mirror of
https://github.com/3proxy/3proxy.git
synced 2026-09-09 04:32:30 +00:00
Update wiki
parent
75a0d37f35
commit
2ea1c069fc
6 changed files with 301 additions and 282 deletions
571
3proxy.cfg.md
571
3proxy.cfg.md
|
|
@ -84,10 +84,10 @@ smtpp</b> [options] <b><br>
|
|||
ftppr</b> [options] <b><br>
|
||||
admin</b> [options] <b><br>
|
||||
dnspr</b> [options] <b><br>
|
||||
tcppm</b> [options] <SRCPORT> <DSTADDR>
|
||||
<DSTPORT> <b><br>
|
||||
udppm</b> [options] <SRCPORT> <DSTADDR>
|
||||
<DSTPORT> <br>
|
||||
tcppm</b> [options] <i><SRCPORT> <DSTADDR>
|
||||
<DSTPORT></i> <b><br>
|
||||
udppm</b> [options] <i><SRCPORT> <DSTADDR>
|
||||
<DSTPORT></i> <br>
|
||||
Descriptions: <b><br>
|
||||
proxy</b> HTTP/HTTPS proxy (default port 3128) <b><br>
|
||||
socks</b> SOCKS 4/4.5/5 proxy (default port 1080) <b><br>
|
||||
|
|
@ -111,15 +111,14 @@ specified for syntax compatibility. <b><br>
|
|||
udppm</b> UDP portmapper</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">Options: <b><br>
|
||||
-pNUMBER</b> change default server port to NUMBER <b><br>
|
||||
-n</b> disable NTLM authentication (required if passwords
|
||||
are stored in Unix crypt format). <b><br>
|
||||
-n1</b> enable NTLMv1 authentication. <b><br>
|
||||
-g(GRACE_TRAFF,GRACE_NUM,GRACE_DELAY)</b> delay GRACE_DELAY
|
||||
milliseconds before polling if average polling size is below
|
||||
GRACE_TRAFF bytes and GRACE_NUM read operations in a single
|
||||
direction are detected within 1 second. Useful to minimize
|
||||
polling <b>-s</b> <br>
|
||||
-p</b><i>NUMBER</i> change default server port to NUMBER
|
||||
<b><br>
|
||||
|
||||
-g(</b><i>GRACE_TRAFF</i><b>,</b><i>GRACE_NUM</i><b>,</b><i>GRACE_DELAY</i>)
|
||||
delay GRACE_DELAY milliseconds before polling if average
|
||||
polling size is below GRACE_TRAFF bytes and GRACE_NUM read
|
||||
operations in a single direction are detected within 1
|
||||
second. Useful to minimize polling <b>-s</b> <br>
|
||||
(for admin) secure, allow only secure operations, currently
|
||||
only traffic counters view without ability to reset. <br>
|
||||
(for dnspr) simple, do not use resolver and 3proxy cache,
|
||||
|
|
@ -142,35 +141,37 @@ packed in IPv6 in IPV6_V6ONLY compatible way. <b><br>
|
|||
resolvable <b><br>
|
||||
-64</b> Resolve IPv4 addresses if IPv6 address is not
|
||||
resolvable <b><br>
|
||||
-RHOST:port</b> listen on given local HOST:port for incoming
|
||||
connections instead of making remote outgoing connection.
|
||||
Can be used with another 3proxy service running -r option
|
||||
for connect back functionality. Most commonly used with
|
||||
tcppm. HOST can be given as IP or hostname, useful in case
|
||||
of dynamic DNS. <b><br>
|
||||
-rHOST:port</b> connect to given remote HOST:port instead of
|
||||
listening local connection on -p or default port. Can be
|
||||
used with another 3proxy service running -R option for
|
||||
connect back functionality. Most commonly used with proxy or
|
||||
socks. HOST can be given as IP or hostname, useful in case
|
||||
of dynamic DNS. <b><br>
|
||||
-ocOPTIONS, -osOPTIONS, -olOPTIONS, -orOPTIONS,
|
||||
-oROPTIONS</b> options for proxy-to-client (oc),
|
||||
proxy-to-server (os), proxy listening (ol), connect back
|
||||
client (or), connect back listening (oR) sockets. Options
|
||||
like TCP_CORK, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK,
|
||||
TCP_TIMESTAMPS, USE_TCP_FASTOPEN, SO_REUSEADDR,
|
||||
SO_REUSEPORT, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT,
|
||||
SO_KEEPALIVE, SO_DONTROUTE may be supported depending on OS.
