Squid your proxy server on a virtual server

We all face the problem of blocking resources on the Internet. The reasons for these blockages can be completely different. In many countries, the government blocks unwanted resources or the countries themselves block access to resources to other states. Moreover, quite harmless and useful resources sometimes get blocked. There are quite a lot of ways out, you can use proxy plugins for browsers, buy a proxy or use a VPN, or you can raise your own proxy server. Let's start with the fact that the simplest VDS/VPS server is suitable. Installation and configuration will take a little time, especially if you understand Linux at least a little.
Let's get started, I use Debian on servers, so the instructions are for this distribution, but it is also suitable for Debian-like systems (Ubuntu), and those who are friends with Linux can easily adapt to other distributions.
Updating and rebooting the system:
apt update && apt upgrade -y && apt dist-upgrade -y && reboot
Let's install the Squid3 proxy server:
apt-get install squid3
Go to the directory:
cd /etc/squid
Making a backup copy of the squid3 settings file:
cp squid.conf squid.conf.default
Clearing the configuration file:
> squid.conf
Opening the configuration file:
nano squid.conf
And fill it with the following contents:
# the port where the proxy is available
http_port 3128
dns_nameservers 208.67.222.222 208.67.220.220
# authorization, details belowauth_param basic program /usr/lib/squid3/basic_ncsa_auth /etc/squid/passwdauth_param basic children 5 startup=5 idle=1auth_param basic realm Welcome to Free VPN Proxy Masterauth_param basic credentialsttl 2 hours
acl all src allacl Users proxy_auth REQUIRED# to let a friend in from this ip without a passwordacl KnownUsers src "/etc/squid/KnownUsers.acl"
acl SSL_ports port 443 # httpsacl SSL_ports port 563 # snewsacl SSL_ports port 873 # rsyncacl Safe_ports port 80 # httpacl Safe_ports port 21 # ftpacl Safe_ports port 443 # httpsacl Safe_ports port 70 # gopheracl Safe_ports port 210 # waisacl Safe_ports port 1025-65535 # unregistered portsacl Safe_ports port 280 # http-mgmtacl Safe_ports port 488 # gss-httpacl Safe_ports port 591 # filemakeracl Safe_ports port 777 # multiling httpacl Safe_ports port 631 # cupsacl Safe_ports port 873 # rsyncacl Safe_ports port 901 # SWAT
acl purge method PURGEacl CONNECT method CONNECT
# access only from trusted ip addresses or by passwordhttp_access allow KnownUsershttp_access allow Users
http_access deny purgehttp_access deny !Safe_portshttp_access deny CONNECT !SSL_portshttp_access deny allicp_access deny all
# turning squid into an anonymous proxyforwarded_for offheader_access From deny allheader_access Server deny allheader_access User-Agent deny allheader_replace User-Agent Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Firefox/52.0header_access Referer deny allheader_replace Referer unknownheader_access WWW-Authenticate deny allheader_access Link deny allheader_access X-Forwarded-For deny allheader_access Via deny allheader_access Cache-Control deny all# to send the URL of the request source, many sites behave incorrectly without it. With a paranoid approach, you should use##header_access Referer deny all
coredump_dir /var/spool/squid3
# Disabling the disk cache completelycache_mem 8 MBcache_dir null /tmpcache deny allshutdown_lifetime 5 seconds
# we trim the logs, you do not need to store unnecessary information about usaccess_log none allcache_store_log none
refresh_pattern ^ftp: 1440 20% 10080refresh_pattern ^gopher: 1440 0% 1440refresh_pattern -i (/cgi-bin/|\?) 0 0% 0refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880refresh_pattern . 0 20% 4320
Creating a passwd file:
touch /etc/squid/passwd
Creating the Known Users.acl file:
touch /etc/squid/KnownUsers.acl
Restarting the squid proxy server:
service squid restart
If you have a static IP address, you can add it to the Known Users.acl file to use the proxy server without a username or password. You can add as many addresses as you want, each from a new line.
If the IP address is dynamic, it is easier to create a user and password. This is how it is done:
htpasswd /etc/squid/passwd proxyuser
where proxy user is your user's name, it can be anything. When creating a user, you will be asked for a password and its confirmation. Use non-trivial usernames and complex passwords!
After any configuration or access changes, do not forget to restart the proxy server.

Spain
Portugal

