Compare commits

..

No commits in common. "0ae2754c1e2ea44f3c821e00ba3f268dd2dfebdc" and "7b85f6a6843ac13e830c75a982ce95eb41412bba" have entirely different histories.

16 changed files with 1791 additions and 2085 deletions

View File

@ -1,2 +1,2 @@
<H2><A href="howtoe.html">See HowTo:</a></h2> <H2><A href="howtoe.html">See HowTo:</a></H2>

View File

@ -1,2 +1,2 @@
<H2><A href="howtoe.html">См. HowTo</a></h2> <H2><A href="howtoe.html">См. HowTo</a></H2>

View File

@ -5,8 +5,8 @@
<h4>Configuring 'maxconn'</h4> <h4>Configuring 'maxconn'</h4>
The number of simultaneous connections per service is limited by the 'maxconn' option. The number of simultaneous connections per service is limited by the 'maxconn' option.
The default maxconn value is 500. You may want to set 'maxconn' The default maxconn value since 3proxy 0.8 is 500. You may want to set 'maxconn'
to a higher value; it must be set before the services it should apply to. Under this configuration: to a higher value. Under this configuration:
<pre> <pre>
maxconn 1000 maxconn 1000
proxy -p3129 proxy -p3129
@ -19,10 +19,6 @@ simultaneous connections to 3proxy.
<p>Avoid setting 'maxconn' to an arbitrarily high value; it should be carefully <p>Avoid setting 'maxconn' to an arbitrarily high value; it should be carefully
chosen to protect the system and proxy from resource exhaustion. Setting maxconn chosen to protect the system and proxy from resource exhaustion. Setting maxconn
above available resources can lead to denial of service conditions. above available resources can lead to denial of service conditions.
<p>'maxconn' is not reduced automatically to fit the open file limit. If the limit is
too low 3proxy only prints a warning at startup
("current open file ulimits are too low") and then fails to accept connections once
the limit is reached, so check for this warning after changing 'maxconn'.
<h4>Understanding Resource Requirements</h4> <h4>Understanding Resource Requirements</h4>
Each running service requires: Each running service requires:
<ul> <ul>
@ -60,45 +56,19 @@ system "ulimit -Sa >>/tmp/3proxy.ulim.soft"
at the beginning (before the first service is started) and at the end of the config file. at the beginning (before the first service is started) and at the end of the config file.
Perform both a hard restart (i.e., kill and start the 3proxy process) and a soft restart Perform both a hard restart (i.e., kill and start the 3proxy process) and a soft restart
by sending SIGUSR1 to the 3proxy process; check that the ulimits recorded to files match your by sending SIGUSR1 to the 3proxy process; check that the ulimits recorded to files match your
expectations. In systemd-based distros (e.g., latest Debian/Ubuntu) changing limits.conf is not expectations. In systemd-based distros (e.g., latest Debian/Ubuntu), changing limits.conf
enough for a service: limits must be set in the unit file. Set them in the 3proxy is not enough; limits must be adjusted in the systemd configuration, e.g., by setting:
unit itself rather than globally, so the rest of the system is unaffected. The
shipped 3proxy.service already contains:
<pre> <pre>
LimitNOFILE=1048576 DefaultLimitDATA=infinity
LimitNPROC=infinity DefaultLimitSTACK=infinity
TasksMax=infinity DefaultLimitCORE=infinity
</pre> DefaultLimitRSS=infinity
To change them on an installed system use an override instead of editing the unit: DefaultLimitNOFILE=102400
<pre> DefaultLimitAS=infinity
systemctl edit 3proxy DefaultLimitNPROC=10240
systemctl daemon-reload &amp;&amp; systemctl restart 3proxy DefaultLimitMEMLOCK=infinity
systemctl show 3proxy -p LimitNOFILE -p LimitNPROC -p TasksMax
</pre>
<b>TasksMax is the one that is easy to miss.</b> It is the cgroup limit on the number
of threads, and if it is not set the unit inherits DefaultTasksMax, which is 15% of
kernel.threads-max (about 9000 on a typical host). Since 3proxy uses one thread per
connection, that caps concurrent connections at that number regardless of LimitNPROC
and maxconn, and the only symptom is "pthread_create()" errors in the log.
<p>On systemd older than 227, which has no TasksMax, and for limits that must apply to
several services, the same values can be set globally as DefaultLimitNOFILE /
DefaultLimitNPROC in /etc/systemd/system.conf, but prefer the per-unit settings.
<p>With SysV init the limits are not applied by limits.conf either, because
start-stop-daemon does not open a PAM session, so the daemon simply inherits the limits
of init. The shipped init script raises them itself before starting 3proxy:
<pre>
ulimit -n 65536
ulimit -u 32768
</pre>
adjust these values in the script to match 'maxconn'.
<p>On FreeBSD rc.subr applies limits(1) with the login class of the service (the
"daemon" class by default), so the limits can be set either in /etc/login.conf for that
class, or per service in rc.conf:
<pre>
3proxy_limits="-n 65536"
</pre> </pre>
in user.conf / system.conf
<h4>Extending System Limitations</h4> <h4>Extending System Limitations</h4>
@ -113,168 +83,6 @@ proxy -olSO_REUSEADDR,SO_REUSEPORT -ocTCP_TIMESTAMPS,TCP_NODELAY -osTCP_NODELAY
</pre> </pre>
Available options are system-dependent. Available options are system-dependent.
<h4>Linux Tuning Hints</h4>
Values below are examples, not recommendations: check the current value first
(<tt>sysctl NAME</tt>), change only what your workload actually hits, and make changes
persistent in <tt>/etc/sysctl.d/</tt>. Defaults given in parentheses are from a recent
(6.x) kernel and vary between distributions and versions.
<p><b>File descriptors.</b> 3proxy needs 2 descriptors per connection (4 for FTP), plus
one per service, plus temporary ones for name resolution and RADIUS.
<pre>
fs.nr_open = 1048576 &#35; (1048576) upper bound for any process' RLIMIT_NOFILE
</pre>
<tt>ulimit -n</tt> (RLIMIT_NOFILE) is the limit that actually applies and is commonly
left at 1024; it must be raised for the 3proxy process itself, see "Setting ulimits"
above. <tt>fs.file-max</tt> is effectively unlimited on 64-bit kernels and rarely needs
changing.
<p><b>Threads.</b> Because of the "one connection - one thread" model these limits are
reached earlier with 3proxy than with event-driven servers. Each thread also consumes
one or two mappings, so <tt>vm.max_map_count</tt> matters too.
<pre>
kernel.threads-max = 200000 &#35; (~60000 on a 16G host, scales with RAM)
kernel.pid_max = 4194304 &#35; (4194304)
vm.max_map_count = 1048576 &#35; (1048576)
</pre>
RLIMIT_NPROC (<tt>ulimit -u</tt>) limits threads per user and must be raised as well.
Check the actual thread count with <tt>grep Threads /proc/PID/status</tt>.
<p><b>Listen queue.</b> 3proxy uses a listen backlog of 1+(maxconn/8) unless the
'backlog' command is given, so a large 'maxconn' does not automatically give a large
queue, and the kernel caps it at somaxconn:
<pre>
net.core.somaxconn = 4096 &#35; (4096)
net.ipv4.tcp_max_syn_backlog = 4096 &#35; (512) raise for bursty connection rates
net.ipv4.tcp_syncookies = 1 &#35; (1) keep enabled
</pre>
<p><b>Ephemeral ports and TIME_WAIT.</b> See "Extending the Ephemeral Port Range" above
for the multi-IP case. The range gives about 28000 outgoing connections per
destination address by default:
<pre>
net.ipv4.ip_local_port_range = 10240 65535 &#35; (32768 60999)
net.ipv4.tcp_tw_reuse = 2 &#35; (2) reuse TIME_WAIT for outgoing connections
net.ipv4.tcp_fin_timeout = 30 &#35; (60)
</pre>
Do not enable tcp_tw_recycle; it was removed in kernel 4.12 and breaks NAT clients.
<p><b>Socket buffers.</b> Autotuning is usually right. Buffer memory is per connection,
so raising the maximums with tens of thousands of connections costs a lot of RAM:
<pre>
net.core.rmem_max = 4194304 &#35; (212992)
net.core.wmem_max = 4194304 &#35; (212992)
net.ipv4.tcp_rmem = 4096 131072 6291456 &#35; (same) min default max
net.ipv4.tcp_wmem = 4096 16384 4194304 &#35; (same)
</pre>
Raise these only for high bandwidth-delay product links, and prefer raising the third
(max) value and leaving the default alone.
<p><b>Conntrack.</b> Only relevant if netfilter/nftables tracks the proxy's traffic. If
it does, the table is exhausted long before 3proxy's own limits, with
"nf_conntrack: table full, dropping packet" in dmesg:
<pre>
net.netfilter.nf_conntrack_max = 1048576
net.netfilter.nf_conntrack_buckets = 262144
net.netfilter.nf_conntrack_tcp_timeout_established = 3600 &#35; (432000, i.e. 5 days)
net.netfilter.nf_conntrack_tcp_timeout_time_wait = 30 &#35; (120)
</pre>
nf_conntrack_max defaults to nf_conntrack_buckets, which itself is derived from the
amount of RAM, so it is often much lower than expected on small machines. Each
connection takes two entries (one per direction). The default established timeout of
5 days matters more than the table size with high connection churn: entries for
connections that are long gone keep occupying the table.
<p>If no rules need conntrack, not loading it at all is faster: the modules are loaded
on demand by the first rule that needs them ("-m state", "-m conntrack", any NAT
rule), so a ruleset without such rules keeps the proxy traffic untracked. If conntrack
is needed for other traffic but not for the proxy's, exempt the proxy's traffic
explicitly in the raw table:
<pre>
iptables -t raw -A PREROUTING -p tcp --dport 3128 -j CT --notrack
iptables -t raw -A OUTPUT -p tcp -m owner --uid-owner proxy -j CT --notrack
</pre>
<p><b>Conntrack helpers (ALGs).</b> The helper modules - nf_conntrack_ftp,
nf_conntrack_sip, nf_conntrack_h323, nf_conntrack_pptp, nf_conntrack_irc,
nf_conntrack_tftp - inspect the payload of every matching packet and create additional
"expectation" entries, so they cost both CPU and table space, and they have a long
