Re: [squid-users] Blocking Canonical Names, Not IP Addresses

From: Joe Cooper <joe@dont-contact.us>
Date: Sun, 09 Jun 2002 08:50:00 -0500

Of course. Squid can block on just about any aspect of the URL,
including domain name.

See the ACL section of the FAQ for all ACL types currently supported:

http://www.squid-cache.org/Doc/FAQ/FAQ-10.html

Cliff wrote:
> Hi Squid Listers
>
> Problem:
>
> Many hosting providers will co-locate porn sites
> on the same webserver that also hosts non-porn web sites.
> They use Apache's name based virtual web hosting for this.
>
> So a porn site may actually exist at the exact same
> IP address as a non-porn site.
>
> Our existing porn filter does a canonical name lookup
> and then blocks the web site's IP address. So if we choose
> to block a porn site...we are also choosing to block any/all
> web sites that may exist at that IP address.
>
> The existing porn filter is from H2N.
>
> Needless to say, the users don't understand why
> http://non-porn.website.com is blocked, the reason being
> that http://good-porn.website.com and http://non-porn.website.com
> are both hosted at the same IP addy via name based virtual hosting.
>
> So can squid block by canonical name only?
> It seems like blocking by canonical name only would leave
> the rest of the non-porn websites at the same address reachable.
>
> Or perhaps I'm mistaking/misunderstanding something?
>
> Thank you fellow Squid Gurus.
>

-- 
Joe Cooper <joe@swelltech.com>
Web caching appliances and support.
http://www.swelltech.com
Received on Sun Jun 09 2002 - 07:50:46 MDT

This archive was generated by hypermail pre-2.1.9 : Tue Dec 09 2003 - 17:08:37 MST