Squid Proxy deny rules doesn't work when authentication is included in squid configuration file

Viewed 270

I am using the SQUID proxy for my outbound connection.My whitelist rule and deny rule doesn't work the moment i added the authentication layer.When i am trying to hit the URL with the URL which is not defined in my configuration file the proxy is returning 200.Is something with the rule priority list. It filters only at the authentication if it is correct it directly by pass all filters.

# Proxy Authentication
auth_param basic program /usr/lib64/squid/basic_ncsa_auth /etc/squid/passwd
acl authenticated proxy_auth REQUIRED
http_access allow authenticated

# Local network access to proxy
# Safe ports that can be used
acl SSL_ports port 443
acl Safe_ports port 80          # http
acl Safe_ports port 21          # ftp
acl Safe_ports port 443         # https
acl Safe_ports port 70          # gopher
acl Safe_ports port 210         # wais
acl Safe_ports port 280         # http-mgmt
acl Safe_ports port 488         # gss-http
acl Safe_ports port 591         # filemaker
acl Safe_ports port 777         # multiling http
acl Safe_ports port 3128
acl CONNECT method CONNECT

# Deny requests to certain unsafe ports
http_access deny !Safe_ports

# Deny CONNECT to other than secure SSL ports
http_access deny CONNECT !SSL_ports

# Destination domains that can be accessed
acl whitelist dstdomain .bing.com
acl whitelist dstdomain .google.com 

http_access allow whitelist

# Destination domains that cannot be accessed
http_access deny all
1 Answers

the issue is described in the "Common Mistakes" section of the wiki: https://wiki.squid-cache.org/SquidFaq/SquidAcl#Common_Mistakes

specifically:

  • All elements of an acl entry are OR'ed together.
  • All elements of an access entry are AND'ed together (e.g. http_access and icp_access)

so when you write two different lines for http_access, e.g.:

http_access allow authenticated
http_access allow whitelist

they are interpreted as "OR" and therefore either one will "hit".

if you want to force the proxy to only allow authenticated users to use whitelist acl, they have to be on the same line. so in your case:

http_access allow authenticated whitelist

and that means - (only) allow authenticated AND whitelist.

followed by a http_access deny all this should block all other traffic as well.

Related