history of security issues. Unload and blacklist the ones you do not actually need:
<pre>
lsmod | grep nf_conntrack
modprobe -r nf_conntrack_sip nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_pptp
echo "blacklist nf_conntrack_sip" >> /etc/modprobe.d/no-alg.conf
</pre>
On current kernels a helper only acts when it is attached explicitly
("-j CT --helper ftp"), so simply not attaching it is enough; automatic helper
assignment was deprecated and later removed. Older kernels, and most router firmware,
still enable them by default.
<p><b>Checking the result.</b> <tt>ss -s</tt> for socket state totals,
<tt>ss -lnt</tt> for listen queue overflow, <tt>nstat -az TcpExtListenOverflows
TcpExtListenDrops</tt> for accept queue drops, and
<tt>cat /proc/PID/limits</tt> for the limits actually applied to the running process.
<h4>Windows Tuning Hints</h4>
<p><b>Dynamic (ephemeral) port range.</b> Since Windows Vista / Server 2008 the default
range is 49152-65535, i.e. only 16384 outgoing connections per local address, which is
reached quickly by a busy proxy. Show and change it with:
<pre>
netsh int ipv4 show dynamicport tcp
netsh int ipv4 set dynamicport tcp start=10000 num=55535
</pre>
The minimum start port is 1025, the minimum size of the range is 255, and the end of
the range cannot exceed 65535. The range is set separately for TCP and UDP, and for
IPv4 and IPv6. On pre-Vista systems the equivalent is the MaxUserPort registry value
in HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters.
<p><b>Listening socket.</b> 3proxy sets SO_REUSEADDR on the listening socket by
default on Unix, but not on Windows: there it is not needed to rebind the port, and it
only allows another local process to bind the same address and port, with undefined
behaviour as to which of them receives the connections. If the machine is shared or
untrusted, harden the listening socket instead:
<pre>
proxy -olSO_EXCLUSIVEADDRUSE
</pre>
Note that a socket with SO_EXCLUSIVEADDRUSE may not be immediately rebindable after a
restart if accepted connections are still active, so test restarts before using it.
<p><b>Port reuse.</b> 3proxy always binds the outgoing socket before connecting, so
Windows does not apply its automatic ephemeral port reuse (which it does only for
connections with an implicit bind). Setting the option explicitly on the
proxy-to-server socket therefore helps against port exhaustion:
<pre>
proxy -osSO_REUSE_UNICASTPORT
</pre>
SO_REUSE_UNICASTPORT requires Windows 10 / Server 2019 or later. On older systems
(Windows 7 / Server 2008 and later) use SO_PORT_SCALABILITY instead; where both are
available Microsoft recommends SO_REUSE_UNICASTPORT. Note that SO_REUSEADDR has
different, weaker semantics on Windows than on Unix and allows another socket to bind
the same address and port, so do not use it on the listening socket as a substitute.
<p><b>TIME_WAIT.</b> Closed connections hold their port for the TcpTimedWaitDelay
period, set in
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters (DWORD, seconds). The
effective default differs between Windows versions (2 to 4 minutes); check the current
behaviour before changing it, and lower it only together with an extended port range.
Count the connections in that state with:
<pre>
netstat -ano -p tcp | find /c "TIME_WAIT"
</pre>
<p><b>Threads and address space.</b> Windows has no ulimit equivalent, and the handle
count is not normally the limit. On 32-bit builds the 2 GB of user address space is:
each connection thread reserves its stack there, so a few thousand connections can
exhaust the address space while physical memory is still free. Use a 64-bit build for high load, and
see "Setting Stack Size" above.
<p><b>Filter drivers.</b> Antivirus, endpoint protection and other LSP/WFP filter
drivers inspect every connection and are frequently the actual bottleneck on Windows,
costing far more than any tuning above can recover. Exclude the 3proxy process and its
ports, or test with the protection temporarily disabled to see the difference before
tuning anything else.
<h4>Using 3proxy in a Virtual Environment</h4> <h4>Using 3proxy in a Virtual Environment</h4>
If 3proxy is used in a VPS environment, there can be additional limitations. If 3proxy is used in a VPS environment, there can be additional limitations.
@ -340,10 +148,10 @@ Under the latest Linux versions, you can also start multiple services with diffe
external addresses on a single port with SO_REUSEPORT on the listening socket to external addresses on a single port with SO_REUSEPORT on the listening socket to
evenly distribute incoming connections between outgoing interfaces: evenly distribute incoming connections between outgoing interfaces:
<pre> <pre>
socks -olSO_REUSEPORT -p3128 -e1.1.1.1 socks -olSO_REUSEPORT -p3128 -e 1.1.1.1
socks -olSO_REUSEPORT -p3128 -e2.2.2.2 socks -olSO_REUSEPORT -p3128 -e 2.2.2.2
socks -olSO_REUSEPORT -p3128 -e3.3.3.3 socks -olSO_REUSEPORT -p3128 -e 3.3.3.3
socks -olSO_REUSEPORT -p3128 -e4.4.4.4 socks -olSO_REUSEPORT -p3128 -e 4.4.4.4
</pre> </pre>
For web browsing, the last two examples are not recommended because the same client can get For web browsing, the last two examples are not recommended because the same client can get
a different external address for different requests; you should choose the external a different external address for different requests; you should choose the external
@ -364,39 +172,6 @@ randomly fail due to IP+port pair collisions if the remote or local system
doesn't support this trick. doesn't support this trick.
</ol> </ol>
<h4>NAT on the Path Must Be Tuned Too</h4>
Everything above tunes the machine 3proxy runs on. If the outgoing traffic passes
through NAT - a router, a firewall, a CGNAT of the provider, or a cloud NAT gateway -
that device keeps its own translation table and its own pool of source ports, and it
limits the number of connections independently of the proxy. Extending
ip_local_port_range on the 3proxy host changes nothing if the NAT device rewrites the
source port from its own, smaller pool.
<p>On a Linux based router the same knobs apply and have to be raised there as well:
nf_conntrack_max / nf_conntrack_buckets and the conntrack timeouts (see "Linux Tuning
Hints" above), plus the port range used for translation, which is ip_local_port_range
for MASQUERADE, or the explicit range if SNAT is configured with --to-ports. Note that
the range is per translated address: with a single public IP, all clients share it.
<p>Entry level and SOHO routers are the usual bottleneck here. They typically have a
small fixed NAT/conntrack table (a few thousand entries), aggressive or non-adjustable
timeouts, and no way to change either. Symptoms are seen on the proxy but caused by the
router: connections that fail or hang at random under load while the proxy is far from
its own limits, no error in the 3proxy log except a failed outgoing connect, and
recovery after a pause or a router reboot. Before tuning 3proxy further, check the
router's session/NAT table counters. For high load either give the proxy a public
address without NAT in the path, or use a router where the table size and timeouts are
configurable.
<p>On the router, also turn off the application layer gateways that are not actually
used - they usually appear in the web interface as "SIP ALG", "FTP ALG", "H.323 ALG",
"PPTP passthrough", "IPsec/VPN passthrough". They are commonly enabled by default, they
parse the payload of matching connections, and they consume additional session table
entries for the connections they expect. If nothing behind the proxy uses FTP, VoIP or
those VPN protocols, disabling them frees table space and CPU on exactly the device
that is the bottleneck.
<h4>Setting Stack Size</h4> <h4>Setting Stack Size</h4>
'stacksize' is a size added to all stack allocations and can be both positive and 'stacksize' is a size added to all stack allocations and can be both positive and
@ -412,11 +187,7 @@ the need to add additional physical memory,
but it's system/libc dependent and requires additional testing under your but it's system/libc dependent and requires additional testing under your
installation. Don't forget about memory-related ulimits. installation. Don't forget about memory-related ulimits.
<p>For 32-bit systems, address space can be a bottleneck you should consider. If <p>For 32-bit systems, address space can be a bottleneck you should consider. If
you're short on address space, you can try using a negative stack size. The result is you're short on address space, you can try using a negative stack size.
never lowered below the system minimum (PTHREAD_STACK_MIN), so a large negative value
can not disable the thread stack. The base value the 'stacksize' is added to is 48K
(64K on FreeBSD/NetBSD/OpenBSD/DragonFly, where libc uses more stack, e.g. in
vfprintf() called by syslog()).
<h4>Known System Issues</h4> <h4>Known System Issues</h4>
@ -495,5 +266,5 @@ The example above adds a 10-millisecond delay before reading data if the average
polling size is below 8000 bytes and 3 read operations have been made in the same polling size is below 8000 bytes and 3 read operations have been made in the same
direction. <pre>logdump 1 1</pre> is useful direction. <pre>logdump 1 1</pre> is useful
to see how grace delays work; choose a delay value to avoid filling the read to see how grace delays work; choose a delay value to avoid filling the read
buffer (typically 64K) but keep the request sizes close to the chosen average pipe/buffer (typically 64K) but keep the request sizes close to the chosen average
on large file uploads/downloads. on large file uploads/downloads.