|
||||
<b><br>
|
||||
-DiINTERFACE, -DeINTERFACE</b> bind internal interface /
|
||||
external interface to given INTERFACE (e.g. eth0) if
|
||||
SO_BINDTODEVICE is supported by the system. You may need to
|
||||
run as root or have CAP_NET_RAW capability in order to bind
|
||||
to an interface, depending on the system, so this option may
|
||||
-R</b><i>HOST</i><b>:</b><i>port</i> listen on given local
|
||||
HOST:port for incoming connections instead of making remote
|
||||
outgoing connection. Can be used with another 3proxy service
|
||||
running -r option for connect back functionality. Most
|
||||
commonly used with tcppm. HOST can be given as IP or
|
||||
hostname, useful in case of dynamic DNS. <b><br>
|
||||
-r</b><i>HOST</i><b>:</b><i>port</i> connect to given remote
|
||||
HOST:port instead of listening local connection on -p or
|
||||
default port. Can be used with another 3proxy service
|
||||
running -R option for connect back functionality. Most
|
||||
commonly used with proxy or socks. HOST can be given as IP
|
||||
or hostname, useful in case of dynamic DNS. <b><br>
|
||||
-oc</b><i>OPTIONS</i><b>, -os</b><i>OPTIONS</i><b>,
|
||||
-ol</b><i>OPTIONS</i><b>, -or</b><i>OPTIONS</i><b>,
|
||||
-oR</b><i>OPTIONS</i> options for proxy-to-client
|
||||
(<b>-oc</b>), proxy-to-server (<b>-os</b>), proxy listening
|
||||
(<b>-ol</b>), connect back client (<b>-or</b>), connect back
|
||||
listening (<b>-oR</b>) sockets. Options like TCP_CORK,
|
||||
TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS,
|
||||
USE_TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT,
|
||||
SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE,
|
||||
SO_DONTROUTE may be supported depending on OS. <b><br>
|
||||
-Di</b><i>INTERFACE</i><b>, -De</b><i>INTERFACE</i> bind
|
||||
internal (<b>-Di</b>) / external (<b>-De</b>) interface to
|
||||
given INTERFACE (e.g. eth0) if <b>SO_BINDTODEVICE</b> is
|
||||
supported by the system. You may need to run as root or have
|
||||
<b>CAP_NET_RAW</b> capability in order to bind to an
|
||||
interface, depending on the system, so this option may
|
||||
require root privileges and can be incompatible with some
|
||||
configuration commands like chroot and setuid (and daemon if
|
||||
setcap is used). <b><br>
|
||||
configuration commands like <b>chroot</b> and <b>setuid</b>
|
||||
(and <b>daemon</b> if setcap is used). <b><br>
|
||||
-e</b> External address. IP address of the interface the
|
||||
proxy should initiate connections from. External IP must be
|
||||
specified if you need incoming connections. By default the
|
||||
|
|
@ -207,10 +208,10 @@ proxy access must be authenticated, you can specify username
|
|||
as proxy_username:proxy_password:POP3_username@pop3server
|
||||
<br>
|
||||
DNS proxy resolves any types of records but only hostnames
|
||||
are cached. It requires nserver/nscache to be configured. If
|
||||
nserver is configured as TCP, redirections are applied on
|
||||
connection, so parent proxy may be used to resolve names to
|
||||
IP. <br>
|
||||
are cached. It requires <b>nserver</b>/<b>nscache</b> to be
|
||||
configured. If <b>nserver</b> is configured as TCP,
|
||||
redirections are applied on connection, so parent proxy may
|
||||
be used to resolve names to IP. <br>
|
||||
FTP proxy can be used as FTP server in any FTP client or
|
||||
configured as FTP proxy on a client with FTP proxy support.
|
||||
Username format is one of <br>
|
||||
|
|
@ -224,11 +225,11 @@ authentication use proxyuser:proxypassword:FTPuser as FTP
|
|||
username, otherwise do not change original FTP user name</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>include</b>
|
||||
<path> <br>
|
||||
<i><path></i> <br>
|
||||
Include config file</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>config</b>
|
||||
<path> <br>
|
||||
<i><path></i> <br>
|
||||
Path to configuration file to use on 3proxy restart or to
|
||||
save configuration.</p>
|
||||
|
||||
|
|
@ -244,20 +245,20 @@ using it.</p>
|
|||
End of configuration</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>log</b>
|
||||
[[@|&]logfile] [<LOGTYPE>] <br>
|
||||
[[@|&]<i>logfile</i>] [<i><LOGTYPE></i>] <br>
|
||||
sets logfile for all gateways <br>
|
||||
@ (for Unix) use syslog, filename is used as ident name <br>
|
||||
& use ODBC, filename consists of comma-delimited
|
||||
datasource,username,password (username and password are
|
||||
optional) <br>
|
||||
radius - use RADIUS for logging <br>
|
||||
LOGTYPE is one of: <br>
|
||||
c Minutely <br>
|
||||
H Hourly <br>
|
||||
D Daily <br>
|
||||
W Weekly (starting from Sunday) <br>
|
||||
M Monthly <br>
|
||||
Y Annually <br>
|
||||
LOGTYPE is one of: <b><br>
|
||||
c</b> Minutely <b><br>
|
||||
H</b> Hourly <b><br>
|
||||
D</b> Daily <b><br>
|
||||
W</b> Weekly (starting from Sunday) <b><br>
|
||||
M</b> Monthly <b><br>
|
||||
Y</b> Annually <br>
|
||||
if logfile is not specified logging goes to stdout. You can
|
||||
specify individual logging options for gateway by using -l
|
||||
option in gateway configuration. <br>
|
||||
|
|
@ -270,12 +271,12 @@ Grinwitch time zone for all time-based format
|
|||
specificators.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>rotate</b>
|
||||
<n> <br>
|
||||
<i><n></i> <br>
|
||||
how many archived log files to keep</p>
|
||||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>logformat</b>
|
||||
<format> <br>
|
||||
<i><format></i> <br>
|
||||
Format for log record. First symbol in format must be L
|
||||
(local time) or G (absolute Grinwitch time). It can be
|
||||
preceeded with -XXX+Y where XXX is list of characters to be
|
||||
|
|
@ -332,7 +333,8 @@ l_service, l_in, l_out, l_descr) values (´%d-%m-%Y
|
|||
´%T´)"</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>logdump</b>
|
||||
<in_traffic_limit> <out_traffic_limit> <br>
|
||||
<i><in_traffic_limit> <out_traffic_limit></i>
|
||||
<br>
|
||||
Immediately creates additional log records if given amount
|
||||
of incoming/outgoing traffic is achieved for connection,
|
||||
without waiting for connection to finish. It may be useful
|
||||
|
|
@ -341,7 +343,7 @@ server shutdown.</p>
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>delimchar</b>
|
||||
<char> <br>
|
||||
<i><char></i> <br>
|
||||
Sets the delimiter character used to separate username from
|
||||
hostname in proxy authentication strings (e.g. for FTP, POP3
|
||||
proxies). Default is ´@´. For example, to use
|
||||
|
|
@ -349,48 +351,50 @@ proxies). Default is ´@´. For example, to use
