/attachment.bin>


More information about the squid-users mailing list