View File

@ -2,20 +2,20 @@
<li>3APA3A 3proxy Tiny Proxy Server HowTo <li>3APA3A 3proxy Tiny Proxy Server HowTo
<br>Under construction, very incomplete <br>Under construction, very incomplete
<ul> <ul>
<li><A HREF="#COMPILE">Compilation</a> <li><A HREF="#COMPILE">Compilation</A>
<ul> <ul>
<li><A HREF="#MSVC">How to compile 3proxy with Visual C++</a> <li><A HREF="#MSVC">How to compile 3proxy with Visual C++</A>
<li><A HREF="#CMAKE">How to compile 3proxy with CMake</a> <li><A HREF="#CMAKE">How to compile 3proxy with CMake</A>
<li><A HREF="#GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</a> <li><A HREF="#GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</A>
</ul> </ul>
<li><A HREF="#INSTALL">Proxy server installation and removal</a> <li><A HREF="#INSTALL">Proxy server installation and removal</A>
<ul> <ul>
<li><A HREF="#INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</a> <li><A HREF="#INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</A>
<li><A HREF="#INSTUNIX">How to install/remove 3proxy under Unix/Linux</a> <li><A HREF="#INSTUNIX">How to install/remove 3proxy under Unix/Linux</A>
<li><A HREF="#INSTMACOS">How to install/remove 3proxy under macOS</a> <li><A HREF="#INSTMACOS">How to install/remove 3proxy under macOS</A>
<li><A HREF="#INSTDOCKER">How to use 3proxy with Docker</a> <li><A HREF="#INSTDOCKER">How to use 3proxy with Docker</A>
</ul> </ul>
<li><A HREF="#SERVER">Server configuration</a> <li><A HREF="#SERVER">Server configuration</A>
<ul> <ul>
<li><a href="#NOTHING">How to make 3proxy start</a></li> <li><a href="#NOTHING">How to make 3proxy start</a></li>
<li><a href="#LIMITS">How to make limitations (access, bandwidth, traffic, connections) work</a></li> <li><a href="#LIMITS">How to make limitations (access, bandwidth, traffic, connections) work</a></li>
@ -24,11 +24,11 @@
<li><a href="#ODBC">How to make ODBC logging work?</a></li> <li><a href="#ODBC">How to make ODBC logging work?</a></li>
<li><a href="#IPV6">How to make IPv6 work</a></li> <li><a href="#IPV6">How to make IPv6 work</a></li>
<li><a href="#CRASH">How to fix 3proxy crashes</a></li> <li><a href="#CRASH">How to fix 3proxy crashes</a></li>
<li><A HREF="#SAMPLE">Where to find a configuration example</a> <li><A HREF="#SAMPLE">Where to find a configuration example</A>
<li><A HREF="#LOGGING">How to set up logging</a> <li><A HREF="#LOGGING">How to set up logging</A>
<li><A HREF="#LOGFORMAT">How to set up logging format</a> <li><A HREF="#LOGFORMAT">How to set up logging format</A>
<li><A HREF="#LOGANALIZERS">How to use log analyzers with 3proxy</a> <li><A HREF="#LOGANALIZERS">How to use log analyzers with 3proxy</A>
<li><A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a> <li><A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>
<li><a href="#BIND">How to bind a service to a specific interface or port</a> <li><a href="#BIND">How to bind a service to a specific interface or port</a>
<li><a href="#NAMES">How to resolve names through a parent proxy</a></li> <li><a href="#NAMES">How to resolve names through a parent proxy</a></li>
<li><a href="#ISFTP">How to set up an FTP proxy</a></li> <li><a href="#ISFTP">How to set up an FTP proxy</a></li>
@ -37,39 +37,39 @@
<li><a href="#SSLPLUGIN">How to set up TLS/SSL (https proxy, mTLS)</a></li> <li><a href="#SSLPLUGIN">How to set up TLS/SSL (https proxy, mTLS)</a></li>
<li><a href="#CERTIFICATES">How to create CA and certificates for SSL</a></li> <li><a href="#CERTIFICATES">How to create CA and certificates for SSL</a></li>
<li><a href="#PCRE">How to use PCRE filtering (regular expressions)</a></li> <li><a href="#PCRE">How to use PCRE filtering (regular expressions)</a></li>
<li><A HREF="#AUTH">How to limit service access</a> <li><A HREF="#AUTH">How to limit service access</A>
<li><A HREF="#USERS">How to create a user list</a> <li><A HREF="#USERS">How to create a user list</A>
<li><A HREF="#ACL">How to limit user access to resources</a> <li><A HREF="#ACL">How to limit user access to resources</A>
<li><A HREF="#REDIR">How to manage redirections</a> <li><A HREF="#REDIR">How to manage redirections</A>
<li><a href="#SOCKSREDIR">How to manage local redirections</a> <li><a href="#SOCKSREDIR">How to manage local redirections</a>
<li><A HREF="#ROUNDROBIN">How to balance traffic between multiple external channels?</a> <li><A HREF="#ROUNDROBIN">How to balance traffic between multiple external channels?</A>
<li><A HREF="#CHAIN">How to manage proxy chains</a> <li><A HREF="#CHAIN">How to manage proxy chains</A>
<li><A HREF="#BANDLIM">How to limit bandwidth</a> <li><A HREF="#BANDLIM">How to limit bandwidth</A>
<li><A HREF="#TRAFLIM">How to limit traffic amount</a> <li><A HREF="#TRAFLIM">How to limit traffic amount</A>
<li><a href="#TRAF">How to fix incorrect traffic accounting</a> <li><a href="#TRAF">How to fix incorrect traffic accounting</a>
<li><A HREF="#NETLIST">How to build network lists</a> <li><A HREF="#NETLIST">How to build network lists</A>
<li><a href="#NSCACHING">How to configure name resolution and DNS caching</a> <li><a href="#NSCACHING">How to configure name resolution and DNS caching</a>
<li><a href="#IPV6">How to use IPv6</a> <li><a href="#IPV6">How to use IPv6</a>
<li><a href="#CONNBACK">How to use connect back</a> <li><a href="#CONNBACK">How to use connect back</a>
<li><a href="#HAPROXY">How to use HAProxy PROXY protocol</a> <li><a href="#HAPROXY">How to use HAProxy PROXY protocol</a>
<li><a href="#MAXSEG">How to set TCP maximum segment size (MSS)</a> <li><a href="#MAXSEG">How to set TCP maximum segment size (MSS)</a>
</ul> </ul>
<li><A HREF="#CLIENT">Client configuration</a> <li><A HREF="#CLIENT">Client configuration</A>
<li><A HREF="#ADMIN">Administering and information analysis</a> <li><A HREF="#ADMIN">Administering and information analysis</A>
<ul> <ul>
<li><A HREF="#NEWVERSION">How to obtain the latest 3proxy version</a> <li><A HREF="#NEWVERSION">How to obtain the latest 3proxy version</A>
<li><A HREF="#NTSERVICE">How to control the 3proxy service under Windows NT/2000/XP</a> <li><A HREF="#NTSERVICE">How to control the 3proxy service under Windows NT/2000/XP</A>
<li><A HREF="#ERRORS">Log error codes reference</a> <li><A HREF="#ERRORS">Log error codes reference</A>
</ul> </ul>
<li><A HREF="#QUEST">How to ask a question not in How To?</a> <li><A HREF="#QUEST">How to ask a question not in How To?</A>
</ul> </ul>
<br> <br>
<ul> <ul>
<hr> <hr>
<li><A NAME="COMPILE">Compilation</a> <li><A NAME="COMPILE">Compilation</A>
<p> <p>
<ul> <ul>
<li><A NAME="MSVC">How to compile 3proxy with Visual C++</a> <li><A NAME="MSVC">How to compile 3proxy with Visual C++</A>
<p> <p>
Extract source code files from 3proxy.tgz (with WinZip or another utility) or use git. Extract source code files from 3proxy.tgz (with WinZip or another utility) or use git.
@ -78,7 +78,7 @@ nmake /f Makefile.msvc
</pre> </pre>
Binaries will be placed in the <code>bin/</code> directory. Binaries will be placed in the <code>bin/</code> directory.
</p> </p>
<li><A NAME="CMAKE">How to compile 3proxy with CMake</a> <li><A NAME="CMAKE">How to compile 3proxy with CMake</A>
<p> <p>
CMake provides a cross-platform build system. It works on Windows (MSVC, MinGW), Linux, macOS, and BSD. CMake provides a cross-platform build system. It works on Windows (MSVC, MinGW), Linux, macOS, and BSD.
<br>Basic build steps: <br>Basic build steps:
@ -100,7 +100,7 @@ cmake -D3PROXY_USE_OPENSSL=ON -D3PROXY_USE_PCRE2=ON ..
Available options: 3PROXY_USE_OPENSSL, 3PROXY_USE_PCRE2, 3PROXY_USE_PAM, 3PROXY_USE_ODBC. Available options: 3PROXY_USE_OPENSSL, 3PROXY_USE_PCRE2, 3PROXY_USE_PAM, 3PROXY_USE_ODBC.
<br>Binaries will be placed in the <code>build/bin/</code> directory. <br>Binaries will be placed in the <code>build/bin/</code> directory.
</p> </p>
<li><A NAME="GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</a></li> <li><A NAME="GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</A></li>
<p> <p>
For Linux, use: For Linux, use:
<pre> <pre>
@ -121,14 +121,14 @@ and add the ODBC library to the linker variable.
</p> </p>
</ul> </ul>
<hr> <hr>
<li><A NAME="INSTALL">Proxy server installation and removal</a> <li><A NAME="INSTALL">Proxy server installation and removal</A>
<p> <p>
<ul> <ul>
<li><A NAME="INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</a> <li><A NAME="INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</A>
<p> <p>
Unpack 3proxy.zip to any directory, for example Unpack 3proxy.zip to any directory, for example
c:\Program Files\3proxy. If needed, create a directory for storing log files, c:\Program Files\3proxy. If needed, create a directory for storing log files,
ODBC sources, etc. Create 3proxy.cfg in the 3proxy installation directory (see <A HREF="#SERVER">Server configuration</a>). ODBC sources, etc. Create 3proxy.cfg in the 3proxy installation directory (see <A HREF="#SERVER">Server configuration</A>).
Now, start a command prompt (cmd.exe). Now, start a command prompt (cmd.exe).
Change to the 3proxy installation directory and run 3proxy.exe --install: Change to the 3proxy installation directory and run 3proxy.exe --install:
<pre> <pre>
@ -148,10 +148,10 @@ C:\Program Files\3proxy>3proxy.exe --remove
</pre> </pre>
Now you can simply remove the 3proxy installation directory. Now you can simply remove the 3proxy installation directory.
</p> </p>
<li><A NAME="INSTUNIX">How to install/remove 3proxy under Unix/Linux</a> <li><A NAME="INSTUNIX">How to install/remove 3proxy under Unix/Linux</A>
<p> <p>
<b>Using Makefile:</b> <b>Using Makefile:</b>
<br>Compile 3proxy (see <A HREF="#COMPILE">Compilation</a>) then run: <br>Compile 3proxy (see <A HREF="#COMPILE">Compilation</A>) then run:
<pre> <pre>
sudo make install sudo make install
</pre> </pre>
@ -186,7 +186,7 @@ sudo systemctl enable 3proxy