|
|||
to contain the ´@´ character.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>archiver</b>
|
||||
<ext> <commandline> <br>
|
||||
<i><ext> <commandline></i> <br>
|
||||
Archiver to use for log files. <ext> is file extension
|
||||
produced by archiver. Filename will be last argument to
|
||||
archiver, optionally you can use %A as produced archive name
|
||||
and %F as filename.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>timeouts</b>
|
||||
<BYTE_SHORT> <BYTE_LONG> <STRING_SHORT>
|
||||
<i><BYTE_SHORT> <BYTE_LONG> <STRING_SHORT>
|
||||
<STRING_LONG> <CONNECTION_SHORT>
|
||||
<CONNECTION_LONG> <DNS> <CHAIN>
|
||||
<CONNECT> <CONNECTBACK> <br>
|
||||
<CONNECT> <CONNECTBACK></i> <br>
|
||||
Sets timeout values, defaults 1, 5, 30, 60, 180, 1800, 15,
|
||||
60, 15, 5. <br>
|
||||
BYTE_SHORT short timeout for single byte, is usually used
|
||||
for receiving single byte from stream. <br>
|
||||
BYTE_LONG long timeout for single byte, is usually used for
|
||||
receiving first byte in frame (for example first byte in
|
||||
socks request). <br>
|
||||
STRING_SHORT short timeout, for character string within
|
||||
stream (for example to wait between 2 HTTP headers) <br>
|
||||
STRING_LONG long timeout, for first string in stream (for
|
||||
example to wait for HTTP request). <br>
|
||||
CONNECTION_SHORT inactivity timeout for short connections
|
||||
(HTTP, POP3, etc). <br>
|
||||
CONNECTION_LONG inactivity timeout for long connection
|
||||
(SOCKS, portmappers, etc). <br>
|
||||
DNS timeout for DNS request before requesting next server
|
||||
60, 15, 5. <b><br>
|
||||
BYTE_SHORT</b> short timeout for single byte, is usually
|
||||
used for receiving single byte from stream. <b><br>
|
||||
BYTE_LONG</b> long timeout for single byte, is usually used
|
||||
for receiving first byte in frame (for example first byte in
|
||||
socks request). <b><br>
|
||||
STRING_SHORT</b> short timeout, for character string within
|
||||
stream (for example to wait between 2 HTTP headers) <b><br>
|
||||
STRING_LONG</b> long timeout, for first string in stream
|
||||
(for example to wait for HTTP request). <b><br>
|
||||
CONNECTION_SHORT</b> inactivity timeout for short
|
||||
connections (HTTP, POP3, etc). <b><br>
|
||||
CONNECTION_LONG</b> inactivity timeout for long connection
|
||||
(SOCKS, portmappers, etc). <b><br>
|
||||
DNS</b> timeout for DNS request before requesting next
|
||||
server <b><br>
|
||||
CHAIN</b> timeout for reading data from chained connection
|
||||
<br>
|
||||
CHAIN timeout for reading data from chained connection <br>
|
||||
default timeouts 1 5 30 60 180 1800 15 60 15 5</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>maxseg</b>
|
||||
<value> <br>
|
||||
<i><value></i> <br>
|
||||
Sets TCP maximum segment size (MSS) for outgoing
|
||||
connections. This can be used to work around path MTU
|
||||
discovery issues or to optimize traffic for specific network
|
||||
conditions.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>radius</b>
|
||||
<NAS_SECRET>
|
||||
<radius_server_1[:port][/local_address_1]>
|
||||
<radius_server_2[:port][/local_address_2]> <br>
|
||||
<i><NAS_SECRET>
|
||||
<radius_server_1</i>[:<i>port</i>][/<i>local_address_1</i>]
|
||||
<i><radius_server_2</i>[:<i>port</i>][/<i>local_address_2</i>]
|
||||
<br>
|
||||
Configures RADIUS servers to be used for logging and
|
||||
authentication (log and auth types must be set to radius).
|
||||
port and local address to use with given server may be
|
||||
|
|
@ -409,12 +413,12 @@ CONNECT), Login-TCP-Port: (requested port), Login-IPv6-Host
|
|||
/ Login-IP-Host: (requested IP). <br>
|
||||
Supported reply attributes for authentication:
|
||||
Framed-IP-Address / Framed-IPv6-Address (IP to assign to
|
||||
user), Reply-Message. Use authcache to speedup
|
||||
user), Reply-Message. Use <b>authcache</b> to speedup
|
||||
authentication. RADIUS feature is currently
|
||||
experimental.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>nserver</b>
|
||||
<ipaddr>[:port][/tcp] <br>
|
||||
<i><ipaddr></i>[:<i>port</i>][/<i>tcp</i>] <br>
|
||||
Nameserver to use for name resolutions. If none specified
|
||||
system routines for name resolution is used. Optional port
|
||||
number may be specified. If optional /tcp is added to IP
|
||||
|
|
@ -422,33 +426,36 @@ address, name resolution is performed over TCP.</p>
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>authnserver</b>
|
||||
<ipaddr>[:port][/tcp] <br>
|
||||
<i><ipaddr></i>[:<i>port</i>][/<i>tcp</i>] <br>
|
||||
Nameserver to use for DNS-based authentication (e.g. dnsname
|
||||
auth type). If not specified, nserver is used. The syntax is
|
||||
the same as for nserver.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>nscache</b>
|
||||
<cachesize> <b>nscache6</b> <cachesize> <br>
|
||||
Cache <cachesize> records for name resolution (nscache
|
||||
for IPv4, nscache6 for IPv6). The cache size should usually
|
||||
be large enough (for example, 65536).</p>
|
||||
<i><cachesize></i> <b>nscache6</b>
|
||||
<i><cachesize></i> <br>
|
||||
Cache <i><cachesize></i> records for name resolution
|
||||
(<b>nscache</b> for IPv4, <b>nscache6</b> for IPv6). The
|
||||
cache size should usually be large enough (for example,
|
||||
65536).</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>nsrecord</b>
|
||||
<hostname> <hostaddr> <br>
|
||||
Adds static record to nscache. nscache must be enabled. If
|
||||
0.0.0.0 is used as a hostaddr host will never resolve, it
|
||||
can be used to blacklist something or together with
|
||||
<b>dialer</b> command to set up UDL for dialing.</p>
|
||||
<i><hostname> <hostaddr></i> <br>
|
||||
Adds static record to nscache. <b>nscache</b> must be
|
||||
enabled. If 0.0.0.0 is used as a hostaddr host will never
|
||||
resolve, it can be used to blacklist something or together
|
||||
with <b>dialer</b> command to set up UDL for dialing.</p>
|
||||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>fakeresolve</b>
|
||||
<br>
|
||||
All names are resolved to the 127.0.0.2 address. Useful if
|
||||
all requests are redirected to a parent proxy with http,
|
||||
socks4+, connect+ or socks5+.</p>
|
||||
all requests are redirected to a parent proxy with
|
||||
<b>http</b>, <b>socks4+</b>, <b>connect+</b> or
|
||||
<b>socks5+</b>.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>dialer</b>
|
||||
<progname> <br>
|
||||
<i><progname></i> <br>
|
||||
Execute progname if external name can´t be resolved.
