<html><head></head><body><div style="color:#000; background-color:#fff; font-family:Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif;font-size:16px"><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31274"><span style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;" id="yui_3_16_0_ym19_1_1493932418810_31188">> acl From_Source_Domains srcdomain domain1 domain2 domain3</span><br clear="none" style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;" id="yui_3_16_0_ym19_1_1493932418810_31189"><span style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;" id="yui_3_16_0_ym19_1_1493932418810_31190">> acl To_Destination_Domains dstdomain domain4 domain5 domain6</span><span></span></div><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31264"><span style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;"><br></span></div><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31263"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31217">if:</span><br clear="none" style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31218"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31219">> http_access allow From_Source_Domains</span><br clear="none" style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31220"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31221">or, if:</span><br clear="none" style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31222"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31223">> http_access allow To_Destination_Domains</span><br clear="none" style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31224"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;" id="yui_3_16_0_ym19_1_1493932418810_31225">or, deny all</span><span style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;"><br></span></div><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31266"><span style="font-family: HelveticaNeue, "Helvetica Neue", Helvetica, Arial, "Lucida Grande", sans-serif;"><br></span></div><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31268"><font face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif" id="yui_3_16_0_ym19_1_1493932418810_31479">According to your answer, if these are ORed, first http_access should allow connection to everywhere from  </font><span style="font-family: "Helvetica Neue", "Segoe UI", Helvetica, Arial, "Lucida Grande", sans-serif; font-size: 13px;" id="yui_3_16_0_ym19_1_1493932418810_31482">domain1,domain2,domain3</span></div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173" dir="ltr">Second http_access allow connections to from everywhere.</div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173" dir="ltr"><br></div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173" dir="ltr"><br><font face="HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif" id="yui_3_16_0_ym19_1_1493932418810_31565">Is above statement correct ?</font></div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173" dir="ltr"><br></div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173" dir="ltr"><br></div><div class="qtdSeparateBR" id="yui_3_16_0_ym19_1_1493932418810_31173"><br></div><div class="yahoo_quoted" id="yui_3_16_0_ym19_1_1493932418810_31177" style="display: block;">  <div style="font-family: Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;" id="yui_3_16_0_ym19_1_1493932418810_31176"> <div style="font-family: HelveticaNeue, Helvetica Neue, Helvetica, Arial, Lucida Grande, sans-serif; font-size: 16px;" id="yui_3_16_0_ym19_1_1493932418810_31175"> <div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31174"> <font size="2" face="Arial" id="yui_3_16_0_ym19_1_1493932418810_31181"> <hr size="1" id="yui_3_16_0_ym19_1_1493932418810_31198"> <b><span style="font-weight:bold;">From:</span></b> Amos Jeffries <squid3@treenet.co.nz><br> <b><span style="font-weight: bold;">To:</span></b> "squid-users@lists.squid-cache.org" <squid-users@lists.squid-cache.org> <br> <b><span style="font-weight: bold;">Sent:</span></b> Thursday, May 4, 2017 11:12 PM<br> <b id="yui_3_16_0_ym19_1_1493932418810_31551"><span style="font-weight: bold;" id="yui_3_16_0_ym19_1_1493932418810_31550">Subject:</span></b> Re: [squid-users] limit access with acl only based on source and destination domain<br> </font> </div> <div class="y_msg_container" id="yui_3_16_0_ym19_1_1493932418810_31191"><br><div dir="ltr" id="yui_3_16_0_ym19_1_1493932418810_31192">On 05/05/17 15:47, Blaxton wrote:<br clear="none">> What is the difference between :<br clear="none"><br clear="none">That is documented in <br clear="none"><<a shape="rect" href="http://wiki.squid-cache.org/SquidFaq/SquidAcl#Common_Mistakes" target="_blank" id="yui_3_16_0_ym19_1_1493932418810_31193">http://wiki.squid-cache.org/SquidFaq/SquidAcl#Common_Mistakes</a>><br clear="none"><br clear="none"><br clear="none">if:<br clear="none">> http_access allow From_Source_Domains<br clear="none">or, if:<br clear="none">> http_access allow To_Destination_Domains<br clear="none">or, deny all<br clear="none"><br clear="none"><br clear="none">versus ...<br clear="none"><br clear="none">if:<br clear="none">> http_access allow From_Source_Domains To_Destination_Domains<br clear="none">or, deny all.<div class="yqt3014967334" id="yqtfd85239"><br clear="none"><br clear="none"><br clear="none"><br clear="none">Amos<br clear="none">_______________________________________________<br clear="none">squid-users mailing list<br clear="none"><a shape="rect" ymailto="mailto:squid-users@lists.squid-cache.org" href="mailto:squid-users@lists.squid-cache.org">squid-users@lists.squid-cache.org</a><br clear="none"><a shape="rect" href="http://lists.squid-cache.org/listinfo/squid-users" target="_blank">http://lists.squid-cache.org/listinfo/squid-users</a><br clear="none"></div></div><br><br></div> </div> </div>  </div></div></body></html>