配置squid服務

來源:互聯網
上載者:User

配置squid服務

第二十一章配置squid服務

【什麼是squid】

Squid是比較知名的代理軟體,它不僅可以跑在linux上還可以跑在windows以及Unix上,它的技術已經非常成熟。目前使用Squid的使用者也是十分廣泛的。Squid與Linux下其它的代理軟體如Apache、Socks、TIS FWTK和delegate相比,下載安裝簡單,配置簡單靈活,支援緩衝和多種協議。

Squid的緩衝功能相當好用,不僅可以減少頻寬的佔用,同樣也大大降低了背景WEB伺服器的磁碟I/O的壓力。Squid接收使用者的下載申請,並自動處理所下載的資料。也就是說,當一個使用者象要下載一個首頁時,它向Squid發出一個申請,要Squid替它下載,然後Squid 串連所申請網站並請求該首頁,接著把該首頁傳給使用者同時保留一個備份,當別的使用者申請同樣的頁面時,Squid把儲存的備份立即傳給使用者,使使用者覺得速度相當快。

Squid將資料元緩衝在記憶體中,同時也緩衝DNS查尋的結果,除此之外,它還支援非模組化的DNS查詢,對失敗的請求進行消極緩衝。Squid支援SSL,支援存取控制。由於使用了ICP,Squid能夠實現重疊的代理陣列,從而最大限度的節約頻寬。

Squid對硬體的要求是記憶體一定要大,不應小於128M,硬碟轉速越快越好,最好使用伺服器專用SCSI 硬碟,處理器要求不高,400MH以上既可。

【安裝squid】

wget http://www.squid-cache.org/Versions/v2/2.6/squid-2.6.STABLE20.tar.gz

tar zxvf squid-2.6.STABLE20.tar.gz

cd squid-2.6.STABLE20
ulimit -HSn 65535

useradd squid
編譯參數
./configure --prefix=/usr/local/squid \
--disable-dependency-tracking \
--enable-dlmalloc \
--enable-gnuregex \
--disable-carp \
--enable-async-io=240 \
--with-pthreads \
--enable-storeio=ufs,aufs,diskd,null \
--disable-wccp \
--disable-wccpv2 \
--enable-kill-parent-hack \
--enable-cachemgr-hostname=localhost \
--enable-default-err-language=Simplify_Chinese \
--with-build-environment=POSIX_V6_ILP32_OFFBIG \
--with-maxfd=65535 \
--with-aio \
--disable-poll \
--enable-epoll \
--enable-linux-netfilter \
--enable-large-cache-files \
--disable-ident-lookups \
--enable-default-hostsfile=/etc/hosts \
--with-dl \
--with-large-files \
--enable-removal-policies=heap,lru \
--enable-delay-pools \
--enable-snmp \
--disable-internal-dns

make && make install

關於squid的版本,有必要提一下,目前squid最新版本已經到了3.1了,但是筆者認為2.6版本比較好用,如果你有興趣可以研究一下3.1。

【squid配置】

編輯設定檔 /usr/local/squid/etc/squid.conf

把原來設定檔刪除,替換成:

http_port 80 transparent

cache_replacement_policy lru #如果有多個(下面兩行)緩衝目錄,則需要寫這個參數
cache_dir aufs /cache1 8192 16 256 #緩衝目錄1 /cache1 大小為8G
cache_dir aufs /cache2 4096 16 256 #緩衝目錄2 /cache2 大小為4G