|
||||
Hint: if you use nscache, dialer may not work, because names
|
||||
will be resolved through cache. In this case you can use
|
||||
|
|
@ -456,7 +463,7 @@ something like http://dial.right.now/ from browser to set up
|
|||
connection.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>internal</b>
|
||||
<ipaddr> <br>
|
||||
<i><ipaddr></i> <br>
|
||||
sets ip address of internal interface. This IP address will
|
||||
be used to bind gateways. Alternatively you can use -i
|
||||
option for individual gateways. Since 0.8 version, IPv6
|
||||
|
|
@ -470,27 +477,29 @@ using Unix sockets, the socket file is automatically created
|
|||
and removed on service start/stop.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>external</b>
|
||||
<ipaddr> <br>
|
||||
<i><ipaddr></i> <br>
|
||||
sets ip address of external interface. This IP address will
|
||||
be source address for all connections made by proxy.
|
||||
Alternatively you can use -e option to specify individual
|
||||
address for gateway. Since 0.8 version External or -e can be
|
||||
given twice: once with IPv4 and once with IPv6 address.</p>
|
||||
address for gateway. Since 0.8 version External or <b>-e</b>
|
||||
can be given twice: once with IPv4 and once with IPv6
|
||||
address.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>maxconn</b>
|
||||
<number> <br>
|
||||
<i><number></i> <br>
|
||||
sets the maximum number of simultaneous connections to each
|
||||
service started after this command at the network level.
|
||||
Default is 100. <br>
|
||||
To limit clients, use connlim instead. maxconn will silently
|
||||
ignore new connections, while connlim will report back to
|
||||
the client that the connection limit has been reached.</p>
|
||||
To limit clients, use <b>connlim</b> instead. <b>maxconn</b>
|
||||
will silently ignore new connections, while <b>connlim</b>
|
||||
will report back to the client that the connection limit has
|
||||
been reached.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>backlog</b>
|
||||
<br>
|
||||
sets the listening socket backlog of new connections.
|
||||
Default is 1 + maxconn/8. Maximum value is capped by kernel
|
||||
tunable somaxconn.</p>
|
||||
Default is 1 + <b>maxconn</b>/8. Maximum value is capped by
|
||||
kernel tunable somaxconn.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>service</b>
|
||||
<br>
|
||||
|
|
@ -504,35 +513,35 @@ reinstall the service.</p>
|
|||
<br>
|
||||
Should be specified to close the console. Do not use
|
||||
´daemon´ with ´service´. At least
|
||||
under FreeBSD, ´daemon´ should precede any proxy
|
||||
under FreeBSD, <b>daemon</b> should precede any proxy
|
||||
service and log commands to avoid socket problems. Always
|
||||
place it in the beginning of the configuration file.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>auth</b>
|
||||
<authtype> [...] <br>
|
||||
Type of user authorization. Currently supported: <br>
|
||||
none - no authentication or authorization required. <br>
|
||||
<i><authtype></i> [...] <br>
|
||||
Type of user authorization. Currently supported: <b><br>
|
||||
none</b> - no authentication or authorization required. <br>
|
||||
Note: if auth is none, any IP-based limitation, redirection,
|
||||
etc. will not work. This is the default authentication type
|
||||
<br>
|
||||
iponly - authentication by access control list with username
|
||||
ignored. <br>
|
||||
Appropriate for most cases <br>
|
||||
useronly - authentication by username without checking for
|
||||
any password with authorization by ACLs. Useful for e.g.
|
||||
<b><br>
|
||||
iponly</b> - authentication by access control list with
|
||||
username ignored. <br>
|
||||
Appropriate for most cases <b><br>
|
||||
useronly</b> - authentication by username without checking
|
||||
for any password with authorization by ACLs. Useful for e.g.
|
||||
SOCKSv4 proxy and icqpr (icqpr set UIN / AOL screen name as
|
||||
a username) <br>
|
||||
dnsname - authentication by DNS hostname with authorization
|
||||
by ACLs. The DNS hostname is resolved via a PTR (reverse)
|
||||
record and validated (the resolved name must resolve to the
|
||||
same IP address). It´s recommended to use authcache by
|
||||
IP for this authentication. NB: there is no password check;
|
||||
the name may be spoofed. <br>
|
||||
strong - username/password authentication required. It will
|
||||
work with SOCKSv5, FTP, POP3 and HTTP proxy. <br>
|
||||
cache - cached authentication, may be used with
|
||||
´authcache´. <br>
|
||||
radius - authentication with RADIUS. <br>
|
||||
a username) <b><br>
|
||||
dnsname</b> - authentication by DNS hostname with
|
||||
authorization by ACLs. The DNS hostname is resolved via a
|
||||
PTR (reverse) record and validated (the resolved name must
|
||||
resolve to the same IP address). It´s recommended to
|
||||
use authcache by IP for this authentication. NB: there is no
|
||||
password check; the name may be spoofed. <b><br>
|
||||
strong</b> - username/password authentication required. It
|
||||
will work with SOCKSv5, FTP, POP3 and HTTP proxy. <b><br>
|
||||
cache</b> - cached authentication, may be used with
|
||||
´authcache´. <b><br>
|
||||
radius</b> - authentication with RADIUS. <br>
|
||||
Plugins may add additional authentication types.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">It´s
|
||||
|
|
@ -550,38 +559,39 @@ shared ones.</p>
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>authcache</b>
|
||||
<cachtype> <cachtime> <br>
|
||||
<i><cachtype> <cachtime> <cachesize></i>
|
||||
<br>
|
||||
Cache authentication information for a given amount of time
|
||||
(cachetime) in seconds. Cachetype is one of: <br>
|
||||
ip - after successful authentication all connections during
|
||||
caching time from same IP are assigned to the same user,
