Tiny Web Proxy And Content Filtering Appliance (Version 1.2) With Debian Squeeze - Page 2
Step 4. Install Apache 2
It is also a good idea to have a web server installed on the virtual machine. This web server will later host the status and report information for Squid and Content Security for Squid Proxy. In order to have the Apache2 installed issue the following commands in the root terminal:
# apt-get install apache2 libapache2-mod-php5
Then open your browser and navigate to http://192.168.1.2. You should see the “It Works!” greetings from Apache.
Step 5. Install QuintoLabs Content Security 1.2
Next step would be to install the Content Security 1.2 for Squid from QuintoLabs (I will refer to it as qlproxy further in text). NOTE: this part was upgraded from the previous version of this howto. The 1.2 version of qlproxy now supports ICAP based integration with Squid and is much easier to install.
For those who do not know, qlproxy is a content filtering server to be used as a companion to the Squid web proxy that (citation) "allows the administrator to filter/block web downloads, remove advertisements and banners and control web site usage by the proxy clients" (i.e. prohibit explicit and adult content).
Unfortunately QuintoLabs does not yet have online package repository with qlproxy but I heard it will change in the future :). So until it happens we have to get the Debian 6 package of qlproxy manually from the QuintoLabs web site at http://www.quintolabs.com/qlicap_download.php using your favorite browser (thorough your new squid of course :) ) and upload the package to the system using scp. Another (much easier) way would be to type the following commands in the root terminal:
# wget http://www.quintolabs.com/qlproxy/binaries/126.96.36.199/qlproxy-1.2-debian-1.2.217_i386.deb
Wait a little until the download completes (approx. 20Mb) and run the following command to install the downloaded package
# dpkg –install qlproxy-1.2-debian-1.2.217_i386.deb
Installer will run and after a short while the program will be installed into /opt/quintolabs/qlproxy.
Now we need to configure it and integrate it with Squid. The configuration files are plain text and stored in /opt/quintolabs/qlproxy/etc/*.conf and rather simple to modify with a handful of comments inside. I am going to perform the following modifications:
Good for now, let us issue a restart command to make the qlproxyd daemon reload the configuration:
Next we need to integrate it with Squid. As the qlproxy daemon now supports the shiny ICAP protocol this is a little bit different from the url_rewrite_program integration described in the previous version of this howto. By the way, README file in /opt/quintolabs/qlproxy/ contains instructions on how to do that. Anyway here are the steps required:
Now restart the squid by typing
# service squid3 restart
in the root terminal. After restart try surfing the same sites with your browser and see how nicely ads are blocked. Another useful test is to go to the eicar.com web site and try to download a sample artificial eicar.com virus to see that com files are blocked by the download filter.
Note: for those of you who must stick with squid 2.6 for performance reasons the url rewriter integration is quite straightforward. Open /etc/squid3/squid.conf and find the url_rewrite_program section. Add the following url_rewrite_program /opt/quintolabs/qlproxy/sbin/qlproxyd_redirector --config_path=/opt/quintolabs/qlproxy/etc/qlproxyd.conf
The last thing to do is to integrate the qlproxy with Apache to be able to see the reports on user activities generated once a day. This is actually quite easy, open the /etc/apache2/sites-enabled/default file and add the following to it near the </VirtualHost> directive:
Alias /reports /opt/quintolabs/qlproxy/reports <Directory /opt/quintolabs/qlproxy/reports > Options FollowSymLinks AllowOverride None </Directory>
Now reload the apache by typing in the terminal #service apache2 restart.
You can navigate to http://192.168.1.2/reports to see the generated reports. The funny thing is that qlproxy blocks access by the IP address according to our settings in httpblock.conf described earlier. Solution would be to add the 192.168.1.2 as entry to the /opt/quintolabs/qlproxy/etc/exceptions.conf or just tell the browser not to use proxy for this address.
Finally everything is in place to start the accelerated secure web surfing without adverts – point your browser to 192.168.1.2 port 3128 and browse to your favorite website and see the difference. The IP addresses in URLs are blocked and explicitly adult content sites too. The VMWare takes not more than 256 MB and surfing experience is quite acceptable. The system is automatically updated once a day for the latest url block list and advert subscriptions and requires minimal additional maintenance.
Used Documentation Links