Publicada por wellingtonpg em 17/05/2007 - 12:24h:
* wellingtonpg usa Mandrake

Estou tendo problema com meu squid. Ele está muito lento.
Alguem poderia me dar uma ajuda?
Aqui está toda a conf da criança.

# NETWORK OPTIONS
# -----------------------------------------------------------------------------

# TAG: http_port
#Default:
http_port 3128 8080

# TAG: https_port
#
#Default:
# none

# TAG: ssl_unclean_shutdown
#
#Default:
# ssl_unclean_shutdown off

# TAG: icp_port
#
#Default:
# icp_port 3130

# TAG: htcp_port
#
#Default:
# htcp_port 4827

# TAG: mcast_groups
#
#Default:
# none

# TAG: udp_incoming_address
# TAG: udp_outgoing_address
#
#Default:
# udp_incoming_address 0.0.0.0
# udp_outgoing_address 255.255.255.255


# OPTIONS WHICH AFFECT THE NEIGHBOR SELECTION ALGORITHM
# -----------------------------------------------------------------------------

# TAG: cache_peer
#
#Default:
# none

# TAG: cache_peer_domain
#
#Default:
# none

# TAG: neighbor_type_domain
#
#Default:
# none

# TAG: icp_query_timeout   (msec)
#
#Default:
# icp_query_timeout 0

# TAG: maximum_icp_query_timeout   (msec)
#
#Default:
# maximum_icp_query_timeout 2000

# TAG: mcast_icp_query_timeout   (msec)
#
#Default:
# mcast_icp_query_timeout 2000

# TAG: dead_peer_timeout   (seconds)
#
#Default:
# dead_peer_timeout 10 seconds

# TAG: hierarchy_stoplist
hierarchy_stoplist cgi-bin ?

# TAG: no_cache
acl QUERY urlpath_regex cgi-bin ?
no_cache deny QUERY


# OPTIONS WHICH AFFECT THE CACHE SIZE
# -----------------------------------------------------------------------------

# TAG: cache_mem   (bytes)
#
#Default:
cache_mem 16 MB

# TAG: cache_swap_low   (percent, 0-100)
# TAG: cache_swap_high   (percent, 0-100)
#
#Default:
cache_swap_low 90
cache_swap_high 95

# TAG: maximum_object_size   (bytes)
#
#Default:
maximum_object_size 4096 KB

# TAG: minimum_object_size   (bytes)
#
#Default:
# minimum_object_size 0 KB

# TAG: maximum_object_size_in_memory   (bytes)
#
#Default:
maximum_object_size_in_memory 8 KB

# TAG: ipcache_size   (number of entries)
# TAG: ipcache_low   (percent)
# TAG: ipcache_high   (percent)
#   The size, low-, and high-water marks for the IP cache.
#
#Default:
# ipcache_size 1024
# ipcache_low 90
# ipcache_high 95

# TAG: fqdncache_size   (number of entries)
#
#Default:
# fqdncache_size 1024

# TAG: cache_replacement_policy
#
#Default:
# cache_replacement_policy lru

# TAG: memory_replacement_policy
#   The memory replacement policy parameter determines which
#   objects are purged from memory when memory space is needed.
#
#   See cache_replacement_policy for details.
#
#Default:
# memory_replacement_policy lru


# LOGFILE PATHNAMES AND CACHE DIRECTORIES
# -----------------------------------------------------------------------------

# TAG: cache_dir
#Default:
cache_dir ufs /var/spool/squid 100 16 256

# TAG: cache_access_log
#Default:
cache_access_log /var/log/squid/access.log

# TAG: cache_log
#Default:
cache_log /var/log/squid/cache.log

# TAG: cache_store_log
#Default:
cache_store_log /var/log/squid/store.log

# TAG: cache_swap_log
#Default:
# none

# TAG: emulate_httpd_log   on|off
#Default:
# emulate_httpd_log off

# TAG: log_ip_on_direct   on|off
#Default:
# log_ip_on_direct on

# TAG: mime_table
#Default:
# mime_table /etc/squid/mime.conf

# TAG: log_mime_hdrs   on|off
#Default:
# log_mime_hdrs off

# TAG: useragent_log
#Default:
# none

# TAG: referer_log
#Default:
# none

# TAG: pid_filename
#Default:
# debug_options ALL,1

# TAG: log_fqdn   on|off
#Default:
# log_fqdn off

# TAG: client_netmask
#Default:
# client_netmask 255.255.255.255


# OPTIONS FOR EXTERNAL SUPPORT PROGRAMS
# -----------------------------------------------------------------------------

# TAG: ftp_user
#Default:
# ftp_user Squid@

# TAG: ftp_list_width
#Default:
# ftp_list_width 32

# TAG: ftp_passive
#Default:
# ftp_passive on

# TAG: ftp_sanitycheck
#Default:
# ftp_sanitycheck on

# TAG: cache_dns_program
#Default:
# cache_dns_program /usr/lib/squid/dnsserver

# TAG: dns_children
#Default:
# dns_children 5

# TAG: dns_retransmit_interval
#Default:
# dns_retransmit_interval 5 seconds

# TAG: dns_timeout
#Default:
# dns_timeout 5 minutes

# TAG: dns_defnames   on|off
#Default:
# dns_defnames off

# TAG: dns_nameservers
#Default:
# none

# TAG: hosts_file
#Default:
# hosts_file /etc/hosts

# TAG: diskd_program
#Default:
# diskd_program /usr/lib/squid/diskd

# TAG: unlinkd_program
#Default:
# unlinkd_program /usr/lib/squid/unlinkd

# TAG: pinger_program
#Default:
# pinger_program /usr/lib/squid/pinger

# TAG: redirect_program
#Default:
# none

# TAG: redirect_children
#Default:
# redirect_children 5

# TAG: redirect_rewrites_host_header
#Default:
# redirect_rewrites_host_header on

# TAG: redirector_access
#Default:
# none

# TAG: auth_param
#Recommended minimum configuration:
#auth_param digest program <uncomment and complete this line>
#auth_param digest children 5
#auth_param digest realm Squid proxy-caching web server
#auth_param digest nonce_garbage_interval 5 minutes
#auth_param digest nonce_max_duration 30 minutes
#auth_param digest nonce_max_count 50
#auth_param ntlm program <uncomment and complete this line to activate>
#auth_param ntlm children 5
#auth_param ntlm max_challenge_reuses 0
#auth_param ntlm max_challenge_lifetime 2 minutes
#auth_param basic program <uncomment and complete this line>
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours

# TAG: authenticate_cache_garbage_interval
#Default:
# authenticate_cache_garbage_interval 1 hour

# TAG: authenticate_ttl
#Default:
# authenticate_ttl 1 hour

# TAG: authenticate_ip_ttl
#Default:
# authenticate_ip_ttl 0 seconds

# TAG: external_acl_type
#Default:
# none


# OPTIONS FOR TUNING THE CACHE
# -----------------------------------------------------------------------------

# TAG: wais_relay_host
# TAG: wais_relay_port
#Default:
# wais_relay_port 0

# TAG: request_header_max_size   (KB)
#Default:
# request_header_max_size 10 KB

# TAG: request_body_max_size   (KB)
#Default:
# request_body_max_size 0 KB

# TAG: refresh_pattern
#Suggested default:
refresh_pattern ^ftp:      1440   20%   10080
refresh_pattern ^gopher:   1440   0%   1440
refresh_pattern .      0   20%   4320

# TAG: quick_abort_min   (KB)
# TAG: quick_abort_max   (KB)
# TAG: quick_abort_pct   (percent)
#Default:
# quick_abort_min 16 KB
# quick_abort_max 16 KB
# quick_abort_pct 95

# TAG: negative_ttl   time-units
#Default:
# negative_ttl 5 minutes

# TAG: positive_dns_ttl   time-units
#Default:
# positive_dns_ttl 6 hours

# TAG: negative_dns_ttl   time-units
#Default:
# negative_dns_ttl 5 minutes

# TAG: range_offset_limit   (bytes)
#Default:
# range_offset_limit 0 KB


# TIMEOUTS
# -----------------------------------------------------------------------------

#Default:
# connect_timeout 2 minutes

# TAG: peer_connect_timeout   time-units
#Default:
# peer_connect_timeout 30 seconds

# TAG: read_timeout   time-units
#Default:
#Default:
# request_timeout 5 minutes

# TAG: persistent_request_timeout
#Default:
# persistent_request_timeout 1 minute

# TAG: client_lifetime   time-units
#Default:
# client_lifetime 1 day

# TAG: half_closed_clients
#Default:
# half_closed_clients on

# TAG: pconn_timeout
#Default:
# pconn_timeout 120 seconds

# TAG: ident_timeout
#Default:
# ident_timeout 10 seconds

# TAG: shutdown_lifetime   time-units
#Default:
# shutdown_lifetime 30 seconds


# ACCESS CONTROLS
# -----------------------------------------------------------------------------

# TAG: acl
#Recommended minimum configuration:
#acl all src 0.0.0.0/0.0.0.0
#acl manager proto cache_object
#acl localhost src 127.0.0.1/255.255.255.255
#acl to_localhost dst 127.0.0.0/8
#acl SSL_ports port 443 563
#acl Safe_ports port 80      # http
#acl Safe_ports port 21      # ftp
#acl Safe_ports port 443 563   # https, snews
#acl Safe_ports port 70      # gopher
#acl Safe_ports port 210      # wais
#acl Safe_ports port 1025-65535   # unregistered ports
#acl Safe_ports port 280      # http-mgmt
#acl Safe_ports port 488      # gss-http
#acl Safe_ports port 591      # filemaker
#acl Safe_ports port 777      # multiling http
#acl CONNECT method CONNECT
#########################################################################
#acl fileupload req_mime_type -i ^multipart/form-data$
#acl javascript rep_mime_type -i ^application/x-javascript$
#
#Recommended minimum configuration:
acl all src 10.0.0.0/24
acl all src 192.168.0.0/24
acl blockedsites url_regex -i ./etc/squid/sitesblock.txt.
acl unblockedsites url_regex -i ./etc/squid/sitesunblock.txt.
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80 # http
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT



# TAG: http_access
#Default:
#http_access deny all
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access deny blockedsites !unblockedsites
http_access allow all

# TAG: http_reply_access
#Default:
# http_reply_access allow all
http_reply_access allow all

# TAG: icp_access
# icp_access deny all
icp_access allow all

# TAG: miss_access
#Default setting:
# miss_access allow all

# TAG: cache_peer_access
#Default:
# none

# TAG: ident_lookup_access
#Default:
# ident_lookup_access deny all

# TAG: tcp_outgoing_tos
#Default:
# none

# TAG: tcp_outgoing_address
#Default:
# none

# TAG: reply_body_max_size   bytes allow|deny acl acl...
#Default:
# reply_body_max_size 0 allow all


# ADMINISTRATIVE PARAMETERS
# -----------------------------------------------------------------------------

# TAG: cache_mgr
#Default:
# cache_mgr root

# TAG: cache_effective_user
# TAG: cache_effective_group
#
#Default:
cache_effective_user squid
cache_effective_group squid

# TAG: visible_hostname
#Default:
visible_hostname ConetBrasil

# TAG: unique_hostname
#Default:
# none

# TAG: hostname_aliases
#Default:
# none


# OPTIONS FOR THE CACHE REGISTRATION SERVICE
# -----------------------------------------------------------------------------

# TAG: announce_period
#Default:
# announce_period 0

# TAG: announce_host
# TAG: announce_file
# TAG: announce_port
#Default:
# announce_host tracker.ircache.net
# announce_port 3131


# HTTPD-ACCELERATOR OPTIONS
# -----------------------------------------------------------------------------

# TAG: httpd_accel_host
# TAG: httpd_accel_port
#Default:
httpd_accel_host virtual
httpd_accel_port 80

# TAG: httpd_accel_single_host   on|off
#Default:
httpd_accel_single_host on

# TAG: httpd_accel_with_proxy   on|off
#Default:
httpd_accel_with_proxy on

# TAG: httpd_accel_uses_host_header   on|off
#Default:
httpd_accel_uses_host_header on


# MISCELLANEOUS
# -----------------------------------------------------------------------------

# TAG: dns_testnames
#Default:
# dns_testnames netscape.com internic.net nlanr.net microsoft.com

# TAG: logfile_rotate
#Default:
# logfile_rotate 0

# TAG: append_domain
#Example:
# append_domain .yourdomain.com
#
#Default:
# none

# TAG: tcp_recv_bufsize   (bytes)
#Default:
# tcp_recv_bufsize 0 bytes

# TAG: err_html_text
#Default:
# none

# TAG: deny_info
#Default:
# none

# TAG: memory_pools   on|off
#Default:
# memory_pools on

# TAG: memory_pools_limit   (bytes)
#Default:
# none

# TAG: forwarded_for   on|off
#   If set, Squid will include your system's IP address or name
#   in the HTTP requests it forwards. By default it looks like
#   this:
#
#      X-Forwarded-For: 192.1.2.3
#
#   If you disable this, it will appear as
#
#      X-Forwarded-For: unknown
#
#Default:
# forwarded_for on

# TAG: log_icp_queries   on|off
#Default:
# log_icp_queries on

# TAG: icp_hit_stale   on|off
#Default:
# icp_hit_stale off

# TAG: minimum_direct_hops
#Default:
# minimum_direct_hops 4

# TAG: minimum_direct_rtt
#Default:
# minimum_direct_rtt 400

# TAG: cachemgr_passwd
#Example:
# cachemgr_passwd secret shutdown
# cachemgr_passwd lesssssssecret info stats/objects
# cachemgr_passwd disable all
#Default:
# none

# TAG: store_avg_object_size   (kbytes)
#Default:
# store_avg_object_size 13 KB

# TAG: store_objects_per_bucket
#Default:
# store_objects_per_bucket 20

# TAG: client_db   on|off
#Default:
# client_db on

# TAG: netdb_low
# TAG: netdb_high
#Default:
# netdb_low 900
# netdb_high 1000

# TAG: netdb_ping_period
#Default:
# netdb_ping_period 5 minutes

# TAG: query_icmp   on|off
#Default:
# query_icmp off

# TAG: test_reachability   on|off
#Default:
# test_reachability off

# TAG: buffered_logs   on|off
#Default:
# buffered_logs off

# TAG: reload_into_ims   on|off
#Default:
# reload_into_ims off

# TAG: always_direct
#Default:
# none

# TAG: never_direct
#Default:
# none

# TAG: header_access
#Default:
# none

# TAG: header_replace
#Default:
# none

# TAG: icon_directory
#Default:
# icon_directory /usr/lib/squid/icons

# TAG: error_directory
#error_directory /usr/lib/squid/errors/English
#Default:
error_directory /usr/lib/squid/errors/Portuguese

# TAG: maximum_single_addr_tries
#Default:
# maximum_single_addr_tries 3

# TAG: snmp_port
#Default:
# snmp_port 3401

# TAG: snmp_access
#Default:
# snmp_access deny all

# TAG: snmp_incoming_address
# TAG: snmp_outgoing_address
#Default:
# snmp_incoming_address 0.0.0.0
# snmp_outgoing_address 255.255.255.255

# TAG: as_whois_server
#Default:
# as_whois_server whois.ra.net
# as_whois_server whois.ra.net

# TAG: wccp_router
#Default:
# wccp_router 0.0.0.0

# TAG: wccp_version
#Default:
# wccp_version 4

# TAG: wccp_incoming_address
# TAG: wccp_outgoing_address
#Default:
# wccp_incoming_address 0.0.0.0
# wccp_outgoing_address 255.255.255.255


# DELAY POOL PARAMETERS (all require DELAY_POOLS compilation option)
# -----------------------------------------------------------------------------

# TAG: delay_pools
#Default:
# delay_pools 0

# TAG: delay_class
#Default:
# none

# TAG: delay_access
#Default:
# none

# TAG: delay_parameters
#Default:
# none

# TAG: delay_initial_bucket_level   (percent, 0-100)
#Default:
# delay_initial_bucket_level 50

# TAG: incoming_icp_average
# TAG: incoming_http_average
# TAG: incoming_dns_average
# TAG: min_icp_poll_cnt
# TAG: min_dns_poll_cnt
# TAG: min_http_poll_cnt
#Default:
# incoming_icp_average 6
# incoming_http_average 4
# incoming_dns_average 4
# min_icp_poll_cnt 8
# min_dns_poll_cnt 8
# min_http_poll_cnt 8

# TAG: max_open_disk_fds
#Default:
# max_open_disk_fds 0

# TAG: offline_mode
#Default:
# offline_mode off

# TAG: uri_whitespace
#Default:
# uri_whitespace strip

# TAG: broken_posts
#Default:
# none

# TAG: mcast_miss_addr
#Default:
# mcast_miss_addr 255.255.255.255

# TAG: mcast_miss_ttl
#Default:
# mcast_miss_ttl 16

# TAG: mcast_miss_port
#Default:
# mcast_miss_port 3135

# TAG: mcast_miss_encode_key
#Default:
# mcast_miss_encode_key XXXXXXXXXXXXXXXX

# TAG: nonhierarchical_direct
#Default:
# nonhierarchical_direct on

# TAG: prefer_direct
#Default:
# prefer_direct off

# TAG: strip_query_terms
#Default:
# strip_query_terms on

# TAG: coredump_dir
#Default:
# coredump_dir none
coredump_dir /var/spool/squid
#coredump_dir /etc/squid/cache


# TAG: redirector_bypass
#Default:
# redirector_bypass off

# TAG: ignore_unknown_nameservers
#Default:
# ignore_unknown_nameservers on

# TAG: digest_generation
#Default:
# digest_generation on

# TAG: digest_bits_per_entry
#Default:
# digest_bits_per_entry 5

# TAG: digest_rebuild_period   (seconds)
#Default:
# digest_rebuild_period 1 hour

# TAG: digest_rewrite_period   (seconds)
#Default:
# digest_rewrite_period 1 hour

# TAG: digest_swapout_chunk_size   (bytes)
#Default:
# digest_swapout_chunk_size 4096 bytes

# TAG: digest_rebuild_chunk_percentage   (percent, 0-100)
#Default:
# digest_rebuild_chunk_percentage 10

# TAG: chroot
#Default:
# none

# TAG: client_persistent_connections
# TAG: server_persistent_connections
#Default:
# client_persistent_connections on
# server_persistent_connections on

# TAG: pipeline_prefetch
#Default:
# pipeline_prefetch off

# TAG: extension_methods
#Default:
# none

# TAG: request_entities
#Default:
# request_entities off

# TAG: high_response_time_warning   (msec)
#Default:
# high_response_time_warning 0

# TAG: high_page_fault_warning
#Default:
# high_page_fault_warning 0

# TAG: high_memory_warning
#Default:
# high_memory_warning 0

# TAG: store_dir_select_algorithm
#Default:
# store_dir_select_algorithm least-load

# TAG: forward_log
#Default:
# none

# TAG: ie_refresh   on|off
#Default:
# ie_refresh off

# TAG: vary_ignore_expire   on|off
#Default:
# vary_ignore_expire off

# TAG: sleep_after_fork   (microseconds)
#Default:
# sleep_after_fork 0

  
 
Resposta de Felipe Domingos em 17/05/2007 - 13:12h:
* Felipe Domingos usa Slackware
* Felipe Domingos tem conceito: nenhum voto.
 


Cara na opção http_port logo no inicio, vc esta atendendo 2 portas 3128 e 8080 , é isso mesmo que vc quer ?
Além disso vc não nenhuma interface de rede exclusiva para atender o squid ?, poderia definir uma interface unica para atender as requisições.

Aqui tenho o squid+dansguardian como filtro e roda legal atendendo em média 600 usuarios...
então aqui fica assim:

http_port 127.0.0.1:3128

onde somente a maquina local tem acesso, e o dansguardian se encarrega de atender as requisições na porta 8080.

espero ter ajudado.

T+

 
Resposta de wellingtonpg em 17/05/2007 - 13:34h:
* wellingtonpg usa Mandrake
* wellingtonpg tem conceito: nenhum voto.
 


Legal.
Eu uso duas interfaces no Mandrake 10:
- 192.168.0.0
- 10.0.0.0
Eu poderia fazer isto:
http_port 192.168.0.0:3128
http_port 10.0.0.0:3128


 
Resposta de Felipe Domingos em 17/05/2007 - 13:48h:
* Felipe Domingos usa Slackware
* Felipe Domingos tem conceito: nenhum voto.
 


Então com mais de uma interface deixe assim:
http_port 3128

lembrando que assim, os browsers tem que apontar para essa porta.

T+

  


ATENÇÃO: Antes de contribuir com uma resposta, leia o artigo Qualidade de respostas e certifique-se de que esteja realmente contribuindo com a comunidade. Muitas vezes o ímpeto de contribuir nos leva a atrapalhar ao invés de ajudar.

Contribuir com resposta



CAPTCHA
[ Recarregar imagem ]

Digite o código acima:

  
* Nota: só é possível enviar respostas usuário que possui conta e esteja logado com ela, caso contrário sua mensagem será perdida.



Patrocínio

Site hospedado pelo provedor RedeHost.
Linux banner

Destaques

Artigos

Dicas

Tópicos

Top 10 do mês

Scripts