|
||||
username is not requested. <br>
|
||||
ip,user username is requested and all connections from the
|
||||
same IP are assigned to the same user without actual
|
||||
authentication. <br>
|
||||
user - same as above, but IP is not checked. <br>
|
||||
user,password - both username and password are checked
|
||||
against cached ones. <br>
|
||||
limit - limit user to use only one ip, ´ip´ and
|
||||
´user´ are required <br>
|
||||
acl - only use cached auth if user access service with same
|
||||
ACL <br>
|
||||
ext - cache external IP <br>
|
||||
Use auth type ´cache´ for cached
|
||||
authentication</p>
|
||||
(cachetime) in seconds. cachesize limits number of cache
|
||||
entries. Cachetype is one of: <b><br>
|
||||
ip</b> - after successful authentication all connections
|
||||
during caching time from same IP are assigned to the same
|
||||
user, username is not requested. <b><br>
|
||||
ip,user</b> username is requested and all connections from
|
||||
the same IP are assigned to the same user without actual
|
||||
authentication. <b><br>
|
||||
user</b> - same as above, but IP is not checked. <b><br>
|
||||
user,password</b> - both username and password are checked
|
||||
against cached ones. <b><br>
|
||||
limit</b> - limit user to use only one ip, ´ip´
|
||||
and ´user´ are required <b><br>
|
||||
ack</b> - only use cached auth if user access service with
|
||||
same ACL <b><br>
|
||||
ext</b> - cache external IP <br>
|
||||
Use auth type <b>cache</b> for cached authentication</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>allow</b>
|
||||
<userlist> <sourcelist> <targetlist>
|
||||
<i><userlist> <sourcelist> <targetlist>
|
||||
<targetportlist> <operationlist>
|
||||
<weekdayslist> <timeperiodslist> <b><br>
|
||||
deny</b> <userlist> <sourcelist>
|
||||
<weekdayslist> <timeperiodslist></i> <b><br>
|
||||
deny</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
redirect</b> <ip> <port> <userlist>
|
||||
<timeperiodslist></i> <b><br>
|
||||
redirect</b> <i><ip> <port> <userlist>
|
||||
<sourcelist> <targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <br>
|
||||
<timeperiodslist></i> <br>
|
||||
Access control entries. All lists are comma-separated, no
|
||||
spaces are allowed. Usernames are case sensitive (if used
|
||||
with authtype nbname username must be in uppercase). Source
|
||||
|
|
@ -607,27 +617,28 @@ should either bind proxy to appropriate interface only or to
|
|||
use ip filters.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">Operation is one
|
||||
of: <br>
|
||||
CONNECT establish outgoing TCP connection <br>
|
||||
BIND bind TCP port for listening <br>
|
||||
UDPASSOC make UDP association <br>
|
||||
ICMPASSOC make ICMP association (for future use) <br>
|
||||
HTTP_GET HTTP GET request <br>
|
||||
HTTP_PUT HTTP PUT request <br>
|
||||
HTTP_POST HTTP POST request <br>
|
||||
HTTP_HEAD HTTP HEAD request <br>
|
||||
HTTP_CONNECT HTTP CONNECT request <br>
|
||||
HTTP_OTHER over HTTP request <br>
|
||||
HTTP matches any HTTP request except HTTP_CONNECT <br>
|
||||
HTTPS same as HTTP_CONNECT <br>
|
||||
FTP_GET FTP get request <br>
|
||||
FTP_PUT FTP put request <br>
|
||||
FTP_LIST FTP list request <br>
|
||||
FTP_DATA FTP data connection. Note: FTP_DATA requires access
|
||||
to dynamic non-privileged (1024-65535) ports on the remote
|
||||
side. <br>
|
||||
FTP matches any FTP/FTP Data request <br>
|
||||
ADMIN access to administration interface</p>
|
||||
of: <b><br>
|
||||
CONNECT</b> establish outgoing TCP connection <b><br>
|
||||
BIND</b> bind TCP port for listening <b><br>
|
||||
UDPASSOC</b> make UDP association <b><br>
|
||||
ICMPASSOC</b> make ICMP association (for future use) <b><br>
|
||||
HTTP_GET</b> HTTP GET request <b><br>
|
||||
HTTP_PUT</b> HTTP PUT request <b><br>
|
||||
HTTP_POST</b> HTTP POST request <b><br>
|
||||
HTTP_HEAD</b> HTTP HEAD request <b><br>
|
||||
HTTP_CONNECT</b> HTTP CONNECT request <b><br>
|
||||
HTTP_OTHER</b> over HTTP request <b><br>
|
||||
HTTP</b> matches any HTTP request except HTTP_CONNECT
|
||||
<b><br>
|
||||
HTTPS</b> same as HTTP_CONNECT <b><br>
|
||||
FTP_GET</b> FTP get request <b><br>
|
||||
FTP_PUT</b> FTP put request <b><br>
|
||||
FTP_LIST</b> FTP list request <b><br>
|
||||
FTP_DATA</b> FTP data connection. Note: FTP_DATA requires
|
||||
access to dynamic non-privileged (1024-65535) ports on the
|
||||
remote side. <b><br>
|
||||
FTP</b> matches any FTP/FTP Data request <b><br>
|
||||
ADMIN</b> access to administration interface</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">Weekdays are
|
||||
week day numbers or periods, 0 or 7 means Sunday, 1 is
|
||||
|
|
@ -638,8 +649,8 @@ HH:MM:SS-HH:MM:SS format. For example,
|
|||
hours.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>parent</b>
|
||||
<weight> <type> <ip> <port>
|
||||
<username> <password> <br>
|
||||
<i><weight> <type> <ip> <port>
|
||||
<username> <password></i> <br>
|
||||
this command must follow "allow" rule. It extends
|
||||
last allow rule to build proxy chain. Proxies may be
|
||||
grouped. Proxy inside the group is selected randomly. If few
|
||||
|
|
@ -668,45 +679,51 @@ pipelined (keep-alive) requests in the same connection use
|
|||
the same chain.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">type is one of:
|
||||
<br>
|
||||
extip does not actually redirect the request; it sets the
|
||||
external address for this request to <ip>. It can be
|
||||
chained with another parent type. It’s useful to set
|
||||
the external IP based on ACL or make it random. <br>
|
||||
tcp simply redirect connection. TCP is always last in chain.
|
||||
This type of proxy is a simple TCP redirection, it does not
|
||||
support parent authentication. <br>
|
||||
http redirect to HTTP proxy. HTTP is always the last chain.