sudo systemctl start 3proxy sudo systemctl start 3proxy
</pre> </pre>
</p> </p>
<li><A NAME="INSTMACOS">How to install/remove 3proxy under macOS</a> <li><A NAME="INSTMACOS">How to install/remove 3proxy under macOS</A>
<p> <p>
<b>Using CMake (recommended):</b> <b>Using CMake (recommended):</b>
<pre> <pre>
@ -216,22 +216,22 @@ This installs binaries to <code>/usr/local/3proxy/bin/</code> and configuration
<b>Service management with launchd:</b> <b>Service management with launchd:</b>
<br>After installation via cmake, the service can be managed with launchctl: <br>After installation via cmake, the service can be managed with launchctl:
<pre> <pre>
&#35; Load and start the service # Load and start the service
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
&#35; Stop the service # Stop the service
sudo launchctl stop org.3proxy.3proxy sudo launchctl stop org.3proxy.3proxy
&#35; Start the service # Start the service
sudo launchctl start org.3proxy.3proxy sudo launchctl start org.3proxy.3proxy
&#35; Unload and disable the service # Unload and disable the service
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist
</pre> </pre>
The service runs as user <code>proxy</code> (created during installation). The service runs as user <code>proxy</code> (created during installation).
Configuration file: <code>/etc/3proxy/3proxy.cfg</code> Configuration file: <code>/etc/3proxy/3proxy.cfg</code>
</p> </p>
<li><A NAME="INSTDOCKER">How to use 3proxy with Docker</a> <li><A NAME="INSTDOCKER">How to use 3proxy with Docker</A>
<p> <p>
<b>Using pre-built images from GitHub Container Registry:</b> <b>Using pre-built images from GitHub Container Registry:</b>
<pre> <pre>
@ -264,7 +264,7 @@ For non-chroot execution, mount config to <code>/etc/3proxy</code>.
</p> </p>
</ul> </ul>
<hr> <hr>
<li><A NAME="SERVER">Server configuration</a> <li><A NAME="SERVER">Server configuration</A>
<p> <p>
<ul> <ul>
<li><a name="NOTHING">How to make 3proxy start</a> <li><a name="NOTHING">How to make 3proxy start</a>
@ -293,7 +293,7 @@ location as 3proxy.exe). For an alternative configuration file location, use
</ul> </ul>
<p><A NAME="INTEXT">How to understand internal and external</a> <p><A NAME="INTEXT">How to understand internal and external</A>
<p> <p>
Both internal and external IPs are IPs of the host running 3proxy itself. Both internal and external IPs are IPs of the host running 3proxy itself.
This configuration option is useful in situations where 3proxy is running on a This configuration option is useful in situations where 3proxy is running on a
@ -344,15 +344,15 @@ The best solution is to enable the option to resolve hostnames via the proxy on
The problem can be resolved with the 'stacksize' command or '-S' option starting with 3proxy 0.8.4. The problem can be resolved with the 'stacksize' command or '-S' option starting with 3proxy 0.8.4.
<li><A NAME="SAMPLE">Where to find a configuration example</a> <li><A NAME="SAMPLE">Where to find a configuration example</A>
<p> <p>
A server configuration example, 3proxy.cfg.sample, is included in every 3proxy distribution. A server configuration example, 3proxy.cfg.sample, is included in every 3proxy distribution.
</p> </p>
<li><A NAME="LOGGING">How to set up logging</a> <li><A NAME="LOGGING">How to set up logging</A>
<p> <p>
3proxy can log to stdout, a file, an ODBC datasource, or 3proxy can log to stdout, a file, an ODBC datasource, or
syslog (Unix/Linux/Cygwin only). To use ODBC under Unix/Linux, you must syslog (Unix/Linux/Cygwin only). To use ODBC under Unix/Linux, you must
compile 3proxy with Unix ODBC libraries; see <A HREF="#COMPILE">Compilation</a>. compile 3proxy with Unix ODBC libraries; see <A HREF="#COMPILE">Compilation</A>.
You can control logging from 3proxy.cfg for all services, or you can control You can control logging from 3proxy.cfg for all services, or you can control
logging for an individual service. For example, logging for an individual service. For example,
/usr/local/sbin/socks -l/var/log/socks.log starts a SOCKS proxy with logging to a file. /usr/local/sbin/socks -l/var/log/socks.log starts a SOCKS proxy with logging to a file.
@ -379,14 +379,14 @@ specify an ident for syslog logging. If the filename within the "log" command co
log c:\3proxy\logs\%y%m%d.log D creates a file like c:\3proxy\logs\060729.log; log c:\3proxy\logs\%y%m%d.log D creates a file like c:\3proxy\logs\060729.log;
the date is generated based on local time. the date is generated based on local time.
<pre> <pre>
log &connstring; log &connstring
</pre> </pre>
specifies an ODBC connection string; connstring is in the format specifies an ODBC connection string; connstring is in the format
datasource,username,password (the last two are optional if the datasource,username,password (the last two are optional if the
datasource does not require or already has authentication information). datasource does not require or already has authentication information).
Also, you must specify logformat to build the SQL query to insert a record into Also, you must specify logformat to build the SQL query to insert a record into
the log; see <A HREF="#LOGFORMAT">How to set up logging format</a> the log; see <A HREF="#LOGFORMAT">How to set up logging format</A>
</p> </p>
<p> <p>
Rotation and archiving may be set up with log, rotate, and archiver commands. Rotation and archiving may be set up with log, rotate, and archiver commands.
@ -416,7 +416,7 @@ sets the rotation type. LOGTYPE may be:
Examples are located in Examples are located in
3proxy.cfg.sample 3proxy.cfg.sample
</p> </p>
<li><A NAME="LOGFORMAT">How to set up logging format</a> <li><A NAME="LOGFORMAT">How to set up logging format</A>
<p> <p>
Since version 0.3, the log format may be set with the "logformat" command. Since version 0.3, the log format may be set with the "logformat" command.
The first symbol of the log format specifies the format of the date and time and The first symbol of the log format specifies the format of the date and time and
@ -437,7 +437,7 @@ sets the rotation type. LOGTYPE may be:
<li> %U - Username ('-' if unknown). <li> %U - Username ('-' if unknown).
<li> %N - Service name (PROXY, SOCKS, POP3P, etc.) <li> %N - Service name (PROXY, SOCKS, POP3P, etc.)
<li> %p - Service port <li> %p - Service port
<li> %E - Error code (see <A HREF="#ERRORS">Log error codes reference</a>) <li> %E - Error code (see <A HREF="#ERRORS">Log error codes reference</A>)
<li> %C - client IP <li> %C - client IP
<li> %c - client port <li> %c - client port
<li> %R - target IP <li> %R - target IP
@ -449,7 +449,7 @@ sets the rotation type. LOGTYPE may be:
<li> %O - bytes sent to the target <li> %O - bytes sent to the target
<li> %n - hostname from the request <li> %n - hostname from the request
<li> %h - hops before the target (if redirection or chaining is used); <li> %h - hops before the target (if redirection or chaining is used);
see <A HREF="#CHAIN">How to use chains and parent proxies</a>) see <A HREF="#CHAIN">How to use chains and parent proxies</A>)
<li> %T - service-specific text (for example, the requested URL). %X-YT, <li> %T - service-specific text (for example, the requested URL). %X-YT,
where X and Y are positive numbers, only displays fields where X and Y are positive numbers, only displays fields
(space-delimited) X to Y of the text. An example is %1-2T. (space-delimited) X to Y of the text. An example is %1-2T.
@ -472,7 +472,7 @@ logformat "-\'+_GINSERT INTO proxystat VALUES (%t, '%c', '%U', %I)"</pre>
<br>(no line breaks) <br>(no line breaks)
<br>-\'+_ instructs to replace characters \ and ' with _ <br>-\'+_ instructs to replace characters \ and ' with _
</p> </p>
<li><A NAME="LOGANALIZERS">How to use log analyzers with 3proxy</a> <li><A NAME="LOGANALIZERS">How to use log analyzers with 3proxy</A>
<p> <p>
Just make the format of 3proxy logs compatible with a format supported by your Just make the format of 3proxy logs compatible with a format supported by your
favorite log analyzer. Examples of compatible logformats are: favorite log analyzer. Examples of compatible logformats are:
@ -515,7 +515,7 @@ or a more compatible format without the error code:
<p><font face="courier"> <p><font face="courier">
&quot;-&quot;&quot;+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] &quot;&quot;%T&quot;&quot; 200 %I&quot; &quot;-&quot;&quot;+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] &quot;&quot;%T&quot;&quot; 200 %I&quot;
</p> </p>
<li><A NAME="LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a> <li><A NAME="LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>
<p> <p>
3proxy is distributed in 2 variants: as a set of standalone modules (proxy, 3proxy is distributed in 2 variants: as a set of standalone modules (proxy,
socks, pop3p, tcppm, udppm) and as a universal proxy server. These services are socks, pop3p, tcppm, udppm) and as a universal proxy server. These services are
@ -552,7 +552,7 @@ except socks, which is started with port 3129.
All logs are in the file /var/log/3proxy.log (with daily date modification and All logs are in the file /var/log/3proxy.log (with daily date modification and
rotation). The 30 most recent files are stored. rotation). The 30 most recent files are stored.
</p> </p>
<li><A NAME="BIND">How to bind a service to a specific interface and port?</a> <li><A NAME="BIND">How to bind a service to a specific interface and port?</A>
<p> <p>
The -i option specifies the internal interface; -p specifies the listening port. No spaces are The -i option specifies the internal interface; -p specifies the listening port. No spaces are
allowed. To bind the 'proxy' service to port 8080 on interfaces 192.168.1.1 allowed. To bind the 'proxy' service to port 8080 on interfaces 192.168.1.1
