Networking-Blog

My WordPress Blog

Linux Squid and Dansguardian its slow

Months ago I’ve installed squid and dansguardian without a problems and worked perfect,
but week ago when the users navigate with their browsers its slow
.

I’ve changed some parameters in squid and dansguardian to solve the problem :

sudo vi /etc/squid/squid.conf

cache_dir ufs /var/spool/squid 2000 16 256
cache_mem 2000 MB
maximum_object_size 4096 KB

sudo vi /etc/ dansguardian/dansguardian.conf   ( Default Settings )

maxchildren = 120
minchildren = 8
minsparechildren = 4
preforkchildren = 6
maxsparechildren = 32
maxagechildren = 500

Right now the browsing is fast as I have done some changes
in the config file
:

maxchildren = 999
minchildren = 250
minsparechildren = 24
preforkchildren = 32
maxsparechildren = 64
maxagechildren = 10000

The following are the results I get after running

> # ps aux | grep dans
> 419 3049 0.0 11.3 127952 114912 ? Ss 16:44 0:00
> dansguardian-av -c /etc/dansguardian-av/dansguardian.conf
> 419 3050 0.0 11.3 127956 115024 ? S 16:44 0:00
> dansguardian-av -c /etc/dansguardian-av/dansguardian.conf
> 419 3051 0.0 11.3 132836 114964 ? S 16:44 0:00

Linux Danaguardian Proxy Iptables

Push traffic to Proxy Filter Dansguardian :

PREROUTING Chain :
this will have all traffic destined for port tcp 80 to jump to unfiltered_web chain.

iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web

unfiltered_web chain entry :

iptables -I unfiltered_web -d 83.166.168.43 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -d 212.41.178.44 -p tcp -m tcp –dport 80 -j ACCEPT
iptables -I unfiltered_web -s 172.16.2.49 -p tcp -m tcp –dport 80 -j ACCEPT

Once unfiltered traffic to bypass proxy dansguardian using unfiltered_web chain as above,
the last entry is to poing it back to filtered_web chain,  in order to have other ip addresses or
subnets HTTP traffic filtered using the filtered_web chain .
to have proxy filter HTTP traffic :

This will cause unfiltered_web to jump to filtered_web chain

iptables -I unfiltered_web-j filtered_web

filtered_web chain entry :

This will cause filtered_web chain to push all HTTP traffic to dansguardian proxy server
on 172.16.150.248 on tcp port 8080.

Tcp 80 will be DNAT to tcp port 8080 to destination address of 172.16.150.248.

iptables -I filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080

In Brief Summary :

iptables -I PREROUTING -p tcp -m tcp –dport 80 -j unfiltered_web
!
iptables -I unfiltered_web
-j filtered_web
(Make changes in this chain for unfiltered traffic as seen above)
!
iptables -I 
filtered_web -p tcp -m tcp –dport 80 -j DNAT –to-destination 172.16.150.248:8080

Additional Notes :

For HTTP external sites that need to bypass proxy due to HTTPS authentication,
These are the changes that need to be made within iptables :

sudo iptables -t nat -I PREROUTING -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT
!

sudo iptables -I FORWARD 18 -s 172.16.0.0/16 -d 83.166.168.51/32 -p tcp -m tcp –dport 443 -j ACCEPT

Quick Summary :

sudo iptables -t nat -I PREROUTING 1 -i eth 0 -s 10.10.0.0/16 -p tcp -m tcp –dport 80 -j unfiltered_web
!
sudo iptables -t nat -I unfiltered_web 1 -i eth0 -s 10.10.34.12/32 -j ACCEPT
sudo iptables -t nat -I unfiltered_web 2 -i eth0 -j filtered_web
!
sudo iptables -t nat -I filtered_web 1 -i eth0 -p tcp -m tcp –dport 80 -j REDIRECT –to-ports 8080