|
||||
It should only be used with http (proxy) service, if used
|
||||
with different service, it works as tcp redirection. <br>
|
||||
pop3 redirect to POP3 proxy (only local redirection is
|
||||
supported, can only be used as a first hop in chaining) <br>
|
||||
ftp redirect to FTP proxy (only local redirection is
|
||||
supported, can only be used as a first hop in chaining) <br>
|
||||
connect parent is HTTP CONNECT method proxy <br>
|
||||
connect+ parent is HTTP CONNECT proxy with name resolution
|
||||
(hostname is used instead of IP if available) <br>
|
||||
socks4 parent is SOCKSv4 proxy <br>
|
||||
socks4+ parent is SOCKSv4 proxy with name resolution
|
||||
(SOCKSv4a) <br>
|
||||
socks5 parent is SOCKSv5 proxy <br>
|
||||
socks5+ parent is SOCKSv5 proxy with name resolution <br>
|
||||
socks4b parent is SOCKS4b (broken SOCKSv4 implementation
|
||||
<b><br>
|
||||
extip</b> does not actually redirect the request; it sets
|
||||
the external address for this request to <i><ip></i>.
|
||||
It can be chained with another parent type. It’s
|
||||
useful to set the external IP based on ACL or make it
|
||||
random. <b><br>
|
||||
tcp</b> simply redirect connection. TCP is always last in
|
||||
chain. This type of proxy is a simple TCP redirection, it
|
||||
does not support parent authentication. <b><br>
|
||||
http</b> redirect to HTTP proxy. HTTP is always the last
|
||||
chain. It should only be used with http (proxy) service, if
|
||||
used with different service, it works as tcp redirection.
|
||||
<b><br>
|
||||
pop3</b> redirect to POP3 proxy (only local redirection is
|
||||
supported, can only be used as a first hop in chaining)
|
||||
<b><br>
|
||||
ftp</b> redirect to FTP proxy (only local redirection is
|
||||
supported, can only be used as a first hop in chaining)
|
||||
<b><br>
|
||||
connect</b> parent is HTTP CONNECT method proxy <b><br>
|
||||
connect+</b> parent is HTTP CONNECT proxy with name
|
||||
resolution (hostname is used instead of IP if available)
|
||||
<b><br>
|
||||
socks4</b> parent is SOCKSv4 proxy <b><br>
|
||||
socks4+</b> parent is SOCKSv4 proxy with name resolution
|
||||
(SOCKSv4a) <b><br>
|
||||
socks5</b> parent is SOCKSv5 proxy <b><br>
|
||||
socks5+</b> parent is SOCKSv5 proxy with name resolution
|
||||
<b><br>
|
||||
socks4b</b> parent is SOCKS4b (broken SOCKSv4 implementation
|
||||
with shortened server reply; I never saw this kind of
|
||||
server, but they say there are some). Normally you should
|
||||
not use this option. Do not confuse this option with
|
||||
SOCKSv4a (socks4+). <br>
|
||||
socks5b parent is SOCKS5b (broken SOCKSv5 implementation
|
||||
SOCKSv4a (<b>socks4+</b>). <b><br>
|
||||
socks5b</b> parent is SOCKS5b (broken SOCKSv5 implementation
|
||||
with shortened server reply. I think you will never find it
|
||||
useful). Never use this option unless you know exactly you
|
||||
need it. <br>
|
||||
admin redirect request to local ´admin´ service
|
||||
(with -s parameter). <br>
|
||||
ha send HAProxy PROXY protocol v1 header to parent proxy.
|
||||
Must be the last in the proxy chain. Useful for passing
|
||||
client IP information to the parent proxy. Example: parent
|
||||
1000 ha <br>
|
||||
Use "+" proxy only with "fakeresolve"
|
||||
need it. <b><br>
|
||||
admin</b> redirect request to local ´admin´
|
||||
service (with -s parameter). <b><br>
|
||||
ha</b> send HAProxy PROXY protocol v1 header to parent
|
||||
proxy. Must be the last in the proxy chain. Useful for
|
||||
passing client IP information to the parent proxy. Example:
|
||||
parent 1000 ha <br>
|
||||
Use "+" proxy only with <b>fakeresolve</b>
|
||||
option</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">IP and port are
|
||||
|
|
@ -748,26 +765,26 @@ HTTP proxy, local HTTP proxy parses requests and allows only
|
|||
GET and POST requests. <br>
|
||||
parent 1000 http 1.2.3.4 0 <br>
|
||||
Changes the external address for a given connection to
|
||||
1.2.3.4 (equivalent to -e1.2.3.4) <br>
|
||||
1.2.3.4 (equivalent to <b>-e1.2.3.4</b>) <br>
|
||||
Optional username and password are used to authenticate on
|
||||
parent proxy. Username of ´*´ means username
|
||||
must be supplied by user.</p>
|
||||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>parentretries</b>
|
||||
<number> <br>
|
||||
<i><number></i> <br>
|
||||
Number of retries to connect to parent proxy. Default is
|
||||
1.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>nolog</b>
|
||||
<n> <br>
|
||||
<i><n></i> <br>
|
||||
extends last allow or deny command to prevent logging, e.g.