@ -606,17 +606,17 @@ tlspr supports both: for implicit TLS the destination host is taken from SNI and
the -X option makes tlspr speak the plaintext protocol phase with the client (greeting, STARTTLS command) before the -X option makes tlspr speak the plaintext protocol phase with the client (greeting, STARTTLS command) before
upgrading both sides to TLS. Example: upgrading both sides to TLS. Example:
</p><pre> </p><pre>
&#35; https (implicit) # https (implicit)
tlspr -p443 -P443 -c1 tlspr -p443 -P443 -c1
&#35; imaps (implicit) # imaps (implicit)
tlspr -p993 -P993 -c1 tlspr -p993 -P993 -c1
&#35; submissions (implicit) # submissions (implicit)
tlspr -p465 -P465 -c1 tlspr -p465 -P465 -c1
&#35; imap STARTTLS (explicit) # imap STARTTLS (explicit)
tlspr -p143 -P143 -Ximap tlspr -p143 -P143 -Ximap
&#35; submission STARTTLS (explicit) # submission STARTTLS (explicit)
tlspr -p587 -P587 -Xsmtp tlspr -p587 -P587 -Xsmtp
&#35; pop3 STLS (explicit) # pop3 STLS (explicit)
tlspr -p110 -P110 -Xpop3 tlspr -p110 -P110 -Xpop3
</pre> </pre>
<p> <p>
@ -679,7 +679,9 @@ socks
<p> <p>
3. Using tlspr with HTTP proxy for TLS hostname-based ACL: 3. Using tlspr with HTTP proxy for TLS hostname-based ACL:
</p><pre> </p><pre>
allow * * * * HTTP_CONNECT allow * * * 80
parent 1000 http 0.0.0.0 0
allow * * * 443
parent 1000 tls 0.0.0.0 0 parent 1000 tls 0.0.0.0 0
deny * * blocked.example.com deny * * blocked.example.com
allow * allow *
@ -705,15 +707,15 @@ nscache 65536
nscache6 65536 nscache6 65536
dnspr -p53 dnspr -p53
&#35; google # google
nsrecord smtp.gmail.com 10.0.0.1 nsrecord smtp.gmail.com 10.0.0.1
nsrecord imap.gmail.com 10.0.0.1 nsrecord imap.gmail.com 10.0.0.1
nsrecord pop.gmail.com 10.0.0.1 nsrecord pop.gmail.com 10.0.0.1
&#35; mail.ru # mail.ru
nsrecord smtp.mail.ru 10.0.0.1 nsrecord smtp.mail.ru 10.0.0.1
nsrecord imap.mail.ru 10.0.0.1 nsrecord imap.mail.ru 10.0.0.1
nsrecord pop.mail.ru 10.0.0.1 nsrecord pop.mail.ru 10.0.0.1
&#35; yandex.ru # yandex.ru
nsrecord smtp.yandex.ru 10.0.0.1 nsrecord smtp.yandex.ru 10.0.0.1
nsrecord imap.yandex.ru 10.0.0.1 nsrecord imap.yandex.ru 10.0.0.1
nsrecord pop.yandex.ru 10.0.0.1 nsrecord pop.yandex.ru 10.0.0.1
@ -825,10 +827,10 @@ This creates an HTTPS proxy (ssl_serv) that accepts TLS connections from clients
<b>Creating a Certificate Authority (CA):</b> <b>Creating a Certificate Authority (CA):</b>
<br>For MITM or mTLS, you need a CA. Generate a CA private key and certificate: <br>For MITM or mTLS, you need a CA. Generate a CA private key and certificate:
</p><pre> </p><pre>
&#35; Generate CA private key # Generate CA private key
openssl genrsa -out ca.key 4096 openssl genrsa -out ca.key 4096
&#35; Generate CA certificate (valid for 10 years) # Generate CA certificate (valid for 10 years)
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=My CA" \ -subj "/C=US/ST=State/L=City/O=MyOrg/CN=My CA" \
-out ca.crt -out ca.crt
@ -840,15 +842,15 @@ For MITM, import ca.crt into client browsers/OS as a trusted root CA.
<b>Creating a server certificate for https:// proxy:</b> <b>Creating a server certificate for https:// proxy:</b>
<br>The server certificate must have proper Subject Alternative Names (SAN): <br>The server certificate must have proper Subject Alternative Names (SAN):
</p><pre> </p><pre>
&#35; Generate server private key # Generate server private key
openssl genrsa -out server.key 2048 openssl genrsa -out server.key 2048
&#35; Create a certificate signing request (CSR) # Create a certificate signing request (CSR)
openssl req -new -key server.key \ openssl req -new -key server.key \
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=proxy.example.com" \ -subj "/C=US/ST=State/L=City/O=MyOrg/CN=proxy.example.com" \
-out server.csr -out server.csr
&#35; Create extensions file for SAN # Create extensions file for SAN
cat > server.ext << 'EOF' cat > server.ext << 'EOF'
authorityKeyIdentifier=keyid,issuer authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE basicConstraints=CA:FALSE
@ -862,7 +864,7 @@ DNS.2 = proxy
IP.1 = 192.168.1.100 IP.1 = 192.168.1.100
EOF EOF
&#35; Sign the certificate with CA # Sign the certificate with CA
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out server.crt -days 365 -sha256 \ -CAcreateserial -out server.crt -days 365 -sha256 \
-extfile server.ext -extfile server.ext
@ -873,27 +875,27 @@ For a public https:// proxy, use a CA like Let's Encrypt instead of self-signed.
<p> <p>
<b>Creating a client certificate for mTLS:</b> <b>Creating a client certificate for mTLS:</b>
</p><pre> </p><pre>
&#35; Generate client private key # Generate client private key
openssl genrsa -out client1.key 2048 openssl genrsa -out client1.key 2048
&#35; Create CSR # Create CSR
openssl req -new -key client1.key \ openssl req -new -key client1.key \
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=client1" \ -subj "/C=US/ST=State/L=City/O=MyOrg/CN=client1" \
-out client1.csr -out client1.csr
&#35; Create extensions file # Create extensions file
cat > client.ext << 'EOF' cat > client.ext << 'EOF'
basicConstraints=CA:FALSE basicConstraints=CA:FALSE
keyUsage = digitalSignature, nonRepudiation, keyEncipherment keyUsage = digitalSignature, nonRepudiation, keyEncipherment
extendedKeyUsage = clientAuth extendedKeyUsage = clientAuth
EOF EOF
&#35; Sign with CA # Sign with CA
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out client1.crt -days 365 -sha256 \ -CAcreateserial -out client1.crt -days 365 -sha256 \
-extfile client.ext -extfile client.ext
&#35; Create PKCS&#35;12 bundle for browser import # Create PKCS#12 bundle for browser import
openssl pkcs12 -export -out client1.p12 \ openssl pkcs12 -export -out client1.p12 \
-inkey client1.key -in client1.crt -certfile ca.crt -inkey client1.key -in client1.crt -certfile ca.crt
</pre> </pre>
@ -903,15 +905,15 @@ Import client1.p12 into the client browser or OS certificate store.
<p> <p>
<b>Quick setup script for development/testing:</b> <b>Quick setup script for development/testing:</b>
</p><pre> </p><pre>
&#35;!/bin/sh #!/bin/sh
&#35; Creates CA, server, and client certificates for SSLPlugin testing # Creates CA, server, and client certificates for SSLPlugin testing
&#35; CA # CA
openssl genrsa -out ca.key 4096 openssl genrsa -out ca.key 4096
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
-subj "/CN=3proxy CA" -out ca.crt -subj "/CN=3proxy CA" -out ca.crt
&#35; Server # Server
openssl genrsa -out server.key 2048 openssl genrsa -out server.key 2048
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
cat > server.ext << 'EOF' cat > server.ext << 'EOF'
@ -923,7 +925,7 @@ EOF
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext -CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
&#35; Client # Client
openssl genrsa -out client.key 2048 openssl genrsa -out client.key 2048
openssl req -new -key client.key -subj "/CN=client" -out client.csr openssl req -new -key client.key -subj "/CN=client" -out client.csr
cat > client.ext << 'EOF' cat > client.ext << 'EOF'
@ -980,13 +982,13 @@ matches the connection data.
<p> <p>
<b>Examples:</b> <b>Examples:</b>
</p><pre> </p><pre>
&#35; Block requests containing specific keywords for certain users # Block requests containing specific keywords for certain users
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16 pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
&#35; Block responses with specific content type # Block responses with specific content type
pcre srvheader deny "Content-type: application" pcre srvheader deny "Content-type: application"
&#35; Replace content in both directions (censorship) # Replace content in both directions (censorship)
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
pcre_extend deny * 192.168.0.1/16 pcre_extend deny * 192.168.0.1/16
</pre> </pre>
@ -994,11 +996,11 @@ pcre_extend deny * 192.168.0.1/16
<b>Note:</b> Regular expressions don't require authentication and cannot replace <b>Note:</b> Regular expressions don't require authentication and cannot replace
authentication and/or allow/deny ACLs. authentication and/or allow/deny ACLs.
</p> </p>
<li><A NAME="AUTH">How to limit service access</a> <li><A NAME="AUTH">How to limit service access</A>
<p> <p>
First, always specify the internal interface to accept incoming connections with the First, always specify the internal interface to accept incoming connections with the
'internal' configuration command or '-i' service command. (See 'internal' configuration command or '-i' service command. (See
<A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a>). If <A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>). If
no internal interface is specified, your proxy will act as an open proxy. no internal interface is specified, your proxy will act as an open proxy.
<p>It's also important to specify the external interface to prevent access to the <p>It's also important to specify the external interface to prevent access to the
internal network with 'external' or -e. internal network with 'external' or -e.
@ -1040,7 +1042,7 @@ socks
It's possible to authorize access by client IP address, IP address or requested resource, It's possible to authorize access by client IP address, IP address or requested resource,
target port, time, etc., after authentication. target port, time, etc., after authentication.
(See <A HREF="#ACL">How to limit resource access</a>). (See <A HREF="#ACL">How to limit resource access</A>).
</p><p>Since version 0.6, double authentication is possible, e.g.: </p><p>Since version 0.6, double authentication is possible, e.g.:
<pre> <pre>
auth iponly strong auth iponly strong
@ -1079,7 +1081,7 @@ critical resources, such as web administration.
auth cache strong</pre> auth cache strong</pre>
