| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950 | acl localnet src 0.0.0.1-0.255.255.255	# RFC 1122 "this" network (LAN)acl localnet src 10.0.0.0/8		# RFC 1918 local private network (LAN)acl localnet src 100.64.0.0/10		# RFC 6598 shared address space (CGN)acl localnet src 169.254.0.0/16 	# RFC 3927 link-local (directly plugged) machinesacl localnet src 172.16.0.0/12		# RFC 1918 local private network (LAN)acl localnet src 192.168.0.0/16		# RFC 1918 local private network (LAN)acl localnet src fc00::/7       	# RFC 4193 local private network rangeacl localnet src fe80::/10      	# RFC 4291 link-local (directly plugged) machinesacl SSL_ports port 443acl Safe_ports port 80		# httpacl Safe_ports port 21		# ftpacl Safe_ports port 443		# httpsacl Safe_ports port 70		# gopheracl Safe_ports port 210		# waisacl Safe_ports port 1025-65535	# unregistered portsacl Safe_ports port 280		# http-mgmtacl Safe_ports port 488		# gss-httpacl Safe_ports port 591		# filemakeracl Safe_ports port 777		# multiling httpacl CONNECT method CONNECThttp_access deny !Safe_portshttp_access deny CONNECT !SSL_portshttp_access allow localhost managerhttp_access deny managerhttp_access allow localhostinclude /etc/squid/conf.d/*.confhttp_access deny all################################## Proxy Server ################################http_port ${HTTP_PORT}coredump_dir ${COREDUMP_DIR}refresh_pattern ^ftp:		1440	20%	10080refresh_pattern ^gopher:	1440	0%	1440refresh_pattern -i (/cgi-bin/|\?) 0	0%	0refresh_pattern \/(Packages|Sources)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-imsrefresh_pattern \/Release(|\.gpg)$ 0 0% 0 refresh-imsrefresh_pattern \/InRelease$ 0 0% 0 refresh-imsrefresh_pattern \/(Translation-.*)(|\.bz2|\.gz|\.xz)$ 0 0% 0 refresh-imsrefresh_pattern .		0	20%	4320# cache_dir ufs /var/spool/squid 100 16 256# upstream proxy, set to your own upstream proxy IP to avoid SSRF attacks# cache_peer 172.1.1.1 parent 3128 0 no-query no-digest no-netdb-exchange default ################################## Reverse Proxy To Sandbox ################################http_port ${REVERSE_PROXY_PORT} accel vhostcache_peer ${SANDBOX_HOST} parent ${SANDBOX_PORT} 0 no-query originserveracl src_all src allhttp_access allow src_all
 |