|
||||
<br>
|
||||
allow * * 192.168.1.1 <br>
|
||||
nolog</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>weight</b>
|
||||
<n> <br>
|
||||
<i><n></i> <br>
|
||||
extends last allow or deny command to set weight for this
|
||||
request <br>
|
||||
allow * * 192.168.1.1 <br>
|
||||
|
|
@ -785,30 +802,31 @@ connections.</p>
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>bandlimin</b>
|
||||
<rate> <userlist> <sourcelist>
|
||||
<i><rate> <userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
nobandlimin</b> <userlist> <sourcelist>
|
||||
<timeperiodslist></i> <b><br>
|
||||
nobandlimin</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
bandlimout</b> <rate> <userlist>
|
||||
<timeperiodslist></i> <b><br>
|
||||
bandlimout</b> <i><rate> <userlist>
|
||||
<sourcelist> <targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
nobandlimout</b> <userlist> <sourcelist>
|
||||
<timeperiodslist></i> <b><br>
|
||||
nobandlimout</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <br>
|
||||
bandlim sets a bandwidth limitation filter to <rate>
|
||||
bps (bits per second). If you want to specify bytes per
|
||||
second, multiply your value by 8. bandlim rules act in the
|
||||
same manner as allow/deny rules, except for one thing:
|
||||
bandwidth limiting is applied to all services, not to some
|
||||
specific service. bandlimin and nobandlimin apply to
|
||||
incoming traffic <br>
|
||||
bandlimout and nobandlimout apply to outgoing traffic <br>
|
||||
<timeperiodslist></i> <br>
|
||||
bandlim sets a bandwidth limitation filter to
|
||||
<i><rate></i> bps (bits per second). If you want to
|
||||
specify bytes per second, multiply your value by 8. bandlim
|
||||
rules act in the same manner as allow/deny rules, except for
|
||||
one thing: bandwidth limiting is applied to all services,
|
||||
not to some specific service. <b>bandlimin</b> and
|
||||
<b>nobandlimin</b> apply to incoming traffic <b><br>
|
||||
bandlimout</b> and <b>nobandlimout</b> apply to outgoing
|
||||
traffic <br>
|
||||
If you want to ratelimit your clients with IPs
|
||||
192.168.10.16/30 (4 addresses) to 57600 bps, you have to
|
||||
specify 4 rules like <br>
|
||||
|
|
@ -826,53 +844,54 @@ nobandlimin * * * 110 <br>
|
|||
before the rest of bandlim rules.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>connlim</b>
|
||||
<rate> <period> <userlist>
|
||||
<i><rate> <period> <userlist>
|
||||
<sourcelist> <targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
noconnlim</b> <userlist> <sourcelist>
|
||||
<timeperiodslist></i> <b><br>
|
||||
noconnlim</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <br>
|
||||
<timeperiodslist></i> <br>
|
||||
connlim sets connections rate limit per time period for
|
||||
traffic pattern controlled by ACL. Period is in seconds. If
|
||||
period is 0, connlim limits a number of parallel
|
||||
period is 0, <b>connlim</b> limits a number of parallel
|
||||
connections. <br>
|
||||
connlim 100 60 * 127.0.0.1 <br>
|
||||
allows 100 connections per minute for 127.0.0.1. <br>
|
||||
connlim 20 0 * 127.0.0.1 <br>
|
||||
allows 20 simultaneous connections for 127.0.0.1. <br>
|
||||
Like with bandlimin, if an individual limit is required per
|
||||
client, a separate rule must be added for every client. Like
|
||||
with nobandlimin, noconnlim adds an exception.</p>
|
||||
Like with <b>bandlimin</b>, if an individual limit is
|
||||
required per client, a separate rule must be added for every
|
||||
client. Like with nobandlimin, noconnlim adds an
|
||||
exception.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>counter</b>
|
||||
<filename> <reporttype> <reportname>
|
||||
<b><br>
|
||||
countin</b> <number> <type> <limit>
|
||||
<i><filename> <reporttype>
|
||||
<reportname></i> <b><br>
|
||||
countin</b> <i><number> <type> <limit>
|
||||
<userlist> <sourcelist> <targetlist>
|
||||
<targetportlist> <operationlist>
|
||||
<weekdayslist> <timeperiodslist> <b><br>
|
||||
nocountin</b> <userlist> <sourcelist>
|
||||
<weekdayslist> <timeperiodslist></i> <b><br>
|
||||
nocountin</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
countout</b> <number> <type> <limit>
|
||||
<timeperiodslist></i> <b><br>
|
||||
countout</b> <i><number> <type> <limit>
|
||||
<userlist> <sourcelist> <targetlist>
|
||||
<targetportlist> <operationlist>
|
||||
<weekdayslist> <timeperiodslist> <b><br>
|
||||
nocountout</b> <userlist> <sourcelist>
|
||||
<weekdayslist> <timeperiodslist></i> <b><br>
|
||||
nocountout</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist> <b><br>
|
||||
countall</b> <number> <type> <limit>
|
||||
<timeperiodslist></i> <b><br>
|
||||
countall</b> <i><number> <type> <limit>
|
||||
<userlist> <sourcelist> <targetlist>
|
||||
<targetportlist> <operationlist>
|
||||
<weekdayslist> <timeperiodslist> <b><br>
|
||||
nocountall</b> <userlist> <sourcelist>
|
||||
<weekdayslist> <timeperiodslist></i> <b><br>
|
||||
nocountall</b> <i><userlist> <sourcelist>
|
||||
<targetlist> <targetportlist>
|
||||
<operationlist> <weekdayslist>
|
||||
<timeperiodslist></p>
|
||||
<timeperiodslist></i></p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em">counter,
|
||||
countin, nocountin, countout, nocountout, countall,
|
||||
|
|
@ -885,28 +904,27 @@ not preserved in the counter file (that is, if the proxy is
|
|||
restarted, all counters with 0 are flushed); otherwise, it
|
||||
should be a unique sequential number which points to the
|
||||
position of the counter within the file. Type specifies a
|
||||
type of counter. Type is one of: <br>
|
||||
H - counter is reset hourly <br>
|
||||
D - counter is reset daily <br>
|
||||
W - counter is reset weekly <br>
|
||||
M - counter is reset monthly <br>
|
||||
type of counter. Type is one of: <b><br>
|
||||
H</b> - counter is reset hourly <b><br>
|
||||
D</b> - counter is reset daily <b><br>
|
||||
W</b> - counter is reset weekly <b><br>
|
||||
M</b> - counter is reset monthly <br>
|
||||
reporttype/reportname may be used to generate traffic
|
||||
reports. Reporttype is one of D, W, M, H (hourly) and
|
||||
reportname specifies the filename template for reports. The
|
||||
report is a text file with counter values in the format:
|
||||
<br>
|
||||
<COUNTERNUMBER> <TRAF> <br>
|
||||
<i><br>
|
||||
<COUNTERNUMBER> <TRAF></i> <br>
|
||||
The rest of parameters is identical to
|
||||
bandlim/nobandlim.</p>
|
||||
<b>bandlim</b>/<b>nobandlim</b>.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>users</b>
|
||||
username[:pwtype:password] ... <br>
|
||||
<i>username</i>[:<i>pwtype</i>:<i>password</i>] ... <br>
|
||||
pwtype is one of: <br>
|
||||
none (empty) - use system authentication <br>
|
||||
CL - password is cleartext <br>
|
||||
CR - password is crypt-style password <br>
|
||||
NT - password is NT password (in hex) <br>
|
||||
LM - password is LM password (in hex) <br>
|
||||
none (empty) - use system authentication <b><br>
|
||||
CL</b> - password is cleartext <b><br>
|
||||
CR</b> - password is crypt-style password <b><br>
|
||||
NT</b> - password is NT password (in hex) <br>
|
||||
example: <br>
|
||||
users test1:CL:password1
|
||||
"test2:CR:$1$lFDGlder$pLRb4cU2D7GAT58YQvY49." <br>
|
||||
|
|
@ -938,42 +956,43 @@ socks <br>
|
|||
sets different ACLs for <b>pop3p</b> and <b>socks</b></p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>system</b>
|
||||
<command> <br>
|
||||
<i><command></i> <br>
|
||||
execute system command</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>pidfile</b>
|
||||
<filename> <br>
|
||||
<i><filename></i> <br>
|
||||
write pid of current process to file. It can be used to
|
||||
manipulate 3proxy with signals under Unix. Currently next
|
||||
signals are available:</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>monitor</b>
|
||||
<filename> <br>
|
||||
<i><filename></i> <br>
|
||||
If file monitored changes in modification time or size,
|
||||
3proxy reloads configuration within one minute. Any number
|
||||
of files may be monitored.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>setuid</b>
|
||||
<uid> <br>
|
||||
<i><uid></i> <br>
|
||||
calls setuid(uid), uid can be numeric or since 0.9 username.