the user will not be able to use more than a single IP during the cache time (120 sec). the user will not be able to use more than a single IP during the cache time (120 sec).
</p> </p>
<li><A NAME="USERS">How to create a user list</a> <li><A NAME="USERS">How to create a user list</A>
<p> <p>
The user list is created with the 'users' command. The user list is created with the 'users' command.
<pre> <pre>
@ -1118,7 +1120,7 @@ It's possible to create NT and crypt passwords with the 3proxy_crypt utility inc
in the distribution. in the distribution.
<br>The user list is system-wide. To manage user access to a specific service, use ACLs. <br>The user list is system-wide. To manage user access to a specific service, use ACLs.
</p> </p>
<li><A NAME="ACL">How to limit user access to resources</a> <li><A NAME="ACL">How to limit user access to resources</A>
<p> <p>
The commands allow, deny, and flush are used to manage ACLs: The commands allow, deny, and flush are used to manage ACLs:
<p><font face="courier"> <p><font face="courier">
@ -1130,7 +1132,7 @@ allow &lt;userlist&gt; &lt;sourcelist&gt; &lt;targetlist&gt; &lt;targetportlist&
The 'flush' command is used to finish with the existing ACL and start a new one. The 'flush' command is used to finish with the existing ACL and start a new one.
It's required to have different ACLs for different services. It's required to have different ACLs for different services.
'allow' is used to allow a connection, and 'deny' to deny a connection. The 'allow' 'allow' is used to allow a connection, and 'deny' to deny a connection. The 'allow'
command can be extended by the 'parent' command to manage redirections (see <A href="#REDIR">How to manage redirections</a>). If the ACL command can be extended by the 'parent' command to manage redirections (see <A href="#REDIR">How to manage redirections</A>). If the ACL
is empty, it allows everything. If the ACL is not empty, the first matching ACL entry is empty, it allows everything. If the ACL is not empty, the first matching ACL entry
is searched for the user request, and the ACL action (allow or deny) is performed. If is searched for the user request, and the ACL action (allow or deny) is performed. If
no matching record is found, the connection is denied, and the user will be asked to no matching record is found, the connection is denied, and the user will be asked to
@ -1178,7 +1180,7 @@ add 'deny *' to the end of the list.
* in an ACL means &quot;any&quot;. * in an ACL means &quot;any&quot;.
Usage examples can be found in 3proxy.cfg.sample. Usage examples can be found in 3proxy.cfg.sample.
</p> </p>
<li><A NAME="REDIR">How to manage redirections</a> <li><A NAME="REDIR">How to manage redirections</A>
<p> <p>
Redirections are useful to, e.g., forward requests from specific clients Redirections are useful to, e.g., forward requests from specific clients
to different servers or proxy servers. Additionally, redirections are useful to different servers or proxy servers. Additionally, redirections are useful
@ -1237,22 +1239,22 @@ auth iponly
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http 0.0.0.0 0 parent 1000 http 0.0.0.0 0
allow * * * 80,8080-8088 allow * * * 80,8080-8088
&#35;redirect ports 80 and 8080-8088 to local HTTP proxy #redirect ports 80 and 8080-8088 to local HTTP proxy
&#35;Second allow is required, because ACLs are checked #Second allow is required, because ACLs are checked
&#35;twice: first time by socks and second by http proxy. #twice: first time by socks and second by http proxy.
allow * * * 21,2121 allow * * * 21,2121
parent 1000 ftp 0.0.0.0 0 parent 1000 ftp 0.0.0.0 0
allow * * * 21,2121 allow * * * 21,2121
&#35;redirect ports 21 and 2121 to local #redirect ports 21 and 2121 to local
&#35;ftp proxy #ftp proxy
allow * allow *
&#35;allow the rest of connections directly #allow the rest of connections directly
socks socks
&#35;now let the socks server start #now let the socks server start
</pre> </pre>
<p><i>Q: How does it affect different ACL rules?</i></p> <p><i>Q: How does it affect different ACL rules?</i></p>
@ -1260,20 +1262,20 @@ A: After local redirections, rules are applied again to the protocol-level reque
<pre> <pre>
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http 0.0.0.0 0 parent 1000 http 0.0.0.0 0
&#35;redirect http traffic to internal proxy #redirect http traffic to internal proxy
allow * * $c:\3proxy\local.nets 80,8080-8088 allow * * $c:\3proxy\local.nets 80,8080-8088
&#35;allow direct access to local.nets networks #allow direct access to local.nets networks
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http proxy.3proxy.org 3128 parent 1000 http proxy.3proxy.org 3128
&#35;use parent caching proxy for the rest of the networks #use parent caching proxy for the rest of the networks
allow * allow *
&#35;allow direct connections for the rest of socks #allow direct connections for the rest of socks
&#35;requests #requests
</pre> </pre>
<li><A NAME="ROUNDROBIN">How to balance traffic between multiple external channels?</a> <li><A NAME="ROUNDROBIN">How to balance traffic between multiple external channels?</A>
<p> <p>
The proxy itself doesn't manage network-level routing. The only way to control The proxy itself doesn't manage network-level routing. The only way to control
the outgoing channel is to select the external interface. It's possible to make the outgoing channel is to select the external interface. It's possible to make
@ -1302,7 +1304,7 @@ for Windows:
If you don't have a second address yet, just add it. Under Linux/Unix, it's better If you don't have a second address yet, just add it. Under Linux/Unix, it's better
to use source routing. to use source routing.
</p> </p>
<li><A NAME="CHAIN">How to manage proxy chains</a> <li><A NAME="CHAIN">How to manage proxy chains</A>
<p> <p>
The parent command may also be used to build proxy chains. In this case, The parent command may also be used to build proxy chains. In this case,
multiple 'parent' commands are used for a single 'allow' rule with different multiple 'parent' commands are used for a single 'allow' rule with different
@ -1338,7 +1340,7 @@ the second hop is 192.168.20.1, and the 3rd one is either 192.168.30.1 with a pr
of 30% or 192.168.40.1 with a probability of 70%. of 30% or 192.168.40.1 with a probability of 70%.
</p> </p>
<li><A NAME="BANDLIM">How to limit bandwidth</a> <li><A NAME="BANDLIM">How to limit bandwidth</A>
<p> <p>
3proxy supports bandwidth filters. Use the bandlimin/bandlimout and 3proxy supports bandwidth filters. Use the bandlimin/bandlimout and
nobandlimin/nobandlimout commands to manage filters. 'in' means incoming and 'out' means outgoing traffic. nobandlimin/nobandlimout commands to manage filters. 'in' means incoming and 'out' means outgoing traffic.
@ -1368,7 +1370,7 @@ In this example:
mail traffic from POP3 servers bypasses the pipe and has no bandwidth mail traffic from POP3 servers bypasses the pipe and has no bandwidth
limitation. limitation.
</p> </p>
<li><A NAME="TRAFLIM">How to limit traffic amount</a> <li><A NAME="TRAFLIM">How to limit traffic amount</A>
<p> <p>
<p><font face="courier"> <p><font face="courier">
counter &lt;filename&gt; &lt;type&gt; &lt;reportpath&gt; counter &lt;filename&gt; &lt;type&gt; &lt;reportpath&gt;
@ -1502,21 +1504,21 @@ proxy -p3128 -OcTCP_NODELAY,TCP_MAXSEG -OsTCP_NODELAY,TCP_MAXSEG
</ul> </ul>
<hr> <hr>
<li><A NAME="CLIENT">Client configuration</a> <li><A NAME="CLIENT">Client configuration</A>
<p> <p>
<hr> <hr>
<li><A NAME="ADMIN">Administering and information analysis</a> <li><A NAME="ADMIN">Administering and information analysis</A>
<p> <p>
<ul> <ul>
<li><A NAME="NEWVERSION">How to obtain latest 3proxy version</a> <li><A NAME="NEWVERSION">How to obtain latest 3proxy version</A>
<p> <p>
The latest version of 3proxy may be obtained The latest version of 3proxy may be obtained
<A HREF="https://3proxy.org/">here</a>. <A HREF="https://3proxy.org/">here</A>.
A new version may have changes and incompatibilities with the previous one in file A new version may have changes and incompatibilities with the previous one in file
formats or commands. Please read the CHANGELOG file and other documentation formats or commands. Please read the CHANGELOG file and other documentation
before installing a new version. before installing a new version.
</p> </p>
<li><A NAME="NTSERVICE">How to control 3proxy service under Windows NT/2000/XP</a> <li><A NAME="NTSERVICE">How to control 3proxy service under Windows NT/2000/XP</A>
<p> <p>
If installed as a system service, 3proxy understands Windows service commands If installed as a system service, 3proxy understands Windows service commands
for START, STOP, PAUSE, and RESUME. If the service is PAUSEd, no new connections for START, STOP, PAUSE, and RESUME. If the service is PAUSEd, no new connections
@ -1532,7 +1534,7 @@ You can control the 3proxy service via "Services" administration or via the "net
net continue 3proxy net continue 3proxy
</pre> </pre>
</p> </p>
<li><A NAME="ERRORS">Log error codes reference</a> <li><A NAME="ERRORS">Log error codes reference</A>
<p> <p>
<ul> <ul>
<li>0 - Operation successfully completed (connection <li>0 - Operation successfully completed (connection
@ -1595,9 +1597,9 @@ You can control the 3proxy service via "Services" administration or via the "net
</p> </p>
</ul> </ul>
<hr> <hr>
<li><A NAME="QUEST">How to ask a question not in How To?</a> <li><A NAME="QUEST">How to ask a question not in How To?</A>
<p> <p>
Ask it in <A HREF="https://github.com/z3APA3A/3proxy/issues">Github</a>. Ask it in <A HREF="https://github.com/z3APA3A/3proxy/issues">Github</A>.
Please read this document before asking a question. Please read this document before asking a question.
</ul> </ul>

View File

@ -210,16 +210,16 @@
<b>Управление службой через launchd:</b> <b>Управление службой через launchd:</b>
<br>После установки через cmake службой можно управлять с помощью launchctl: <br>После установки через cmake службой можно управлять с помощью launchctl:
<pre> <pre>
&#35; Загрузить и запустить службу # Загрузить и запустить службу
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
&#35; Остановить службу # Остановить службу
sudo launchctl stop org.3proxy.3proxy sudo launchctl stop org.3proxy.3proxy
&#35; Запустить службу # Запустить службу
sudo launchctl start org.3proxy.3proxy sudo launchctl start org.3proxy.3proxy
&#35; Выгрузить и отключить службу # Выгрузить и отключить службу
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist</pre> sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist</pre>
Служба запускается от имени пользователя <code>proxy</code> (создаётся при установке). Служба запускается от имени пользователя <code>proxy</code> (создаётся при установке).
Файл конфигурации: <code>/etc/3proxy/3proxy.cfg</code> Файл конфигурации: <code>/etc/3proxy/3proxy.cfg</code>
@ -388,7 +388,7 @@
-l@ident</pre> -l@ident</pre>
соответствуют ведению журнала через syslog с идентификатором ident. соответствуют ведению журнала через syslog с идентификатором ident.
<pre> <pre>
log &connstring;</pre> log &connstring</pre>
соответствует ведению журнала через ODBC, connstring задается в формате соответствует ведению журнала через ODBC, connstring задается в формате
datasource,username,password (последние два параметра опциональны, если datasource,username,password (последние два параметра опциональны, если
datasource не требует или уже содержит сведения для авторизации). При этом datasource не требует или уже содержит сведения для авторизации). При этом
@ -614,17 +614,17 @@ tlspr поддерживает оба варианта: для implicit TLS хо
опция -X заставляет tlspr говорить с клиентом на plaintext-фазе протокола (приветствие, команда STARTTLS) перед опция -X заставляет tlspr говорить с клиентом на plaintext-фазе протокола (приветствие, команда STARTTLS) перед
поднятием TLS с обеих сторон. Пример: поднятием TLS с обеих сторон. Пример:
</p><pre> </p><pre>
&#35; https (implicit) # https (implicit)
tlspr -p443 -P443 -c1 tlspr -p443 -P443 -c1
&#35; imaps (implicit) # imaps (implicit)
tlspr -p993 -P993 -c1 tlspr -p993 -P993 -c1
&#35; submissions (implicit) # submissions (implicit)
tlspr -p465 -P465 -c1 tlspr -p465 -P465 -c1
&#35; imap STARTTLS (explicit) # imap STARTTLS (explicit)
tlspr -p143 -P143 -Ximap tlspr -p143 -P143 -Ximap
&#35; submission STARTTLS (explicit) # submission STARTTLS (explicit)
tlspr -p587 -P587 -Xsmtp tlspr -p587 -P587 -Xsmtp
&#35; pop3 STLS (explicit) # pop3 STLS (explicit)
tlspr -p110 -P110 -Xpop3 tlspr -p110 -P110 -Xpop3
</pre> </pre>
<p> <p>
@ -687,7 +687,9 @@ socks
<p> <p>
3. Использование tlspr с HTTP proxy для ACL по имени хоста TLS: 3. Использование tlspr с HTTP proxy для ACL по имени хоста TLS:
</p><pre> </p><pre>
allow * * * * HTTP_CONNECT allow * * * 80
parent 1000 http 0.0.0.0 0
allow * * * 443
parent 1000 tls 0.0.0.0 0 parent 1000 tls 0.0.0.0 0
deny * * blocked.example.com deny * * blocked.example.com
allow * allow *
@ -714,15 +716,15 @@ nscache 65536
nscache6 65536 nscache6 65536
dnspr -p53 dnspr -p53
&#35; google # google
nsrecord smtp.gmail.com 10.0.0.1 nsrecord smtp.gmail.com 10.0.0.1
nsrecord imap.gmail.com 10.0.0.1 nsrecord imap.gmail.com 10.0.0.1
nsrecord pop.gmail.com 10.0.0.1 nsrecord pop.gmail.com 10.0.0.1
&#35; mail.ru # mail.ru
nsrecord smtp.mail.ru 10.0.0.1 nsrecord smtp.mail.ru 10.0.0.1
nsrecord imap.mail.ru 10.0.0.1 nsrecord imap.mail.ru 10.0.0.1
nsrecord pop.mail.ru 10.0.0.1 nsrecord pop.mail.ru 10.0.0.1
&#35; yandex.ru # yandex.ru
nsrecord smtp.yandex.ru 10.0.0.1 nsrecord smtp.yandex.ru 10.0.0.1
nsrecord imap.yandex.ru 10.0.0.1 nsrecord imap.yandex.ru 10.0.0.1
nsrecord pop.yandex.ru 10.0.0.1 nsrecord pop.yandex.ru 10.0.0.1
@ -835,10 +837,10 @@ ssl_nocli
<b>Создание удостоверяющего центра (CA):</b> <b>Создание удостоверяющего центра (CA):</b>
<br>Для MITM или mTLS требуется CA. Сгенерируйте закрытый ключ CA и сертификат: <br>Для MITM или mTLS требуется CA. Сгенерируйте закрытый ключ CA и сертификат:
</p><pre> </p><pre>
&#35; Генерация закрытого ключа CA # Генерация закрытого ключа CA
openssl genrsa -out ca.key 4096 openssl genrsa -out ca.key 4096
&#35; Генерация сертификата CA (действителен 10 лет) # Генерация сертификата CA (действителен 10 лет)
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=My CA" \ -subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=My CA" \
-out ca.crt -out ca.crt
@ -850,15 +852,15 @@ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
<b>Создание серверного сертификата для https:// прокси:</b> <b>Создание серверного сертификата для https:// прокси:</b>
<br>Серверный сертификат должен иметь правильные альтернативные имена (SAN): <br>Серверный сертификат должен иметь правильные альтернативные имена (SAN):
</p><pre> </p><pre>
&#35; Генерация закрытого ключа сервера # Генерация закрытого ключа сервера
openssl genrsa -out server.key 2048 openssl genrsa -out server.key 2048
&#35; Создание запроса на подпись сертификата (CSR) # Создание запроса на подпись сертификата (CSR)
openssl req -new -key server.key \ openssl req -new -key server.key \
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=proxy.example.com" \ -subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=proxy.example.com" \
-out server.csr -out server.csr
&#35; Создание файла расширений для SAN # Создание файла расширений для SAN
cat > server.ext << 'EOF' cat > server.ext << 'EOF'
authorityKeyIdentifier=keyid,issuer authorityKeyIdentifier=keyid,issuer
basicConstraints=CA:FALSE basicConstraints=CA:FALSE
@ -872,7 +874,7 @@ DNS.2 = proxy
IP.1 = 192.168.1.100 IP.1 = 192.168.1.100
EOF EOF
&#35; Подписание сертификата CA # Подписание сертификата CA
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out server.crt -days 365 -sha256 \ -CAcreateserial -out server.crt -days 365 -sha256 \
-extfile server.ext -extfile server.ext
@ -883,27 +885,27 @@ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
<p> <p>
<b>Создание клиентского сертификата для mTLS:</b> <b>Создание клиентского сертификата для mTLS:</b>
</p><pre> </p><pre>
&#35; Генерация закрытого ключа клиента # Генерация закрытого ключа клиента
openssl genrsa -out client1.key 2048 openssl genrsa -out client1.key 2048
&#35; Создание CSR # Создание CSR
openssl req -new -key client1.key \ openssl req -new -key client1.key \
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=client1" \ -subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=client1" \
-out client1.csr -out client1.csr
&#35; Создание файла расширений # Создание файла расширений
cat > client.ext << 'EOF' cat > client.ext << 'EOF'
basicConstraints=CA:FALSE basicConstraints=CA:FALSE
keyUsage = digitalSignature, nonRepudiation, keyEncipherment keyUsage = digitalSignature, nonRepudiation, keyEncipherment
extendedKeyUsage = clientAuth extendedKeyUsage = clientAuth
EOF EOF
&#35; Подписание CA # Подписание CA
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out client1.crt -days 365 -sha256 \ -CAcreateserial -out client1.crt -days 365 -sha256 \
-extfile client.ext -extfile client.ext
&#35; Создание PKCS&#35;12 для импорта в браузер # Создание PKCS#12 для импорта в браузер
openssl pkcs12 -export -out client1.p12 \ openssl pkcs12 -export -out client1.p12 \
-inkey client1.key -in client1.crt -certfile ca.crt -inkey client1.key -in client1.crt -certfile ca.crt
</pre> </pre>
@ -913,15 +915,15 @@ openssl pkcs12 -export -out client1.p12 \
<p> <p>
<b>Скрипт быстрой настройки для разработки/тестирования:</b> <b>Скрипт быстрой настройки для разработки/тестирования:</b>
</p><pre> </p><pre>
&#35;!/bin/sh #!/bin/sh
&#35; Создаёт CA, серверный и клиентский сертификаты для тестирования SSLPlugin # Создаёт CA, серверный и клиентский сертификаты для тестирования SSLPlugin
&#35; CA # CA
openssl genrsa -out ca.key 4096 openssl genrsa -out ca.key 4096
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
-subj "/CN=3proxy CA" -out ca.crt -subj "/CN=3proxy CA" -out ca.crt
&#35; Сервер # Сервер
openssl genrsa -out server.key 2048 openssl genrsa -out server.key 2048
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
cat > server.ext << 'EOF' cat > server.ext << 'EOF'
@ -933,7 +935,7 @@ EOF
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext -CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
&#35; Клиент # Клиент
openssl genrsa -out client.key 2048 openssl genrsa -out client.key 2048
openssl req -new -key client.key -subj "/CN=client" -out client.csr openssl req -new -key client.key -subj "/CN=client" -out client.csr
cat > client.ext << 'EOF' cat > client.ext << 'EOF'
@ -991,13 +993,13 @@ IP назначения, порты и т.д.), аналогичный кома
<p> <p>
<b>Примеры:</b> <b>Примеры:</b>
</p><pre> </p><pre>
&#35; Блокировать запросы с определёнными ключевыми словами для некоторых пользователей # Блокировать запросы с определёнными ключевыми словами для некоторых пользователей
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16 pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
&#35; Блокировать ответы с определённым content-type # Блокировать ответы с определённым content-type
pcre srvheader deny "Content-type: application" pcre srvheader deny "Content-type: application"
&#35; Замена содержимого в обоих направлениях (цензура) # Замена содержимого в обоих направлениях (цензура)
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
pcre_extend deny * 192.168.0.1/16 pcre_extend deny * 192.168.0.1/16
</pre> </pre>
@ -1268,16 +1270,16 @@ pcre_extend deny * 192.168.0.1/16
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http 0.0.0.0 0 parent 1000 http 0.0.0.0 0
allow * * * 80,8080-8088 allow * * * 80,8080-8088
&#35;перенаправить соединения по портам 80 и 8080-8088 в локальный #перенаправить соединения по портам 80 и 8080-8088 в локальный
&#35;http прокси. Вторая команда allow необходима, т.к. контроль доступа #http прокси. Вторая команда allow необходима, т.к. контроль доступа
&#35;осуществляется 2 раза - на уровне socks и на уровне HTTP прокси #осуществляется 2 раза - на уровне socks и на уровне HTTP прокси
allow * * * 21,2121 allow * * * 21,2121
parent 1000 ftp 0.0.0.0 0 parent 1000 ftp 0.0.0.0 0
allow * * * 21,2121 allow * * * 21,2121
&#35;перенаправить соединения по портам 21 и 2121 в локальный #перенаправить соединения по портам 21 и 2121 в локальный
&#35;ftp прокси #ftp прокси
allow * allow *
&#35;пустить все соединения напрямую #пустить все соединения напрямую
socks</pre> socks</pre>
</p> </p>
<li><a name="REDIINTER"><i>Q: Как взаимодействует с другими правилами в ACL?</i></a></li> <li><a name="REDIINTER"><i>Q: Как взаимодействует с другими правилами в ACL?</i></a></li>
@ -1292,14 +1294,14 @@ pcre_extend deny * 192.168.0.1/16
<pre> <pre>
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http 0.0.0.0 0 parent 1000 http 0.0.0.0 0
&#35;перенаправить во внутренний прокси #перенаправить во внутренний прокси
allow * * $c:\3proxy\local.nets 80,8080-8088 allow * * $c:\3proxy\local.nets 80,8080-8088
&#35;разрешить прямой web-доступ к сетям из local.nets #разрешить прямой web-доступ к сетям из local.nets
allow * * * 80,8080-8088 allow * * * 80,8080-8088
parent 1000 http proxy.3proxy.ru 3128 parent 1000 http proxy.3proxy.ru 3128
&#35;все остальные веб-запросы перенаправить на внешний прокси-сервер #все остальные веб-запросы перенаправить на внешний прокси-сервер
allow * allow *
&#35;разрешить socks-запросы по другим портам</pre> #разрешить socks-запросы по другим портам</pre>
</p> </p>
</ul> </ul>
<li><a name="ROUNDROBIN"><i>Как организовать балансировку между несоклькими каналами</i></a> <li><a name="ROUNDROBIN"><i>Как организовать балансировку между несоклькими каналами</i></a>

View File

@ -192,16 +192,9 @@ or hostname, useful in case of dynamic DNS. <b><br>
(<b>-ol</b>), connect back client (<b>-or</b>), connect back (<b>-ol</b>), connect back client (<b>-or</b>), connect back
listening (<b>-oR</b>) sockets. Options like TCP_CORK, listening (<b>-oR</b>) sockets. Options like TCP_CORK,
TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS,
TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT, USE_TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT,
SO_EXCLUSIVEADDRUSE, SO_PORT_SCALABILITY, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE,
SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be SO_DONTROUTE may be supported depending on OS. <b><br>
supported depending on OS. SO_REUSEADDR and SO_REUSEPORT are
set on the listening socket by default on Unix. On Windows
SO_REUSEADDR is not set: it is not required to rebind a
listening port and it only lets another local process bind
the same address and port. Use SO_EXCLUSIVEADDRUSE (Windows)
on the listening socket (<b>-ol</b>) to prevent that.
<b><br>
-H</b> (for all services) Expect HAProxy PROXY protocol v1 -H</b> (for all services) Expect HAProxy PROXY protocol v1
header on incoming connection. This allows the proxy to header on incoming connection. This allows the proxy to
receive real client IP address from HAProxy or other load receive real client IP address from HAProxy or other load
@ -212,16 +205,9 @@ be sent before any protocol-specific data. <b><br>
delay GRACE_DELAY milliseconds before polling if average delay GRACE_DELAY milliseconds before polling if average
polling size is below GRACE_TRAFF bytes and GRACE_NUM read polling size is below GRACE_TRAFF bytes and GRACE_NUM read
operations in a single direction are detected within 1 operations in a single direction are detected within 1
second. Useful to minimize polling <b><br> second. Useful to minimize polling <b>-s</b> <br>
-s</b> <br>
(for admin) secure, allow only secure operations, currently (for admin) secure, allow only secure operations, currently
only traffic counters view without ability to reset. <br> only traffic counters view without ability to reset. <br>
(for TCP services, Linux) enable splice(). splice() is not
built by default and is disabled even when built, because
current Linux does not implement SPLICE_F_MOVE, so no real
zero-copy takes place and the read/write path is faster for
most traffic. Rebuild with -DWITHSPLICE to make -s
available, -s0 disables it explicitly. <br>
(for dnspr) simple, do not use resolver and 3proxy cache, (for dnspr) simple, do not use resolver and 3proxy cache,
always use external DNS server. <br> always use external DNS server. <br>
(for udppm) singlepacket, expect only one packet from both (for udppm) singlepacket, expect only one packet from both
@ -776,8 +762,8 @@ service (with -s parameter). <b><br>
ha</b> send HAProxy PROXY protocol v1 header to the next ha</b> send HAProxy PROXY protocol v1 header to the next
parent proxy (or to the destination if <b>ha</b> is used parent proxy (or to the destination if <b>ha</b> is used
alone). Place <b>ha</b> before the parent that should alone). Place <b>ha</b> before the parent that should
receive the header; after the header is sent, negotiation of receive the header; after the header is sent, negotiation
that parent protocol continues (SOCKS, CONNECT, etc.). of that parent protocol continues (SOCKS, CONNECT, etc.).
Useful for passing client IP information to the parent Useful for passing client IP information to the parent
proxy. Example: <br> proxy. Example: <br>
parent 1000 ha 0.0.0.0 0 <br> parent 1000 ha 0.0.0.0 0 <br>
@ -1062,17 +1048,7 @@ experience 3proxy crash on request processing, try to set
some positive value. You may start with stacksize 65536 and some positive value. You may start with stacksize 65536 and
then find the minimal value for the service to work. If you then find the minimal value for the service to work. If you
experience memory shortage, you can try to experiment with experience memory shortage, you can try to experiment with
negative values. <br> negative values.</p>
With SQL logging (log &amp;ODBC_string) the value is
automatically raised to 32768 if it is smaller, because ODBC
drivers require more stack. A <b>stacksize</b> command
placed after the <b>log</b> command overrides this. <br>
The base stack size the value is added to is 49152. On
FreeBSD, NetBSD, OpenBSD and DragonFly it is 65536, because
libc functions such as vfprintf() called by syslog() use
significantly more stack there. The result is never lowered
below PTHREAD_STACK_MIN, so a large negative value can not
disable the thread stack.</p>
<h2>PLUGINS <h2>PLUGINS
<a name="PLUGINS"></a> <a name="PLUGINS"></a>

View File

@ -178,8 +178,7 @@ connect to given remote HOST:port instead of listening local connection on -p or
.br .br
.B -oc\fIOPTIONS\fB, -os\fIOPTIONS\fB, -ol\fIOPTIONS\fB, -or\fIOPTIONS\fB, -oR\fIOPTIONS\fR .B -oc\fIOPTIONS\fB, -os\fIOPTIONS\fB, -ol\fIOPTIONS\fB, -or\fIOPTIONS\fB, -oR\fIOPTIONS\fR
options for proxy-to-client (\fB-oc\fR), proxy-to-server (\fB-os\fR), proxy listening (\fB-ol\fR), connect back client (\fB-or\fR), connect back listening (\fB-oR\fR) sockets. options for proxy-to-client (\fB-oc\fR), proxy-to-server (\fB-os\fR), proxy listening (\fB-ol\fR), connect back client (\fB-or\fR), connect back listening (\fB-oR\fR) sockets.
Options like TCP_CORK, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS, TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT, SO_EXCLUSIVEADDRUSE, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be supported depending on OS. Options like TCP_CORK, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS, USE_TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be supported depending on OS.
SO_REUSEADDR and SO_REUSEPORT are set on the listening socket by default on Unix. On Windows SO_REUSEADDR is not set: it is not required to rebind a listening port and it only lets another local process bind the same address and port. Use SO_EXCLUSIVEADDRUSE (Windows) on the listening socket (\fB-ol\fR) to prevent that.
.br .br
.B -H .B -H
(for all services) Expect HAProxy PROXY protocol v1 header on incoming connection. (for all services) Expect HAProxy PROXY protocol v1 header on incoming connection.

View File

@ -1,6 +1,6 @@
[Unit] [Unit]
Description=3proxy tiny proxy server Description=3proxy tiny proxy server
Documentation=man:3proxy(8) man:3proxy.cfg(5) Documentation=man:3proxy(1)
After=network.target After=network.target
[Service] [Service]
@ -13,15 +13,8 @@ ExecReload=/bin/kill -SIGUSR1 $MAINPID
KillMode=process KillMode=process
Restart=on-failure Restart=on-failure
RestartSec=60s RestartSec=60s
# 3proxy uses one thread and two descriptors per connection (four for ftppr), LimitNOFILE=65536
# so it reaches these limits much earlier than event driven servers. They are LimitNPROC=32768
# ceilings only: the actual number of connections is governed by 'maxconn' in
# the configuration file. TasksMax must be set explicitly, systemd's
# DefaultTasksMax (15% of kernel.threads-max, e.g. ~9000) otherwise caps the
# number of threads, and thus connections, regardless of LimitNPROC.
LimitNOFILE=1048576
LimitNPROC=infinity
TasksMax=infinity
RuntimeDirectory=3proxy RuntimeDirectory=3proxy
RuntimeDirectoryMode=0755 RuntimeDirectoryMode=0755

View File

@ -24,19 +24,9 @@ if [ -f /etc/init.d/functions ]; then
. /etc/init.d/functions . /etc/init.d/functions
fi fi
# SysV init does not apply limits.conf consistently: start-stop-daemon does not
# open a PAM session, so pam_limits is not involved and the daemon inherits the
# limits of init. 3proxy needs two descriptors per connection (four for ftppr),
# so raise them here. Adjust to match 'maxconn' in the configuration file.
set_limits() {
ulimit -n 65536 2>/dev/null || ulimit -n 4096 2>/dev/null || true
ulimit -u 32768 2>/dev/null || true
}
case "$1" in case "$1" in
start) start)
echo -n "Starting 3Proxy: " echo -n "Starting 3Proxy: "
set_limits
if [ ! -d /var/run/3proxy ]; then if [ ! -d /var/run/3proxy ]; then
mkdir -p /var/run/3proxy mkdir -p /var/run/3proxy

View File

@ -190,7 +190,7 @@ struct extparam conf = {
.paused = 0, .paused = 0,
.archiverc = 0, .archiverc = 0,
.demon = 0, .demon = 0,
.maxchild = DEFAULT_MAXCHILD, .maxchild = 500,
.backlog = 0, .backlog = 0,
.needreload = 0, .needreload = 0,
.timetoexit = 0, .timetoexit = 0,

View File

@ -2025,7 +2025,7 @@ void freeconf(struct extparam *confp){
#endif #endif
*SAFAMILY(&confp->intsa) = AF_INET; *SAFAMILY(&confp->intsa) = AF_INET;
*SAFAMILY(&confp->extsa) = AF_INET; *SAFAMILY(&confp->extsa) = AF_INET;
confp->maxchild = DEFAULT_MAXCHILD; confp->maxchild = 100;
confp->backlog = 0; confp->backlog = 0;
resolvfunc = NULL; resolvfunc = NULL;
numservers = 0; numservers = 0;

View File

@ -34,7 +34,6 @@
#define MAXUSERNAME 128 #define MAXUSERNAME 128
#define _PASSWORD_LEN 256 #define _PASSWORD_LEN 256
#define MAXNSERVERS 5 #define MAXNSERVERS 5
#define DEFAULT_MAXCHILD 500
#define TCPBUFSIZE 65536 #define TCPBUFSIZE 65536
#define SRVBUFSIZE (param->srv->bufsize?param->srv->bufsize:((param->service == S_UDPPM)?UDPBUFSIZE:TCPBUFSIZE)) #define SRVBUFSIZE (param->srv->bufsize?param->srv->bufsize:((param->service == S_UDPPM)?UDPBUFSIZE:TCPBUFSIZE))

View File

@ -149,20 +149,6 @@ void * threadfunc (void *p) {
} }
#undef param #undef param
#ifdef _WIN32
/* Present since Windows 7 (SO_PORT_SCALABILITY) and Windows 10 / Server 2019
(SO_REUSE_UNICASTPORT), define them if the SDK is older so the options can
still be requested. setsockopt() just fails on a system which does not
support them and the failure is ignored.
*/
#ifndef SO_PORT_SCALABILITY
#define SO_PORT_SCALABILITY 0x3006
#endif
#ifndef SO_REUSE_UNICASTPORT
#define SO_REUSE_UNICASTPORT 0x3007
#endif
#endif
struct socketoptions sockopts[] = { struct socketoptions sockopts[] = {
#ifdef TCP_NODELAY #ifdef TCP_NODELAY
{TCP_NODELAY, "TCP_NODELAY"}, {TCP_NODELAY, "TCP_NODELAY"},
@ -185,9 +171,6 @@ struct socketoptions sockopts[] = {
#ifdef SO_REUSEPORT #ifdef SO_REUSEPORT
{SO_REUSEPORT, "SO_REUSEPORT"}, {SO_REUSEPORT, "SO_REUSEPORT"},
#endif #endif
#ifdef SO_EXCLUSIVEADDRUSE
{SO_EXCLUSIVEADDRUSE, "SO_EXCLUSIVEADDRUSE"},
#endif
#ifdef SO_PORT_SCALABILITY #ifdef SO_PORT_SCALABILITY
{SO_PORT_SCALABILITY, "SO_PORT_SCALABILITY"}, {SO_PORT_SCALABILITY, "SO_PORT_SCALABILITY"},
#endif #endif
@ -811,15 +794,8 @@ int MODULEMAINFUNC (int argc, char** argv){
if(*SAFAMILY(&srv.intsa) != AF_UNIX) if(*SAFAMILY(&srv.intsa) != AF_UNIX)
#endif #endif
{ {
/* SO_REUSEADDR is not set on Windows: it is not needed to rebind a listening
port there, and it only allows another local process to bind the same
address and port, with undefined behaviour as to which socket receives the
connections. Use -olSO_EXCLUSIVEADDRUSE to prevent that instead.
*/
#ifndef _WIN32
opt = 1; opt = 1;
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()"); if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
#endif
#ifdef SO_REUSEPORT #ifdef SO_REUSEPORT
opt = 1; opt = 1;
srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int)); srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
@ -935,10 +911,8 @@ int MODULEMAINFUNC (int argc, char** argv){
freesrvstrings(&srv, cbc_string, cbl_string); freesrvstrings(&srv, cbc_string, cbl_string);
return -6; return -6;
} }
#ifndef _WIN32
opt = 1; opt = 1;
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)); srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int));
#endif
#ifdef SO_REUSEPORT #ifdef SO_REUSEPORT
opt = 1; opt = 1;
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int)); srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));