## 上面兩行定義了緩衝目錄,這個緩衝目錄可以只有一個,也可以定義很多個。
cache_mem 2048 MB #分配多少記憶體給squid,建議留至少512M給系統,如果你是虛擬機器記憶體很小,只作為實驗用的話,那就分一半記憶體給squid
maximum_object_size 2048 KB #緩衝的檔案最大不能超過2M
maximum_object_size_in_memory 512 KB #緩衝在記憶體中的檔案最大不超過512k
visible_hostname cache.example.com #顯示給使用者的主機名稱
client_persistent_connections off #client端關閉長串連
server_persistent_connections on #server端開啟長串連
memory_pools on
memory_pools_limit 1024 MB
forwarded_for on
log_icp_queries off
cache_mgr cache@example.com #定義管理員的mail為cache@example.com
via on
httpd_suppress_version_string off
cache_effective_user squid #定義以squid使用者的身份運行squid
cache_effective_group squid
error_directory /usr/local/squid/share/errors/Simplify_Chinese
icon_directory /usr/local/squid/share/icons
mime_table /usr/local/squid/etc/mime.conf
ie_refresh off
tcp_recv_bufsize 32 KB

acl all src 0.0.0.0/0.0.0.0
acl localhost src 127.0.0.0/8
acl Mgr_ip src 127.0.0.0/8
acl allow_ip dst 127.0.0.0/8 192.168.0.0/16 #定義允許代理的web的IP或者IP段
acl PURGE method PURGE
acl Safe_ports port 80 8080
acl CONNECT method CONNECT
acl manager proto cache_object
acl HTTP proto HTTP

http_access allow allow_ip
http_access allow manager Mgr_ip
http_access deny manager
http_access deny PURGE
http_access deny !Safe_ports
http_access deny all
icp_access deny all
ipcache_size 1024
ipcache_low 90
ipcache_high 95
memory_replacement_policy lru
hosts_file /etc/hosts
request_header_max_size 128 KB
hierarchy_stoplist cgi-bin ? \.php \.html
acl QUERY urlpath_regex cgi-bin \? \.php \.html
cache deny QUERY
quick_abort_min -1 KB
quick_abort_max 32 KB
quick_abort_pct 95
# error page
#error_map http://www.92csz.com/404.html 403
#deny_info http://www.92csz.com/error.html cctv_Domain
# timeout
peer_connect_timeout 20 seconds
connect_timeout 20 seconds
read_timeout 60 seconds
request_timeout 20 seconds
pconn_timeout 20 seconds
shutdown_lifetime 5 seconds
strip_query_terms off
icp_port 0
# logfile
emulate_httpd_log on
logformat combined %>a %ui %un [%tl] "%rm %ru HTTP/%rv" %Hs %#access_log /log/squid-log/access.log combined
cache_store_log /dev/null
cache_log /var/log/squid/cache.log
logfile_rotate 12
# MISCELLANEOUS
store_objects_per_bucket 15
client_db off

修改完設定檔後儲存,然後初始化squid

mkdir /cache1 /cache2 /var/log/squid

chown -R squid:squid /cache1 /cache2 /var/log/squid

/usr/local/squid/sbin/squid -z

# 用來產生cache目錄,如果你的設定檔配置出錯,往往會在初始化的時候報錯,錯誤資訊會直接顯示在螢幕上。初始化成功後,就可以啟動squid了,啟動命令為:

nohup /usr/local/squid/bin/RunCache &

啟動後,可以去看看cache.log 在這個日誌中,你可以看到很多關於squid的資訊,當然也包括一些錯誤記錄檔。

如果想開機啟動則需要在/etc/rc.d/rc.local中最後加入一行

/usr/local/bin/RunCache &

到這裡算是配置完成了,但是還有一個問題,就是如何定義被代理的web以及網域名稱?單單看設定檔並沒有說代理的web是哪一個。確實,這個設定檔其實可以代理多台web,只要你在/etc/hosts中定義要代理的網域名稱以及IP即可,hosts格式在前面已經介紹過。筆者要提醒你的是,如果是一台web上的多個網域名稱,請不要寫一行,雖然hosts是允許的,但是如果寫成一個IP對應多個網域名稱,squid代理時就會出錯。所以有幾個網域名稱就要寫幾行。

更改/etc/hosts後要重啟squid才會生效:

/usr/local/squid/sbin/squid -krec

在重啟前可以先檢測一下,是否有錯,命令為:

/usr/local/squid/sbin/squid –kcheck

如果沒有錯,則不會顯示任何資訊,否則會顯示一些資訊出來。

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.