|
||||
Unix only. Warning: under some Linux kernels setuid() works
|
||||
for current thread only. It makes it impossible to suid for
|
||||
all threads.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>setgid</b>
|
||||
<gid> <br>
|
||||
<i><gid></i> <br>
|
||||
calls setgid(gid), gid can be numeric or since 0.9
|
||||
groupname. Unix only.</p>
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>chroot</b>
|
||||
<path> [<uid>] [<gid>] <br>
|
||||
<i><path></i> [<i><uid></i>]
|
||||
[<i><gid></i>] <br>
|
||||
calls chroot(path) and sets gid/uid. Unix only. uid/gid
|
||||
supported since 0.9, can be numeric or
|
||||
username/groupname</p>
|
||||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>stacksize</b>
|
||||
<value_to_add_to_default_stack_size> <br>
|
||||
<i><value_to_add_to_default_stack_size></i> <br>
|
||||
Change the default size for thread stacks. May be required
|
||||
in some situations, e.g. with non-default plugins, or on
|
||||
some platforms (some FreeBSD versions may require adjusting
|
||||
|
|
@ -992,8 +1011,8 @@ negative values.</p>
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>plugin</b>
|
||||
<path_to_shared_library> <function_to_call>
|
||||
[<arg1> ...] <br>
|
||||
<i><path_to_shared_library>
|
||||
<function_to_call></i> [<i><arg1></i> ...] <br>
|
||||
Loads specified library and calls given export function with
|
||||
given arguments, as <br>
|
||||
int functions_to_call(struct pluginlink * pl, int argc, char
|
||||
|
|
@ -1003,7 +1022,7 @@ function_to_call must return 0 in case of success, value
|
|||
|
||||
|
||||
<p style="margin-left:6%; margin-top: 1em"><b>filtermaxsize</b>
|
||||
<max_size_of_data_to_filter> <br>
|
||||
<i><max_size_of_data_to_filter></i> <br>
|
||||
If Content-length (or another data length) is greater than
|
||||
the given value, no data filtering will be performed through
|
||||
filtering plugins to avoid data corruption and/or
|
||||
|
|
|
|||
|
|
@ -983,7 +983,7 @@ openssl pkcs12 -export -out client.p12 -passout pass: \
|
|||
или
|
||||
<pre>
|
||||
users $"c:\Program Files\3proxy\passwords"</pre>
|
||||
Шифрованные NT и crypt пароли можно создавать с помощью утилиты mycrypt.
|
||||
Шифрованные NT и crypt пароли можно создавать с помощью утилиты 3proxy_crypt.
|
||||
<br>Список пользователей един для всех служб. Разграничение доступа по службам
|
||||
необходимо производить с помощью списков доступа.
|
||||
</p>
|
||||
|
|
|
|||
|
|
@ -969,7 +969,7 @@ or
|
|||
<pre>
|
||||
users $"c:\Program Files\3proxy\passwords"
|
||||
</pre>
|
||||
It's possible to create NT and crypt passwords with the mycrypt utility included
|
||||
It's possible to create NT and crypt passwords with the 3proxy_crypt utility included
|
||||
in the distribution.
|
||||
<br>The user list is system-wide. To manage user access to a specific service, use ACLs.
|
||||
</p>
|
||||
|
|
|
|||
2
ftppr.md
2
ftppr.md
|
|
@ -198,7 +198,7 @@ with FTP proxy support, configure <i>internal_ip</i> and
|
|||
FTP proxy support, use <i>internal_ip</i> and <i>port</i> as
|
||||
the FTP server. The address of the real FTP server must be
|
||||
configured as a part of the FTP username. The format for the
|
||||
username is <i>username</i><b>@</b><i>server</i>, where
|
||||
username is <i>username</i>@<i>server</i>, where
|
||||
<i>server</i> is the address of the FTP server and
|
||||
<i>username</i> is the user´s login on this FTP
|
||||
server. The login itself may contain an ´@´
|
||||
|
|
|
|||
4
pop3p.md
4
pop3p.md
|
|
@ -196,8 +196,8 @@ MUA (Mail User Agent) with POP3 support. Set the client to
|
|||
use <i>internal_ip</i> and <i>port</i> as a POP3 server. The
|
||||
address of the real POP3 server must be configured as a part
|
||||
of the POP3 username. The format for the username is
|
||||
<i>username</i><b>@</b><i>server</i>, where <i>server</i> is
|
||||
the address of the POP3 server and <i>username</i> is the
|
||||
<i>username</i>@<i>server</i>, where <i>server</i> is the
|
||||
address of the POP3 server and <i>username</i> is the
|
||||
user´s login on this POP3 server. The login itself may
|
||||
contain an ´@´ sign. Only cleartext
|
||||
authentication is supported, because challenge-response
|
||||
|
|
|
|||
2
smtpp.md
2
smtpp.md
|
|
@ -196,7 +196,7 @@ MUA (Mail User Agent) with SMTP authentication support. Set
|
|||
the client to use <i>internal_ip</i> and <i>port</i> as an
|
||||
SMTP server. The address of the real SMTP server must be
|
||||
configured as a part of the SMTP username. The format for
|
||||
the username is <i>username</i><b>@</b><i>server</i>, where
|
||||
the username is <i>username</i>@<i>server</i>, where
|
||||
<i>server</i> is the address of the SMTP server and
|
||||
<i>username</i> is the user´s login on this SMTP
|
||||
server. The login itself may contain an ´@´
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue