mirror of
https://github.com/3proxy/3proxy.git
synced 2026-09-29 16:55:51 +08:00
Compare commits
4 Commits
7b85f6a684
...
0ae2754c1e
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
0ae2754c1e | ||
|
|
05f83896bf | ||
|
|
f668a34910 | ||
|
|
763e21e053 |
@ -1,2 +1,2 @@
|
|||||||
|
|
||||||
<H2><A href="howtoe.html">See HowTo:</a></H2>
|
<H2><A href="howtoe.html">See HowTo:</a></h2>
|
||||||
@ -1,2 +1,2 @@
|
|||||||
|
|
||||||
<H2><A href="howtoe.html">См. HowTo</a></H2>
|
<H2><A href="howtoe.html">См. HowTo</a></h2>
|
||||||
@ -5,8 +5,8 @@
|
|||||||
<h4>Configuring 'maxconn'</h4>
|
<h4>Configuring 'maxconn'</h4>
|
||||||
|
|
||||||
The number of simultaneous connections per service is limited by the 'maxconn' option.
|
The number of simultaneous connections per service is limited by the 'maxconn' option.
|
||||||
The default maxconn value since 3proxy 0.8 is 500. You may want to set 'maxconn'
|
The default maxconn value is 500. You may want to set 'maxconn'
|
||||||
to a higher value. Under this configuration:
|
to a higher value; it must be set before the services it should apply to. Under this configuration:
|
||||||
<pre>
|
<pre>
|
||||||
maxconn 1000
|
maxconn 1000
|
||||||
proxy -p3129
|
proxy -p3129
|
||||||
@ -19,6 +19,10 @@ simultaneous connections to 3proxy.
|
|||||||
<p>Avoid setting 'maxconn' to an arbitrarily high value; it should be carefully
|
<p>Avoid setting 'maxconn' to an arbitrarily high value; it should be carefully
|
||||||
chosen to protect the system and proxy from resource exhaustion. Setting maxconn
|
chosen to protect the system and proxy from resource exhaustion. Setting maxconn
|
||||||
above available resources can lead to denial of service conditions.
|
above available resources can lead to denial of service conditions.
|
||||||
|
<p>'maxconn' is not reduced automatically to fit the open file limit. If the limit is
|
||||||
|
too low 3proxy only prints a warning at startup
|
||||||
|
("current open file ulimits are too low") and then fails to accept connections once
|
||||||
|
the limit is reached, so check for this warning after changing 'maxconn'.
|
||||||
<h4>Understanding Resource Requirements</h4>
|
<h4>Understanding Resource Requirements</h4>
|
||||||
Each running service requires:
|
Each running service requires:
|
||||||
<ul>
|
<ul>
|
||||||
@ -56,19 +60,45 @@ system "ulimit -Sa >>/tmp/3proxy.ulim.soft"
|
|||||||
at the beginning (before the first service is started) and at the end of the config file.
|
at the beginning (before the first service is started) and at the end of the config file.
|
||||||
Perform both a hard restart (i.e., kill and start the 3proxy process) and a soft restart
|
Perform both a hard restart (i.e., kill and start the 3proxy process) and a soft restart
|
||||||
by sending SIGUSR1 to the 3proxy process; check that the ulimits recorded to files match your
|
by sending SIGUSR1 to the 3proxy process; check that the ulimits recorded to files match your
|
||||||
expectations. In systemd-based distros (e.g., latest Debian/Ubuntu), changing limits.conf
|
expectations. In systemd-based distros (e.g., latest Debian/Ubuntu) changing limits.conf is not
|
||||||
is not enough; limits must be adjusted in the systemd configuration, e.g., by setting:
|
enough for a service: limits must be set in the unit file. Set them in the 3proxy
|
||||||
|
unit itself rather than globally, so the rest of the system is unaffected. The
|
||||||
|
shipped 3proxy.service already contains:
|
||||||
<pre>
|
<pre>
|
||||||
DefaultLimitDATA=infinity
|
LimitNOFILE=1048576
|
||||||
DefaultLimitSTACK=infinity
|
LimitNPROC=infinity
|
||||||
DefaultLimitCORE=infinity
|
TasksMax=infinity
|
||||||
DefaultLimitRSS=infinity
|
</pre>
|
||||||
DefaultLimitNOFILE=102400
|
To change them on an installed system use an override instead of editing the unit:
|
||||||
DefaultLimitAS=infinity
|
<pre>
|
||||||
DefaultLimitNPROC=10240
|
systemctl edit 3proxy
|
||||||
DefaultLimitMEMLOCK=infinity
|
systemctl daemon-reload && systemctl restart 3proxy
|
||||||
|
systemctl show 3proxy -p LimitNOFILE -p LimitNPROC -p TasksMax
|
||||||
|
</pre>
|
||||||
|
<b>TasksMax is the one that is easy to miss.</b> It is the cgroup limit on the number
|
||||||
|
of threads, and if it is not set the unit inherits DefaultTasksMax, which is 15% of
|
||||||
|
kernel.threads-max (about 9000 on a typical host). Since 3proxy uses one thread per
|
||||||
|
connection, that caps concurrent connections at that number regardless of LimitNPROC
|
||||||
|
and maxconn, and the only symptom is "pthread_create()" errors in the log.
|
||||||
|
<p>On systemd older than 227, which has no TasksMax, and for limits that must apply to
|
||||||
|
several services, the same values can be set globally as DefaultLimitNOFILE /
|
||||||
|
DefaultLimitNPROC in /etc/systemd/system.conf, but prefer the per-unit settings.
|
||||||
|
|
||||||
|
<p>With SysV init the limits are not applied by limits.conf either, because
|
||||||
|
start-stop-daemon does not open a PAM session, so the daemon simply inherits the limits
|
||||||
|
of init. The shipped init script raises them itself before starting 3proxy:
|
||||||
|
<pre>
|
||||||
|
ulimit -n 65536
|
||||||
|
ulimit -u 32768
|
||||||
|
</pre>
|
||||||
|
adjust these values in the script to match 'maxconn'.
|
||||||
|
|
||||||
|
<p>On FreeBSD rc.subr applies limits(1) with the login class of the service (the
|
||||||
|
"daemon" class by default), so the limits can be set either in /etc/login.conf for that
|
||||||
|
class, or per service in rc.conf:
|
||||||
|
<pre>
|
||||||
|
3proxy_limits="-n 65536"
|
||||||
</pre>
|
</pre>
|
||||||
in user.conf / system.conf
|
|
||||||
|
|
||||||
<h4>Extending System Limitations</h4>
|
<h4>Extending System Limitations</h4>
|
||||||
|
|
||||||
@ -83,6 +113,168 @@ proxy -olSO_REUSEADDR,SO_REUSEPORT -ocTCP_TIMESTAMPS,TCP_NODELAY -osTCP_NODELAY
|
|||||||
</pre>
|
</pre>
|
||||||
Available options are system-dependent.
|
Available options are system-dependent.
|
||||||
|
|
||||||
|
<h4>Linux Tuning Hints</h4>
|
||||||
|
|
||||||
|
Values below are examples, not recommendations: check the current value first
|
||||||
|
(<tt>sysctl NAME</tt>), change only what your workload actually hits, and make changes
|
||||||
|
persistent in <tt>/etc/sysctl.d/</tt>. Defaults given in parentheses are from a recent
|
||||||
|
(6.x) kernel and vary between distributions and versions.
|
||||||
|
|
||||||
|
<p><b>File descriptors.</b> 3proxy needs 2 descriptors per connection (4 for FTP), plus
|
||||||
|
one per service, plus temporary ones for name resolution and RADIUS.
|
||||||
|
<pre>
|
||||||
|
fs.nr_open = 1048576 # (1048576) upper bound for any process' RLIMIT_NOFILE
|
||||||
|
</pre>
|
||||||
|
<tt>ulimit -n</tt> (RLIMIT_NOFILE) is the limit that actually applies and is commonly
|
||||||
|
left at 1024; it must be raised for the 3proxy process itself, see "Setting ulimits"
|
||||||
|
above. <tt>fs.file-max</tt> is effectively unlimited on 64-bit kernels and rarely needs
|
||||||
|
changing.
|
||||||
|
|
||||||
|
<p><b>Threads.</b> Because of the "one connection - one thread" model these limits are
|
||||||
|
reached earlier with 3proxy than with event-driven servers. Each thread also consumes
|
||||||
|
one or two mappings, so <tt>vm.max_map_count</tt> matters too.
|
||||||
|
<pre>
|
||||||
|
kernel.threads-max = 200000 # (~60000 on a 16G host, scales with RAM)
|
||||||
|
kernel.pid_max = 4194304 # (4194304)
|
||||||
|
vm.max_map_count = 1048576 # (1048576)
|
||||||
|
</pre>
|
||||||
|
RLIMIT_NPROC (<tt>ulimit -u</tt>) limits threads per user and must be raised as well.
|
||||||
|
Check the actual thread count with <tt>grep Threads /proc/PID/status</tt>.
|
||||||
|
|
||||||
|
<p><b>Listen queue.</b> 3proxy uses a listen backlog of 1+(maxconn/8) unless the
|
||||||
|
'backlog' command is given, so a large 'maxconn' does not automatically give a large
|
||||||
|
queue, and the kernel caps it at somaxconn:
|
||||||
|
<pre>
|
||||||
|
net.core.somaxconn = 4096 # (4096)
|
||||||
|
net.ipv4.tcp_max_syn_backlog = 4096 # (512) raise for bursty connection rates
|
||||||
|
net.ipv4.tcp_syncookies = 1 # (1) keep enabled
|
||||||
|
</pre>
|
||||||
|
|
||||||
|
<p><b>Ephemeral ports and TIME_WAIT.</b> See "Extending the Ephemeral Port Range" above
|
||||||
|
for the multi-IP case. The range gives about 28000 outgoing connections per
|
||||||
|
destination address by default:
|
||||||
|
<pre>
|
||||||
|
net.ipv4.ip_local_port_range = 10240 65535 # (32768 60999)
|
||||||
|
net.ipv4.tcp_tw_reuse = 2 # (2) reuse TIME_WAIT for outgoing connections
|
||||||
|
net.ipv4.tcp_fin_timeout = 30 # (60)
|
||||||
|
</pre>
|
||||||
|
Do not enable tcp_tw_recycle; it was removed in kernel 4.12 and breaks NAT clients.
|
||||||
|
|
||||||
|
<p><b>Socket buffers.</b> Autotuning is usually right. Buffer memory is per connection,
|
||||||
|
so raising the maximums with tens of thousands of connections costs a lot of RAM:
|
||||||
|
<pre>
|
||||||
|
net.core.rmem_max = 4194304 # (212992)
|
||||||
|
net.core.wmem_max = 4194304 # (212992)
|
||||||
|
net.ipv4.tcp_rmem = 4096 131072 6291456 # (same) min default max
|
||||||
|
net.ipv4.tcp_wmem = 4096 16384 4194304 # (same)
|
||||||
|
</pre>
|
||||||
|
Raise these only for high bandwidth-delay product links, and prefer raising the third
|
||||||
|
(max) value and leaving the default alone.
|
||||||
|
|
||||||
|
<p><b>Conntrack.</b> Only relevant if netfilter/nftables tracks the proxy's traffic. If
|
||||||
|
it does, the table is exhausted long before 3proxy's own limits, with
|
||||||
|
"nf_conntrack: table full, dropping packet" in dmesg:
|
||||||
|
<pre>
|
||||||
|
net.netfilter.nf_conntrack_max = 1048576
|
||||||
|
net.netfilter.nf_conntrack_buckets = 262144
|
||||||
|
net.netfilter.nf_conntrack_tcp_timeout_established = 3600 # (432000, i.e. 5 days)
|
||||||
|
net.netfilter.nf_conntrack_tcp_timeout_time_wait = 30 # (120)
|
||||||
|
</pre>
|
||||||
|
nf_conntrack_max defaults to nf_conntrack_buckets, which itself is derived from the
|
||||||
|
amount of RAM, so it is often much lower than expected on small machines. Each
|
||||||
|
connection takes two entries (one per direction). The default established timeout of
|
||||||
|
5 days matters more than the table size with high connection churn: entries for
|
||||||
|
connections that are long gone keep occupying the table.
|
||||||
|
<p>If no rules need conntrack, not loading it at all is faster: the modules are loaded
|
||||||
|
on demand by the first rule that needs them ("-m state", "-m conntrack", any NAT
|
||||||
|
rule), so a ruleset without such rules keeps the proxy traffic untracked. If conntrack
|
||||||
|
is needed for other traffic but not for the proxy's, exempt the proxy's traffic
|
||||||
|
explicitly in the raw table:
|
||||||
|
<pre>
|
||||||
|
iptables -t raw -A PREROUTING -p tcp --dport 3128 -j CT --notrack
|
||||||
|
iptables -t raw -A OUTPUT -p tcp -m owner --uid-owner proxy -j CT --notrack
|
||||||
|
</pre>
|
||||||
|
|
||||||
|
<p><b>Conntrack helpers (ALGs).</b> The helper modules - nf_conntrack_ftp,
|
||||||
|
nf_conntrack_sip, nf_conntrack_h323, nf_conntrack_pptp, nf_conntrack_irc,
|
||||||
|
nf_conntrack_tftp - inspect the payload of every matching packet and create additional
|
||||||
|
"expectation" entries, so they cost both CPU and table space, and they have a long
|
||||||
|
history of security issues. Unload and blacklist the ones you do not actually need:
|
||||||
|
<pre>
|
||||||
|
lsmod | grep nf_conntrack
|
||||||
|
modprobe -r nf_conntrack_sip nf_conntrack_h323 nf_conntrack_ftp nf_conntrack_pptp
|
||||||
|
echo "blacklist nf_conntrack_sip" >> /etc/modprobe.d/no-alg.conf
|
||||||
|
</pre>
|
||||||
|
On current kernels a helper only acts when it is attached explicitly
|
||||||
|
("-j CT --helper ftp"), so simply not attaching it is enough; automatic helper
|
||||||
|
assignment was deprecated and later removed. Older kernels, and most router firmware,
|
||||||
|
still enable them by default.
|
||||||
|
|
||||||
|
<p><b>Checking the result.</b> <tt>ss -s</tt> for socket state totals,
|
||||||
|
<tt>ss -lnt</tt> for listen queue overflow, <tt>nstat -az TcpExtListenOverflows
|
||||||
|
TcpExtListenDrops</tt> for accept queue drops, and
|
||||||
|
<tt>cat /proc/PID/limits</tt> for the limits actually applied to the running process.
|
||||||
|
|
||||||
|
<h4>Windows Tuning Hints</h4>
|
||||||
|
|
||||||
|
<p><b>Dynamic (ephemeral) port range.</b> Since Windows Vista / Server 2008 the default
|
||||||
|
range is 49152-65535, i.e. only 16384 outgoing connections per local address, which is
|
||||||
|
reached quickly by a busy proxy. Show and change it with:
|
||||||
|
<pre>
|
||||||
|
netsh int ipv4 show dynamicport tcp
|
||||||
|
netsh int ipv4 set dynamicport tcp start=10000 num=55535
|
||||||
|
</pre>
|
||||||
|
The minimum start port is 1025, the minimum size of the range is 255, and the end of
|
||||||
|
the range cannot exceed 65535. The range is set separately for TCP and UDP, and for
|
||||||
|
IPv4 and IPv6. On pre-Vista systems the equivalent is the MaxUserPort registry value
|
||||||
|
in HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters.
|
||||||
|
|
||||||
|
<p><b>Listening socket.</b> 3proxy sets SO_REUSEADDR on the listening socket by
|
||||||
|
default on Unix, but not on Windows: there it is not needed to rebind the port, and it
|
||||||
|
only allows another local process to bind the same address and port, with undefined
|
||||||
|
behaviour as to which of them receives the connections. If the machine is shared or
|
||||||
|
untrusted, harden the listening socket instead:
|
||||||
|
<pre>
|
||||||
|
proxy -olSO_EXCLUSIVEADDRUSE
|
||||||
|
</pre>
|
||||||
|
Note that a socket with SO_EXCLUSIVEADDRUSE may not be immediately rebindable after a
|
||||||
|
restart if accepted connections are still active, so test restarts before using it.
|
||||||
|
|
||||||
|
<p><b>Port reuse.</b> 3proxy always binds the outgoing socket before connecting, so
|
||||||
|
Windows does not apply its automatic ephemeral port reuse (which it does only for
|
||||||
|
connections with an implicit bind). Setting the option explicitly on the
|
||||||
|
proxy-to-server socket therefore helps against port exhaustion:
|
||||||
|
<pre>
|
||||||
|
proxy -osSO_REUSE_UNICASTPORT
|
||||||
|
</pre>
|
||||||
|
SO_REUSE_UNICASTPORT requires Windows 10 / Server 2019 or later. On older systems
|
||||||
|
(Windows 7 / Server 2008 and later) use SO_PORT_SCALABILITY instead; where both are
|
||||||
|
available Microsoft recommends SO_REUSE_UNICASTPORT. Note that SO_REUSEADDR has
|
||||||
|
different, weaker semantics on Windows than on Unix and allows another socket to bind
|
||||||
|
the same address and port, so do not use it on the listening socket as a substitute.
|
||||||
|
|
||||||
|
<p><b>TIME_WAIT.</b> Closed connections hold their port for the TcpTimedWaitDelay
|
||||||
|
period, set in
|
||||||
|
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters (DWORD, seconds). The
|
||||||
|
effective default differs between Windows versions (2 to 4 minutes); check the current
|
||||||
|
behaviour before changing it, and lower it only together with an extended port range.
|
||||||
|
Count the connections in that state with:
|
||||||
|
<pre>
|
||||||
|
netstat -ano -p tcp | find /c "TIME_WAIT"
|
||||||
|
</pre>
|
||||||
|
|
||||||
|
<p><b>Threads and address space.</b> Windows has no ulimit equivalent, and the handle
|
||||||
|
count is not normally the limit. On 32-bit builds the 2 GB of user address space is:
|
||||||
|
each connection thread reserves its stack there, so a few thousand connections can
|
||||||
|
exhaust the address space while physical memory is still free. Use a 64-bit build for high load, and
|
||||||
|
see "Setting Stack Size" above.
|
||||||
|
|
||||||
|
<p><b>Filter drivers.</b> Antivirus, endpoint protection and other LSP/WFP filter
|
||||||
|
drivers inspect every connection and are frequently the actual bottleneck on Windows,
|
||||||
|
costing far more than any tuning above can recover. Exclude the 3proxy process and its
|
||||||
|
ports, or test with the protection temporarily disabled to see the difference before
|
||||||
|
tuning anything else.
|
||||||
|
|
||||||
<h4>Using 3proxy in a Virtual Environment</h4>
|
<h4>Using 3proxy in a Virtual Environment</h4>
|
||||||
|
|
||||||
If 3proxy is used in a VPS environment, there can be additional limitations.
|
If 3proxy is used in a VPS environment, there can be additional limitations.
|
||||||
@ -148,10 +340,10 @@ Under the latest Linux versions, you can also start multiple services with diffe
|
|||||||
external addresses on a single port with SO_REUSEPORT on the listening socket to
|
external addresses on a single port with SO_REUSEPORT on the listening socket to
|
||||||
evenly distribute incoming connections between outgoing interfaces:
|
evenly distribute incoming connections between outgoing interfaces:
|
||||||
<pre>
|
<pre>
|
||||||
socks -olSO_REUSEPORT -p3128 -e 1.1.1.1
|
socks -olSO_REUSEPORT -p3128 -e1.1.1.1
|
||||||
socks -olSO_REUSEPORT -p3128 -e 2.2.2.2
|
socks -olSO_REUSEPORT -p3128 -e2.2.2.2
|
||||||
socks -olSO_REUSEPORT -p3128 -e 3.3.3.3
|
socks -olSO_REUSEPORT -p3128 -e3.3.3.3
|
||||||
socks -olSO_REUSEPORT -p3128 -e 4.4.4.4
|
socks -olSO_REUSEPORT -p3128 -e4.4.4.4
|
||||||
</pre>
|
</pre>
|
||||||
For web browsing, the last two examples are not recommended because the same client can get
|
For web browsing, the last two examples are not recommended because the same client can get
|
||||||
a different external address for different requests; you should choose the external
|
a different external address for different requests; you should choose the external
|
||||||
@ -172,6 +364,39 @@ randomly fail due to IP+port pair collisions if the remote or local system
|
|||||||
doesn't support this trick.
|
doesn't support this trick.
|
||||||
</ol>
|
</ol>
|
||||||
|
|
||||||
|
<h4>NAT on the Path Must Be Tuned Too</h4>
|
||||||
|
|
||||||
|
Everything above tunes the machine 3proxy runs on. If the outgoing traffic passes
|
||||||
|
through NAT - a router, a firewall, a CGNAT of the provider, or a cloud NAT gateway -
|
||||||
|
that device keeps its own translation table and its own pool of source ports, and it
|
||||||
|
limits the number of connections independently of the proxy. Extending
|
||||||
|
ip_local_port_range on the 3proxy host changes nothing if the NAT device rewrites the
|
||||||
|
source port from its own, smaller pool.
|
||||||
|
|
||||||
|
<p>On a Linux based router the same knobs apply and have to be raised there as well:
|
||||||
|
nf_conntrack_max / nf_conntrack_buckets and the conntrack timeouts (see "Linux Tuning
|
||||||
|
Hints" above), plus the port range used for translation, which is ip_local_port_range
|
||||||
|
for MASQUERADE, or the explicit range if SNAT is configured with --to-ports. Note that
|
||||||
|
the range is per translated address: with a single public IP, all clients share it.
|
||||||
|
|
||||||
|
<p>Entry level and SOHO routers are the usual bottleneck here. They typically have a
|
||||||
|
small fixed NAT/conntrack table (a few thousand entries), aggressive or non-adjustable
|
||||||
|
timeouts, and no way to change either. Symptoms are seen on the proxy but caused by the
|
||||||
|
router: connections that fail or hang at random under load while the proxy is far from
|
||||||
|
its own limits, no error in the 3proxy log except a failed outgoing connect, and
|
||||||
|
recovery after a pause or a router reboot. Before tuning 3proxy further, check the
|
||||||
|
router's session/NAT table counters. For high load either give the proxy a public
|
||||||
|
address without NAT in the path, or use a router where the table size and timeouts are
|
||||||
|
configurable.
|
||||||
|
|
||||||
|
<p>On the router, also turn off the application layer gateways that are not actually
|
||||||
|
used - they usually appear in the web interface as "SIP ALG", "FTP ALG", "H.323 ALG",
|
||||||
|
"PPTP passthrough", "IPsec/VPN passthrough". They are commonly enabled by default, they
|
||||||
|
parse the payload of matching connections, and they consume additional session table
|
||||||
|
entries for the connections they expect. If nothing behind the proxy uses FTP, VoIP or
|
||||||
|
those VPN protocols, disabling them frees table space and CPU on exactly the device
|
||||||
|
that is the bottleneck.
|
||||||
|
|
||||||
<h4>Setting Stack Size</h4>
|
<h4>Setting Stack Size</h4>
|
||||||
|
|
||||||
'stacksize' is a size added to all stack allocations and can be both positive and
|
'stacksize' is a size added to all stack allocations and can be both positive and
|
||||||
@ -187,7 +412,11 @@ the need to add additional physical memory,
|
|||||||
but it's system/libc dependent and requires additional testing under your
|
but it's system/libc dependent and requires additional testing under your
|
||||||
installation. Don't forget about memory-related ulimits.
|
installation. Don't forget about memory-related ulimits.
|
||||||
<p>For 32-bit systems, address space can be a bottleneck you should consider. If
|
<p>For 32-bit systems, address space can be a bottleneck you should consider. If
|
||||||
you're short on address space, you can try using a negative stack size.
|
you're short on address space, you can try using a negative stack size. The result is
|
||||||
|
never lowered below the system minimum (PTHREAD_STACK_MIN), so a large negative value
|
||||||
|
can not disable the thread stack. The base value the 'stacksize' is added to is 48K
|
||||||
|
(64K on FreeBSD/NetBSD/OpenBSD/DragonFly, where libc uses more stack, e.g. in
|
||||||
|
vfprintf() called by syslog()).
|
||||||
|
|
||||||
<h4>Known System Issues</h4>
|
<h4>Known System Issues</h4>
|
||||||
|
|
||||||
@ -266,5 +495,5 @@ The example above adds a 10-millisecond delay before reading data if the average
|
|||||||
polling size is below 8000 bytes and 3 read operations have been made in the same
|
polling size is below 8000 bytes and 3 read operations have been made in the same
|
||||||
direction. <pre>logdump 1 1</pre> is useful
|
direction. <pre>logdump 1 1</pre> is useful
|
||||||
to see how grace delays work; choose a delay value to avoid filling the read
|
to see how grace delays work; choose a delay value to avoid filling the read
|
||||||
pipe/buffer (typically 64K) but keep the request sizes close to the chosen average
|
buffer (typically 64K) but keep the request sizes close to the chosen average
|
||||||
on large file uploads/downloads.
|
on large file uploads/downloads.
|
||||||
|
|||||||
@ -2,20 +2,20 @@
|
|||||||
<li>3APA3A 3proxy Tiny Proxy Server HowTo
|
<li>3APA3A 3proxy Tiny Proxy Server HowTo
|
||||||
<br>Under construction, very incomplete
|
<br>Under construction, very incomplete
|
||||||
<ul>
|
<ul>
|
||||||
<li><A HREF="#COMPILE">Compilation</A>
|
<li><A HREF="#COMPILE">Compilation</a>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A HREF="#MSVC">How to compile 3proxy with Visual C++</A>
|
<li><A HREF="#MSVC">How to compile 3proxy with Visual C++</a>
|
||||||
<li><A HREF="#CMAKE">How to compile 3proxy with CMake</A>
|
<li><A HREF="#CMAKE">How to compile 3proxy with CMake</a>
|
||||||
<li><A HREF="#GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</A>
|
<li><A HREF="#GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</a>
|
||||||
</ul>
|
</ul>
|
||||||
<li><A HREF="#INSTALL">Proxy server installation and removal</A>
|
<li><A HREF="#INSTALL">Proxy server installation and removal</a>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A HREF="#INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</A>
|
<li><A HREF="#INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</a>
|
||||||
<li><A HREF="#INSTUNIX">How to install/remove 3proxy under Unix/Linux</A>
|
<li><A HREF="#INSTUNIX">How to install/remove 3proxy under Unix/Linux</a>
|
||||||
<li><A HREF="#INSTMACOS">How to install/remove 3proxy under macOS</A>
|
<li><A HREF="#INSTMACOS">How to install/remove 3proxy under macOS</a>
|
||||||
<li><A HREF="#INSTDOCKER">How to use 3proxy with Docker</A>
|
<li><A HREF="#INSTDOCKER">How to use 3proxy with Docker</a>
|
||||||
</ul>
|
</ul>
|
||||||
<li><A HREF="#SERVER">Server configuration</A>
|
<li><A HREF="#SERVER">Server configuration</a>
|
||||||
<ul>
|
<ul>
|
||||||
<li><a href="#NOTHING">How to make 3proxy start</a></li>
|
<li><a href="#NOTHING">How to make 3proxy start</a></li>
|
||||||
<li><a href="#LIMITS">How to make limitations (access, bandwidth, traffic, connections) work</a></li>
|
<li><a href="#LIMITS">How to make limitations (access, bandwidth, traffic, connections) work</a></li>
|
||||||
@ -24,11 +24,11 @@
|
|||||||
<li><a href="#ODBC">How to make ODBC logging work?</a></li>
|
<li><a href="#ODBC">How to make ODBC logging work?</a></li>
|
||||||
<li><a href="#IPV6">How to make IPv6 work</a></li>
|
<li><a href="#IPV6">How to make IPv6 work</a></li>
|
||||||
<li><a href="#CRASH">How to fix 3proxy crashes</a></li>
|
<li><a href="#CRASH">How to fix 3proxy crashes</a></li>
|
||||||
<li><A HREF="#SAMPLE">Where to find a configuration example</A>
|
<li><A HREF="#SAMPLE">Where to find a configuration example</a>
|
||||||
<li><A HREF="#LOGGING">How to set up logging</A>
|
<li><A HREF="#LOGGING">How to set up logging</a>
|
||||||
<li><A HREF="#LOGFORMAT">How to set up logging format</A>
|
<li><A HREF="#LOGFORMAT">How to set up logging format</a>
|
||||||
<li><A HREF="#LOGANALIZERS">How to use log analyzers with 3proxy</A>
|
<li><A HREF="#LOGANALIZERS">How to use log analyzers with 3proxy</a>
|
||||||
<li><A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>
|
<li><A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a>
|
||||||
<li><a href="#BIND">How to bind a service to a specific interface or port</a>
|
<li><a href="#BIND">How to bind a service to a specific interface or port</a>
|
||||||
<li><a href="#NAMES">How to resolve names through a parent proxy</a></li>
|
<li><a href="#NAMES">How to resolve names through a parent proxy</a></li>
|
||||||
<li><a href="#ISFTP">How to set up an FTP proxy</a></li>
|
<li><a href="#ISFTP">How to set up an FTP proxy</a></li>
|
||||||
@ -37,39 +37,39 @@
|
|||||||
<li><a href="#SSLPLUGIN">How to set up TLS/SSL (https proxy, mTLS)</a></li>
|
<li><a href="#SSLPLUGIN">How to set up TLS/SSL (https proxy, mTLS)</a></li>
|
||||||
<li><a href="#CERTIFICATES">How to create CA and certificates for SSL</a></li>
|
<li><a href="#CERTIFICATES">How to create CA and certificates for SSL</a></li>
|
||||||
<li><a href="#PCRE">How to use PCRE filtering (regular expressions)</a></li>
|
<li><a href="#PCRE">How to use PCRE filtering (regular expressions)</a></li>
|
||||||
<li><A HREF="#AUTH">How to limit service access</A>
|
<li><A HREF="#AUTH">How to limit service access</a>
|
||||||
<li><A HREF="#USERS">How to create a user list</A>
|
<li><A HREF="#USERS">How to create a user list</a>
|
||||||
<li><A HREF="#ACL">How to limit user access to resources</A>
|
<li><A HREF="#ACL">How to limit user access to resources</a>
|
||||||
<li><A HREF="#REDIR">How to manage redirections</A>
|
<li><A HREF="#REDIR">How to manage redirections</a>
|
||||||
<li><a href="#SOCKSREDIR">How to manage local redirections</a>
|
<li><a href="#SOCKSREDIR">How to manage local redirections</a>
|
||||||
<li><A HREF="#ROUNDROBIN">How to balance traffic between multiple external channels?</A>
|
<li><A HREF="#ROUNDROBIN">How to balance traffic between multiple external channels?</a>
|
||||||
<li><A HREF="#CHAIN">How to manage proxy chains</A>
|
<li><A HREF="#CHAIN">How to manage proxy chains</a>
|
||||||
<li><A HREF="#BANDLIM">How to limit bandwidth</A>
|
<li><A HREF="#BANDLIM">How to limit bandwidth</a>
|
||||||
<li><A HREF="#TRAFLIM">How to limit traffic amount</A>
|
<li><A HREF="#TRAFLIM">How to limit traffic amount</a>
|
||||||
<li><a href="#TRAF">How to fix incorrect traffic accounting</a>
|
<li><a href="#TRAF">How to fix incorrect traffic accounting</a>
|
||||||
<li><A HREF="#NETLIST">How to build network lists</A>
|
<li><A HREF="#NETLIST">How to build network lists</a>
|
||||||
<li><a href="#NSCACHING">How to configure name resolution and DNS caching</a>
|
<li><a href="#NSCACHING">How to configure name resolution and DNS caching</a>
|
||||||
<li><a href="#IPV6">How to use IPv6</a>
|
<li><a href="#IPV6">How to use IPv6</a>
|
||||||
<li><a href="#CONNBACK">How to use connect back</a>
|
<li><a href="#CONNBACK">How to use connect back</a>
|
||||||
<li><a href="#HAPROXY">How to use HAProxy PROXY protocol</a>
|
<li><a href="#HAPROXY">How to use HAProxy PROXY protocol</a>
|
||||||
<li><a href="#MAXSEG">How to set TCP maximum segment size (MSS)</a>
|
<li><a href="#MAXSEG">How to set TCP maximum segment size (MSS)</a>
|
||||||
</ul>
|
</ul>
|
||||||
<li><A HREF="#CLIENT">Client configuration</A>
|
<li><A HREF="#CLIENT">Client configuration</a>
|
||||||
<li><A HREF="#ADMIN">Administering and information analysis</A>
|
<li><A HREF="#ADMIN">Administering and information analysis</a>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A HREF="#NEWVERSION">How to obtain the latest 3proxy version</A>
|
<li><A HREF="#NEWVERSION">How to obtain the latest 3proxy version</a>
|
||||||
<li><A HREF="#NTSERVICE">How to control the 3proxy service under Windows NT/2000/XP</A>
|
<li><A HREF="#NTSERVICE">How to control the 3proxy service under Windows NT/2000/XP</a>
|
||||||
<li><A HREF="#ERRORS">Log error codes reference</A>
|
<li><A HREF="#ERRORS">Log error codes reference</a>
|
||||||
</ul>
|
</ul>
|
||||||
<li><A HREF="#QUEST">How to ask a question not in How To?</A>
|
<li><A HREF="#QUEST">How to ask a question not in How To?</a>
|
||||||
</ul>
|
</ul>
|
||||||
<br>
|
<br>
|
||||||
<ul>
|
<ul>
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="COMPILE">Compilation</A>
|
<li><A NAME="COMPILE">Compilation</a>
|
||||||
<p>
|
<p>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A NAME="MSVC">How to compile 3proxy with Visual C++</A>
|
<li><A NAME="MSVC">How to compile 3proxy with Visual C++</a>
|
||||||
<p>
|
<p>
|
||||||
Extract source code files from 3proxy.tgz (with WinZip or another utility) or use git.
|
Extract source code files from 3proxy.tgz (with WinZip or another utility) or use git.
|
||||||
|
|
||||||
@ -78,7 +78,7 @@ nmake /f Makefile.msvc
|
|||||||
</pre>
|
</pre>
|
||||||
Binaries will be placed in the <code>bin/</code> directory.
|
Binaries will be placed in the <code>bin/</code> directory.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="CMAKE">How to compile 3proxy with CMake</A>
|
<li><A NAME="CMAKE">How to compile 3proxy with CMake</a>
|
||||||
<p>
|
<p>
|
||||||
CMake provides a cross-platform build system. It works on Windows (MSVC, MinGW), Linux, macOS, and BSD.
|
CMake provides a cross-platform build system. It works on Windows (MSVC, MinGW), Linux, macOS, and BSD.
|
||||||
<br>Basic build steps:
|
<br>Basic build steps:
|
||||||
@ -100,7 +100,7 @@ cmake -D3PROXY_USE_OPENSSL=ON -D3PROXY_USE_PCRE2=ON ..
|
|||||||
Available options: 3PROXY_USE_OPENSSL, 3PROXY_USE_PCRE2, 3PROXY_USE_PAM, 3PROXY_USE_ODBC.
|
Available options: 3PROXY_USE_OPENSSL, 3PROXY_USE_PCRE2, 3PROXY_USE_PAM, 3PROXY_USE_ODBC.
|
||||||
<br>Binaries will be placed in the <code>build/bin/</code> directory.
|
<br>Binaries will be placed in the <code>build/bin/</code> directory.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</A></li>
|
<li><A NAME="GCCUNIX">How to compile 3proxy with GCC under Unix/Linux</a></li>
|
||||||
<p>
|
<p>
|
||||||
For Linux, use:
|
For Linux, use:
|
||||||
<pre>
|
<pre>
|
||||||
@ -121,14 +121,14 @@ and add the ODBC library to the linker variable.
|
|||||||
</p>
|
</p>
|
||||||
</ul>
|
</ul>
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="INSTALL">Proxy server installation and removal</A>
|
<li><A NAME="INSTALL">Proxy server installation and removal</a>
|
||||||
<p>
|
<p>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A NAME="INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</A>
|
<li><A NAME="INSTNT">How to install/remove 3proxy under Windows NT/2000/XP</a>
|
||||||
<p>
|
<p>
|
||||||
Unpack 3proxy.zip to any directory, for example
|
Unpack 3proxy.zip to any directory, for example
|
||||||
c:\Program Files\3proxy. If needed, create a directory for storing log files,
|
c:\Program Files\3proxy. If needed, create a directory for storing log files,
|
||||||
ODBC sources, etc. Create 3proxy.cfg in the 3proxy installation directory (see <A HREF="#SERVER">Server configuration</A>).
|
ODBC sources, etc. Create 3proxy.cfg in the 3proxy installation directory (see <A HREF="#SERVER">Server configuration</a>).
|
||||||
Now, start a command prompt (cmd.exe).
|
Now, start a command prompt (cmd.exe).
|
||||||
Change to the 3proxy installation directory and run 3proxy.exe --install:
|
Change to the 3proxy installation directory and run 3proxy.exe --install:
|
||||||
<pre>
|
<pre>
|
||||||
@ -148,10 +148,10 @@ C:\Program Files\3proxy>3proxy.exe --remove
|
|||||||
</pre>
|
</pre>
|
||||||
Now you can simply remove the 3proxy installation directory.
|
Now you can simply remove the 3proxy installation directory.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="INSTUNIX">How to install/remove 3proxy under Unix/Linux</A>
|
<li><A NAME="INSTUNIX">How to install/remove 3proxy under Unix/Linux</a>
|
||||||
<p>
|
<p>
|
||||||
<b>Using Makefile:</b>
|
<b>Using Makefile:</b>
|
||||||
<br>Compile 3proxy (see <A HREF="#COMPILE">Compilation</A>) then run:
|
<br>Compile 3proxy (see <A HREF="#COMPILE">Compilation</a>) then run:
|
||||||
<pre>
|
<pre>
|
||||||
sudo make install
|
sudo make install
|
||||||
</pre>
|
</pre>
|
||||||
@ -186,7 +186,7 @@ sudo systemctl enable 3proxy
|
|||||||
sudo systemctl start 3proxy
|
sudo systemctl start 3proxy
|
||||||
</pre>
|
</pre>
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="INSTMACOS">How to install/remove 3proxy under macOS</A>
|
<li><A NAME="INSTMACOS">How to install/remove 3proxy under macOS</a>
|
||||||
<p>
|
<p>
|
||||||
<b>Using CMake (recommended):</b>
|
<b>Using CMake (recommended):</b>
|
||||||
<pre>
|
<pre>
|
||||||
@ -216,22 +216,22 @@ This installs binaries to <code>/usr/local/3proxy/bin/</code> and configuration
|
|||||||
<b>Service management with launchd:</b>
|
<b>Service management with launchd:</b>
|
||||||
<br>After installation via cmake, the service can be managed with launchctl:
|
<br>After installation via cmake, the service can be managed with launchctl:
|
||||||
<pre>
|
<pre>
|
||||||
# Load and start the service
|
# Load and start the service
|
||||||
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
||||||
|
|
||||||
# Stop the service
|
# Stop the service
|
||||||
sudo launchctl stop org.3proxy.3proxy
|
sudo launchctl stop org.3proxy.3proxy
|
||||||
|
|
||||||
# Start the service
|
# Start the service
|
||||||
sudo launchctl start org.3proxy.3proxy
|
sudo launchctl start org.3proxy.3proxy
|
||||||
|
|
||||||
# Unload and disable the service
|
# Unload and disable the service
|
||||||
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
||||||
</pre>
|
</pre>
|
||||||
The service runs as user <code>proxy</code> (created during installation).
|
The service runs as user <code>proxy</code> (created during installation).
|
||||||
Configuration file: <code>/etc/3proxy/3proxy.cfg</code>
|
Configuration file: <code>/etc/3proxy/3proxy.cfg</code>
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="INSTDOCKER">How to use 3proxy with Docker</A>
|
<li><A NAME="INSTDOCKER">How to use 3proxy with Docker</a>
|
||||||
<p>
|
<p>
|
||||||
<b>Using pre-built images from GitHub Container Registry:</b>
|
<b>Using pre-built images from GitHub Container Registry:</b>
|
||||||
<pre>
|
<pre>
|
||||||
@ -264,7 +264,7 @@ For non-chroot execution, mount config to <code>/etc/3proxy</code>.
|
|||||||
</p>
|
</p>
|
||||||
</ul>
|
</ul>
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="SERVER">Server configuration</A>
|
<li><A NAME="SERVER">Server configuration</a>
|
||||||
<p>
|
<p>
|
||||||
<ul>
|
<ul>
|
||||||
<li><a name="NOTHING">How to make 3proxy start</a>
|
<li><a name="NOTHING">How to make 3proxy start</a>
|
||||||
@ -293,7 +293,7 @@ location as 3proxy.exe). For an alternative configuration file location, use
|
|||||||
|
|
||||||
</ul>
|
</ul>
|
||||||
|
|
||||||
<p><A NAME="INTEXT">How to understand internal and external</A>
|
<p><A NAME="INTEXT">How to understand internal and external</a>
|
||||||
<p>
|
<p>
|
||||||
Both internal and external IPs are IPs of the host running 3proxy itself.
|
Both internal and external IPs are IPs of the host running 3proxy itself.
|
||||||
This configuration option is useful in situations where 3proxy is running on a
|
This configuration option is useful in situations where 3proxy is running on a
|
||||||
@ -344,15 +344,15 @@ The best solution is to enable the option to resolve hostnames via the proxy on
|
|||||||
The problem can be resolved with the 'stacksize' command or '-S' option starting with 3proxy 0.8.4.
|
The problem can be resolved with the 'stacksize' command or '-S' option starting with 3proxy 0.8.4.
|
||||||
|
|
||||||
|
|
||||||
<li><A NAME="SAMPLE">Where to find a configuration example</A>
|
<li><A NAME="SAMPLE">Where to find a configuration example</a>
|
||||||
<p>
|
<p>
|
||||||
A server configuration example, 3proxy.cfg.sample, is included in every 3proxy distribution.
|
A server configuration example, 3proxy.cfg.sample, is included in every 3proxy distribution.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="LOGGING">How to set up logging</A>
|
<li><A NAME="LOGGING">How to set up logging</a>
|
||||||
<p>
|
<p>
|
||||||
3proxy can log to stdout, a file, an ODBC datasource, or
|
3proxy can log to stdout, a file, an ODBC datasource, or
|
||||||
syslog (Unix/Linux/Cygwin only). To use ODBC under Unix/Linux, you must
|
syslog (Unix/Linux/Cygwin only). To use ODBC under Unix/Linux, you must
|
||||||
compile 3proxy with Unix ODBC libraries; see <A HREF="#COMPILE">Compilation</A>.
|
compile 3proxy with Unix ODBC libraries; see <A HREF="#COMPILE">Compilation</a>.
|
||||||
You can control logging from 3proxy.cfg for all services, or you can control
|
You can control logging from 3proxy.cfg for all services, or you can control
|
||||||
logging for an individual service. For example,
|
logging for an individual service. For example,
|
||||||
/usr/local/sbin/socks -l/var/log/socks.log starts a SOCKS proxy with logging to a file.
|
/usr/local/sbin/socks -l/var/log/socks.log starts a SOCKS proxy with logging to a file.
|
||||||
@ -379,14 +379,14 @@ specify an ident for syslog logging. If the filename within the "log" command co
|
|||||||
log c:\3proxy\logs\%y%m%d.log D creates a file like c:\3proxy\logs\060729.log;
|
log c:\3proxy\logs\%y%m%d.log D creates a file like c:\3proxy\logs\060729.log;
|
||||||
the date is generated based on local time.
|
the date is generated based on local time.
|
||||||
<pre>
|
<pre>
|
||||||
log &connstring
|
log &connstring;
|
||||||
</pre>
|
</pre>
|
||||||
|
|
||||||
specifies an ODBC connection string; connstring is in the format
|
specifies an ODBC connection string; connstring is in the format
|
||||||
datasource,username,password (the last two are optional if the
|
datasource,username,password (the last two are optional if the
|
||||||
datasource does not require or already has authentication information).
|
datasource does not require or already has authentication information).
|
||||||
Also, you must specify logformat to build the SQL query to insert a record into
|
Also, you must specify logformat to build the SQL query to insert a record into
|
||||||
the log; see <A HREF="#LOGFORMAT">How to set up logging format</A>
|
the log; see <A HREF="#LOGFORMAT">How to set up logging format</a>
|
||||||
</p>
|
</p>
|
||||||
<p>
|
<p>
|
||||||
Rotation and archiving may be set up with log, rotate, and archiver commands.
|
Rotation and archiving may be set up with log, rotate, and archiver commands.
|
||||||
@ -416,7 +416,7 @@ sets the rotation type. LOGTYPE may be:
|
|||||||
Examples are located in
|
Examples are located in
|
||||||
3proxy.cfg.sample
|
3proxy.cfg.sample
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="LOGFORMAT">How to set up logging format</A>
|
<li><A NAME="LOGFORMAT">How to set up logging format</a>
|
||||||
<p>
|
<p>
|
||||||
Since version 0.3, the log format may be set with the "logformat" command.
|
Since version 0.3, the log format may be set with the "logformat" command.
|
||||||
The first symbol of the log format specifies the format of the date and time and
|
The first symbol of the log format specifies the format of the date and time and
|
||||||
@ -437,7 +437,7 @@ sets the rotation type. LOGTYPE may be:
|
|||||||
<li> %U - Username ('-' if unknown).
|
<li> %U - Username ('-' if unknown).
|
||||||
<li> %N - Service name (PROXY, SOCKS, POP3P, etc.)
|
<li> %N - Service name (PROXY, SOCKS, POP3P, etc.)
|
||||||
<li> %p - Service port
|
<li> %p - Service port
|
||||||
<li> %E - Error code (see <A HREF="#ERRORS">Log error codes reference</A>)
|
<li> %E - Error code (see <A HREF="#ERRORS">Log error codes reference</a>)
|
||||||
<li> %C - client IP
|
<li> %C - client IP
|
||||||
<li> %c - client port
|
<li> %c - client port
|
||||||
<li> %R - target IP
|
<li> %R - target IP
|
||||||
@ -449,7 +449,7 @@ sets the rotation type. LOGTYPE may be:
|
|||||||
<li> %O - bytes sent to the target
|
<li> %O - bytes sent to the target
|
||||||
<li> %n - hostname from the request
|
<li> %n - hostname from the request
|
||||||
<li> %h - hops before the target (if redirection or chaining is used);
|
<li> %h - hops before the target (if redirection or chaining is used);
|
||||||
see <A HREF="#CHAIN">How to use chains and parent proxies</A>)
|
see <A HREF="#CHAIN">How to use chains and parent proxies</a>)
|
||||||
<li> %T - service-specific text (for example, the requested URL). %X-YT,
|
<li> %T - service-specific text (for example, the requested URL). %X-YT,
|
||||||
where X and Y are positive numbers, only displays fields
|
where X and Y are positive numbers, only displays fields
|
||||||
(space-delimited) X to Y of the text. An example is %1-2T.
|
(space-delimited) X to Y of the text. An example is %1-2T.
|
||||||
@ -472,7 +472,7 @@ logformat "-\'+_GINSERT INTO proxystat VALUES (%t, '%c', '%U', %I)"</pre>
|
|||||||
<br>(no line breaks)
|
<br>(no line breaks)
|
||||||
<br>-\'+_ instructs to replace characters \ and ' with _
|
<br>-\'+_ instructs to replace characters \ and ' with _
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="LOGANALIZERS">How to use log analyzers with 3proxy</A>
|
<li><A NAME="LOGANALIZERS">How to use log analyzers with 3proxy</a>
|
||||||
<p>
|
<p>
|
||||||
Just make the format of 3proxy logs compatible with a format supported by your
|
Just make the format of 3proxy logs compatible with a format supported by your
|
||||||
favorite log analyzer. Examples of compatible logformats are:
|
favorite log analyzer. Examples of compatible logformats are:
|
||||||
@ -515,7 +515,7 @@ or a more compatible format without the error code:
|
|||||||
<p><font face="courier">
|
<p><font face="courier">
|
||||||
"-""+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] ""%T"" 200 %I"
|
"-""+_L%C - %U [%d/%o/%Y:%H:%M:%S %z] ""%T"" 200 %I"
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>
|
<li><A NAME="LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a>
|
||||||
<p>
|
<p>
|
||||||
3proxy is distributed in 2 variants: as a set of standalone modules (proxy,
|
3proxy is distributed in 2 variants: as a set of standalone modules (proxy,
|
||||||
socks, pop3p, tcppm, udppm) and as a universal proxy server. These services are
|
socks, pop3p, tcppm, udppm) and as a universal proxy server. These services are
|
||||||
@ -552,7 +552,7 @@ except socks, which is started with port 3129.
|
|||||||
All logs are in the file /var/log/3proxy.log (with daily date modification and
|
All logs are in the file /var/log/3proxy.log (with daily date modification and
|
||||||
rotation). The 30 most recent files are stored.
|
rotation). The 30 most recent files are stored.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="BIND">How to bind a service to a specific interface and port?</A>
|
<li><A NAME="BIND">How to bind a service to a specific interface and port?</a>
|
||||||
<p>
|
<p>
|
||||||
The -i option specifies the internal interface; -p specifies the listening port. No spaces are
|
The -i option specifies the internal interface; -p specifies the listening port. No spaces are
|
||||||
allowed. To bind the 'proxy' service to port 8080 on interfaces 192.168.1.1
|
allowed. To bind the 'proxy' service to port 8080 on interfaces 192.168.1.1
|
||||||
@ -606,17 +606,17 @@ tlspr supports both: for implicit TLS the destination host is taken from SNI and
|
|||||||
the -X option makes tlspr speak the plaintext protocol phase with the client (greeting, STARTTLS command) before
|
the -X option makes tlspr speak the plaintext protocol phase with the client (greeting, STARTTLS command) before
|
||||||
upgrading both sides to TLS. Example:
|
upgrading both sides to TLS. Example:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# https (implicit)
|
# https (implicit)
|
||||||
tlspr -p443 -P443 -c1
|
tlspr -p443 -P443 -c1
|
||||||
# imaps (implicit)
|
# imaps (implicit)
|
||||||
tlspr -p993 -P993 -c1
|
tlspr -p993 -P993 -c1
|
||||||
# submissions (implicit)
|
# submissions (implicit)
|
||||||
tlspr -p465 -P465 -c1
|
tlspr -p465 -P465 -c1
|
||||||
# imap STARTTLS (explicit)
|
# imap STARTTLS (explicit)
|
||||||
tlspr -p143 -P143 -Ximap
|
tlspr -p143 -P143 -Ximap
|
||||||
# submission STARTTLS (explicit)
|
# submission STARTTLS (explicit)
|
||||||
tlspr -p587 -P587 -Xsmtp
|
tlspr -p587 -P587 -Xsmtp
|
||||||
# pop3 STLS (explicit)
|
# pop3 STLS (explicit)
|
||||||
tlspr -p110 -P110 -Xpop3
|
tlspr -p110 -P110 -Xpop3
|
||||||
</pre>
|
</pre>
|
||||||
<p>
|
<p>
|
||||||
@ -679,9 +679,7 @@ socks
|
|||||||
<p>
|
<p>
|
||||||
3. Using tlspr with HTTP proxy for TLS hostname-based ACL:
|
3. Using tlspr with HTTP proxy for TLS hostname-based ACL:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
allow * * * 80
|
allow * * * * HTTP_CONNECT
|
||||||
parent 1000 http 0.0.0.0 0
|
|
||||||
allow * * * 443
|
|
||||||
parent 1000 tls 0.0.0.0 0
|
parent 1000 tls 0.0.0.0 0
|
||||||
deny * * blocked.example.com
|
deny * * blocked.example.com
|
||||||
allow *
|
allow *
|
||||||
@ -707,15 +705,15 @@ nscache 65536
|
|||||||
nscache6 65536
|
nscache6 65536
|
||||||
dnspr -p53
|
dnspr -p53
|
||||||
|
|
||||||
# google
|
# google
|
||||||
nsrecord smtp.gmail.com 10.0.0.1
|
nsrecord smtp.gmail.com 10.0.0.1
|
||||||
nsrecord imap.gmail.com 10.0.0.1
|
nsrecord imap.gmail.com 10.0.0.1
|
||||||
nsrecord pop.gmail.com 10.0.0.1
|
nsrecord pop.gmail.com 10.0.0.1
|
||||||
# mail.ru
|
# mail.ru
|
||||||
nsrecord smtp.mail.ru 10.0.0.1
|
nsrecord smtp.mail.ru 10.0.0.1
|
||||||
nsrecord imap.mail.ru 10.0.0.1
|
nsrecord imap.mail.ru 10.0.0.1
|
||||||
nsrecord pop.mail.ru 10.0.0.1
|
nsrecord pop.mail.ru 10.0.0.1
|
||||||
# yandex.ru
|
# yandex.ru
|
||||||
nsrecord smtp.yandex.ru 10.0.0.1
|
nsrecord smtp.yandex.ru 10.0.0.1
|
||||||
nsrecord imap.yandex.ru 10.0.0.1
|
nsrecord imap.yandex.ru 10.0.0.1
|
||||||
nsrecord pop.yandex.ru 10.0.0.1
|
nsrecord pop.yandex.ru 10.0.0.1
|
||||||
@ -827,10 +825,10 @@ This creates an HTTPS proxy (ssl_serv) that accepts TLS connections from clients
|
|||||||
<b>Creating a Certificate Authority (CA):</b>
|
<b>Creating a Certificate Authority (CA):</b>
|
||||||
<br>For MITM or mTLS, you need a CA. Generate a CA private key and certificate:
|
<br>For MITM or mTLS, you need a CA. Generate a CA private key and certificate:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Generate CA private key
|
# Generate CA private key
|
||||||
openssl genrsa -out ca.key 4096
|
openssl genrsa -out ca.key 4096
|
||||||
|
|
||||||
# Generate CA certificate (valid for 10 years)
|
# Generate CA certificate (valid for 10 years)
|
||||||
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
||||||
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=My CA" \
|
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=My CA" \
|
||||||
-out ca.crt
|
-out ca.crt
|
||||||
@ -842,15 +840,15 @@ For MITM, import ca.crt into client browsers/OS as a trusted root CA.
|
|||||||
<b>Creating a server certificate for https:// proxy:</b>
|
<b>Creating a server certificate for https:// proxy:</b>
|
||||||
<br>The server certificate must have proper Subject Alternative Names (SAN):
|
<br>The server certificate must have proper Subject Alternative Names (SAN):
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Generate server private key
|
# Generate server private key
|
||||||
openssl genrsa -out server.key 2048
|
openssl genrsa -out server.key 2048
|
||||||
|
|
||||||
# Create a certificate signing request (CSR)
|
# Create a certificate signing request (CSR)
|
||||||
openssl req -new -key server.key \
|
openssl req -new -key server.key \
|
||||||
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=proxy.example.com" \
|
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=proxy.example.com" \
|
||||||
-out server.csr
|
-out server.csr
|
||||||
|
|
||||||
# Create extensions file for SAN
|
# Create extensions file for SAN
|
||||||
cat > server.ext << 'EOF'
|
cat > server.ext << 'EOF'
|
||||||
authorityKeyIdentifier=keyid,issuer
|
authorityKeyIdentifier=keyid,issuer
|
||||||
basicConstraints=CA:FALSE
|
basicConstraints=CA:FALSE
|
||||||
@ -864,7 +862,7 @@ DNS.2 = proxy
|
|||||||
IP.1 = 192.168.1.100
|
IP.1 = 192.168.1.100
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
# Sign the certificate with CA
|
# Sign the certificate with CA
|
||||||
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out server.crt -days 365 -sha256 \
|
-CAcreateserial -out server.crt -days 365 -sha256 \
|
||||||
-extfile server.ext
|
-extfile server.ext
|
||||||
@ -875,27 +873,27 @@ For a public https:// proxy, use a CA like Let's Encrypt instead of self-signed.
|
|||||||
<p>
|
<p>
|
||||||
<b>Creating a client certificate for mTLS:</b>
|
<b>Creating a client certificate for mTLS:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Generate client private key
|
# Generate client private key
|
||||||
openssl genrsa -out client1.key 2048
|
openssl genrsa -out client1.key 2048
|
||||||
|
|
||||||
# Create CSR
|
# Create CSR
|
||||||
openssl req -new -key client1.key \
|
openssl req -new -key client1.key \
|
||||||
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=client1" \
|
-subj "/C=US/ST=State/L=City/O=MyOrg/CN=client1" \
|
||||||
-out client1.csr
|
-out client1.csr
|
||||||
|
|
||||||
# Create extensions file
|
# Create extensions file
|
||||||
cat > client.ext << 'EOF'
|
cat > client.ext << 'EOF'
|
||||||
basicConstraints=CA:FALSE
|
basicConstraints=CA:FALSE
|
||||||
keyUsage = digitalSignature, nonRepudiation, keyEncipherment
|
keyUsage = digitalSignature, nonRepudiation, keyEncipherment
|
||||||
extendedKeyUsage = clientAuth
|
extendedKeyUsage = clientAuth
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
# Sign with CA
|
# Sign with CA
|
||||||
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out client1.crt -days 365 -sha256 \
|
-CAcreateserial -out client1.crt -days 365 -sha256 \
|
||||||
-extfile client.ext
|
-extfile client.ext
|
||||||
|
|
||||||
# Create PKCS#12 bundle for browser import
|
# Create PKCS#12 bundle for browser import
|
||||||
openssl pkcs12 -export -out client1.p12 \
|
openssl pkcs12 -export -out client1.p12 \
|
||||||
-inkey client1.key -in client1.crt -certfile ca.crt
|
-inkey client1.key -in client1.crt -certfile ca.crt
|
||||||
</pre>
|
</pre>
|
||||||
@ -905,15 +903,15 @@ Import client1.p12 into the client browser or OS certificate store.
|
|||||||
<p>
|
<p>
|
||||||
<b>Quick setup script for development/testing:</b>
|
<b>Quick setup script for development/testing:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# Creates CA, server, and client certificates for SSLPlugin testing
|
# Creates CA, server, and client certificates for SSLPlugin testing
|
||||||
|
|
||||||
# CA
|
# CA
|
||||||
openssl genrsa -out ca.key 4096
|
openssl genrsa -out ca.key 4096
|
||||||
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
||||||
-subj "/CN=3proxy CA" -out ca.crt
|
-subj "/CN=3proxy CA" -out ca.crt
|
||||||
|
|
||||||
# Server
|
# Server
|
||||||
openssl genrsa -out server.key 2048
|
openssl genrsa -out server.key 2048
|
||||||
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
|
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
|
||||||
cat > server.ext << 'EOF'
|
cat > server.ext << 'EOF'
|
||||||
@ -925,7 +923,7 @@ EOF
|
|||||||
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
|
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
|
||||||
|
|
||||||
# Client
|
# Client
|
||||||
openssl genrsa -out client.key 2048
|
openssl genrsa -out client.key 2048
|
||||||
openssl req -new -key client.key -subj "/CN=client" -out client.csr
|
openssl req -new -key client.key -subj "/CN=client" -out client.csr
|
||||||
cat > client.ext << 'EOF'
|
cat > client.ext << 'EOF'
|
||||||
@ -982,13 +980,13 @@ matches the connection data.
|
|||||||
<p>
|
<p>
|
||||||
<b>Examples:</b>
|
<b>Examples:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Block requests containing specific keywords for certain users
|
# Block requests containing specific keywords for certain users
|
||||||
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
|
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
|
||||||
|
|
||||||
# Block responses with specific content type
|
# Block responses with specific content type
|
||||||
pcre srvheader deny "Content-type: application"
|
pcre srvheader deny "Content-type: application"
|
||||||
|
|
||||||
# Replace content in both directions (censorship)
|
# Replace content in both directions (censorship)
|
||||||
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
|
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
|
||||||
pcre_extend deny * 192.168.0.1/16
|
pcre_extend deny * 192.168.0.1/16
|
||||||
</pre>
|
</pre>
|
||||||
@ -996,11 +994,11 @@ pcre_extend deny * 192.168.0.1/16
|
|||||||
<b>Note:</b> Regular expressions don't require authentication and cannot replace
|
<b>Note:</b> Regular expressions don't require authentication and cannot replace
|
||||||
authentication and/or allow/deny ACLs.
|
authentication and/or allow/deny ACLs.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="AUTH">How to limit service access</A>
|
<li><A NAME="AUTH">How to limit service access</a>
|
||||||
<p>
|
<p>
|
||||||
First, always specify the internal interface to accept incoming connections with the
|
First, always specify the internal interface to accept incoming connections with the
|
||||||
'internal' configuration command or '-i' service command. (See
|
'internal' configuration command or '-i' service command. (See
|
||||||
<A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</A>). If
|
<A HREF="#LAUNCH">How to start any of the proxy services (HTTP, SOCKS, etc.)</a>). If
|
||||||
no internal interface is specified, your proxy will act as an open proxy.
|
no internal interface is specified, your proxy will act as an open proxy.
|
||||||
<p>It's also important to specify the external interface to prevent access to the
|
<p>It's also important to specify the external interface to prevent access to the
|
||||||
internal network with 'external' or -e.
|
internal network with 'external' or -e.
|
||||||
@ -1042,7 +1040,7 @@ socks
|
|||||||
|
|
||||||
It's possible to authorize access by client IP address, IP address or requested resource,
|
It's possible to authorize access by client IP address, IP address or requested resource,
|
||||||
target port, time, etc., after authentication.
|
target port, time, etc., after authentication.
|
||||||
(See <A HREF="#ACL">How to limit resource access</A>).
|
(See <A HREF="#ACL">How to limit resource access</a>).
|
||||||
</p><p>Since version 0.6, double authentication is possible, e.g.:
|
</p><p>Since version 0.6, double authentication is possible, e.g.:
|
||||||
<pre>
|
<pre>
|
||||||
auth iponly strong
|
auth iponly strong
|
||||||
@ -1081,7 +1079,7 @@ critical resources, such as web administration.
|
|||||||
auth cache strong</pre>
|
auth cache strong</pre>
|
||||||
the user will not be able to use more than a single IP during the cache time (120 sec).
|
the user will not be able to use more than a single IP during the cache time (120 sec).
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="USERS">How to create a user list</A>
|
<li><A NAME="USERS">How to create a user list</a>
|
||||||
<p>
|
<p>
|
||||||
The user list is created with the 'users' command.
|
The user list is created with the 'users' command.
|
||||||
<pre>
|
<pre>
|
||||||
@ -1120,7 +1118,7 @@ It's possible to create NT and crypt passwords with the 3proxy_crypt utility inc
|
|||||||
in the distribution.
|
in the distribution.
|
||||||
<br>The user list is system-wide. To manage user access to a specific service, use ACLs.
|
<br>The user list is system-wide. To manage user access to a specific service, use ACLs.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="ACL">How to limit user access to resources</A>
|
<li><A NAME="ACL">How to limit user access to resources</a>
|
||||||
<p>
|
<p>
|
||||||
The commands allow, deny, and flush are used to manage ACLs:
|
The commands allow, deny, and flush are used to manage ACLs:
|
||||||
<p><font face="courier">
|
<p><font face="courier">
|
||||||
@ -1132,7 +1130,7 @@ allow <userlist> <sourcelist> <targetlist> <targetportlist&
|
|||||||
The 'flush' command is used to finish with the existing ACL and start a new one.
|
The 'flush' command is used to finish with the existing ACL and start a new one.
|
||||||
It's required to have different ACLs for different services.
|
It's required to have different ACLs for different services.
|
||||||
'allow' is used to allow a connection, and 'deny' to deny a connection. The 'allow'
|
'allow' is used to allow a connection, and 'deny' to deny a connection. The 'allow'
|
||||||
command can be extended by the 'parent' command to manage redirections (see <A href="#REDIR">How to manage redirections</A>). If the ACL
|
command can be extended by the 'parent' command to manage redirections (see <A href="#REDIR">How to manage redirections</a>). If the ACL
|
||||||
is empty, it allows everything. If the ACL is not empty, the first matching ACL entry
|
is empty, it allows everything. If the ACL is not empty, the first matching ACL entry
|
||||||
is searched for the user request, and the ACL action (allow or deny) is performed. If
|
is searched for the user request, and the ACL action (allow or deny) is performed. If
|
||||||
no matching record is found, the connection is denied, and the user will be asked to
|
no matching record is found, the connection is denied, and the user will be asked to
|
||||||
@ -1180,7 +1178,7 @@ add 'deny *' to the end of the list.
|
|||||||
* in an ACL means "any".
|
* in an ACL means "any".
|
||||||
Usage examples can be found in 3proxy.cfg.sample.
|
Usage examples can be found in 3proxy.cfg.sample.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="REDIR">How to manage redirections</A>
|
<li><A NAME="REDIR">How to manage redirections</a>
|
||||||
<p>
|
<p>
|
||||||
Redirections are useful to, e.g., forward requests from specific clients
|
Redirections are useful to, e.g., forward requests from specific clients
|
||||||
to different servers or proxy servers. Additionally, redirections are useful
|
to different servers or proxy servers. Additionally, redirections are useful
|
||||||
@ -1239,22 +1237,22 @@ auth iponly
|
|||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http 0.0.0.0 0
|
parent 1000 http 0.0.0.0 0
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
#redirect ports 80 and 8080-8088 to local HTTP proxy
|
#redirect ports 80 and 8080-8088 to local HTTP proxy
|
||||||
#Second allow is required, because ACLs are checked
|
#Second allow is required, because ACLs are checked
|
||||||
#twice: first time by socks and second by http proxy.
|
#twice: first time by socks and second by http proxy.
|
||||||
|
|
||||||
allow * * * 21,2121
|
allow * * * 21,2121
|
||||||
parent 1000 ftp 0.0.0.0 0
|
parent 1000 ftp 0.0.0.0 0
|
||||||
allow * * * 21,2121
|
allow * * * 21,2121
|
||||||
#redirect ports 21 and 2121 to local
|
#redirect ports 21 and 2121 to local
|
||||||
#ftp proxy
|
#ftp proxy
|
||||||
|
|
||||||
|
|
||||||
allow *
|
allow *
|
||||||
#allow the rest of connections directly
|
#allow the rest of connections directly
|
||||||
|
|
||||||
socks
|
socks
|
||||||
#now let the socks server start
|
#now let the socks server start
|
||||||
</pre>
|
</pre>
|
||||||
|
|
||||||
<p><i>Q: How does it affect different ACL rules?</i></p>
|
<p><i>Q: How does it affect different ACL rules?</i></p>
|
||||||
@ -1262,20 +1260,20 @@ A: After local redirections, rules are applied again to the protocol-level reque
|
|||||||
<pre>
|
<pre>
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http 0.0.0.0 0
|
parent 1000 http 0.0.0.0 0
|
||||||
#redirect http traffic to internal proxy
|
#redirect http traffic to internal proxy
|
||||||
|
|
||||||
allow * * $c:\3proxy\local.nets 80,8080-8088
|
allow * * $c:\3proxy\local.nets 80,8080-8088
|
||||||
#allow direct access to local.nets networks
|
#allow direct access to local.nets networks
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http proxy.3proxy.org 3128
|
parent 1000 http proxy.3proxy.org 3128
|
||||||
#use parent caching proxy for the rest of the networks
|
#use parent caching proxy for the rest of the networks
|
||||||
|
|
||||||
allow *
|
allow *
|
||||||
#allow direct connections for the rest of socks
|
#allow direct connections for the rest of socks
|
||||||
#requests
|
#requests
|
||||||
</pre>
|
</pre>
|
||||||
|
|
||||||
<li><A NAME="ROUNDROBIN">How to balance traffic between multiple external channels?</A>
|
<li><A NAME="ROUNDROBIN">How to balance traffic between multiple external channels?</a>
|
||||||
<p>
|
<p>
|
||||||
The proxy itself doesn't manage network-level routing. The only way to control
|
The proxy itself doesn't manage network-level routing. The only way to control
|
||||||
the outgoing channel is to select the external interface. It's possible to make
|
the outgoing channel is to select the external interface. It's possible to make
|
||||||
@ -1304,7 +1302,7 @@ for Windows:
|
|||||||
If you don't have a second address yet, just add it. Under Linux/Unix, it's better
|
If you don't have a second address yet, just add it. Under Linux/Unix, it's better
|
||||||
to use source routing.
|
to use source routing.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="CHAIN">How to manage proxy chains</A>
|
<li><A NAME="CHAIN">How to manage proxy chains</a>
|
||||||
<p>
|
<p>
|
||||||
The parent command may also be used to build proxy chains. In this case,
|
The parent command may also be used to build proxy chains. In this case,
|
||||||
multiple 'parent' commands are used for a single 'allow' rule with different
|
multiple 'parent' commands are used for a single 'allow' rule with different
|
||||||
@ -1340,7 +1338,7 @@ the second hop is 192.168.20.1, and the 3rd one is either 192.168.30.1 with a pr
|
|||||||
of 30% or 192.168.40.1 with a probability of 70%.
|
of 30% or 192.168.40.1 with a probability of 70%.
|
||||||
</p>
|
</p>
|
||||||
|
|
||||||
<li><A NAME="BANDLIM">How to limit bandwidth</A>
|
<li><A NAME="BANDLIM">How to limit bandwidth</a>
|
||||||
<p>
|
<p>
|
||||||
3proxy supports bandwidth filters. Use the bandlimin/bandlimout and
|
3proxy supports bandwidth filters. Use the bandlimin/bandlimout and
|
||||||
nobandlimin/nobandlimout commands to manage filters. 'in' means incoming and 'out' means outgoing traffic.
|
nobandlimin/nobandlimout commands to manage filters. 'in' means incoming and 'out' means outgoing traffic.
|
||||||
@ -1370,7 +1368,7 @@ In this example:
|
|||||||
mail traffic from POP3 servers bypasses the pipe and has no bandwidth
|
mail traffic from POP3 servers bypasses the pipe and has no bandwidth
|
||||||
limitation.
|
limitation.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="TRAFLIM">How to limit traffic amount</A>
|
<li><A NAME="TRAFLIM">How to limit traffic amount</a>
|
||||||
<p>
|
<p>
|
||||||
<p><font face="courier">
|
<p><font face="courier">
|
||||||
counter <filename> <type> <reportpath>
|
counter <filename> <type> <reportpath>
|
||||||
@ -1504,21 +1502,21 @@ proxy -p3128 -OcTCP_NODELAY,TCP_MAXSEG -OsTCP_NODELAY,TCP_MAXSEG
|
|||||||
</ul>
|
</ul>
|
||||||
|
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="CLIENT">Client configuration</A>
|
<li><A NAME="CLIENT">Client configuration</a>
|
||||||
<p>
|
<p>
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="ADMIN">Administering and information analysis</A>
|
<li><A NAME="ADMIN">Administering and information analysis</a>
|
||||||
<p>
|
<p>
|
||||||
<ul>
|
<ul>
|
||||||
<li><A NAME="NEWVERSION">How to obtain latest 3proxy version</A>
|
<li><A NAME="NEWVERSION">How to obtain latest 3proxy version</a>
|
||||||
<p>
|
<p>
|
||||||
The latest version of 3proxy may be obtained
|
The latest version of 3proxy may be obtained
|
||||||
<A HREF="https://3proxy.org/">here</A>.
|
<A HREF="https://3proxy.org/">here</a>.
|
||||||
A new version may have changes and incompatibilities with the previous one in file
|
A new version may have changes and incompatibilities with the previous one in file
|
||||||
formats or commands. Please read the CHANGELOG file and other documentation
|
formats or commands. Please read the CHANGELOG file and other documentation
|
||||||
before installing a new version.
|
before installing a new version.
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="NTSERVICE">How to control 3proxy service under Windows NT/2000/XP</A>
|
<li><A NAME="NTSERVICE">How to control 3proxy service under Windows NT/2000/XP</a>
|
||||||
<p>
|
<p>
|
||||||
If installed as a system service, 3proxy understands Windows service commands
|
If installed as a system service, 3proxy understands Windows service commands
|
||||||
for START, STOP, PAUSE, and RESUME. If the service is PAUSEd, no new connections
|
for START, STOP, PAUSE, and RESUME. If the service is PAUSEd, no new connections
|
||||||
@ -1534,7 +1532,7 @@ You can control the 3proxy service via "Services" administration or via the "net
|
|||||||
net continue 3proxy
|
net continue 3proxy
|
||||||
</pre>
|
</pre>
|
||||||
</p>
|
</p>
|
||||||
<li><A NAME="ERRORS">Log error codes reference</A>
|
<li><A NAME="ERRORS">Log error codes reference</a>
|
||||||
<p>
|
<p>
|
||||||
<ul>
|
<ul>
|
||||||
<li>0 - Operation successfully completed (connection
|
<li>0 - Operation successfully completed (connection
|
||||||
@ -1597,9 +1595,9 @@ You can control the 3proxy service via "Services" administration or via the "net
|
|||||||
</p>
|
</p>
|
||||||
</ul>
|
</ul>
|
||||||
<hr>
|
<hr>
|
||||||
<li><A NAME="QUEST">How to ask a question not in How To?</A>
|
<li><A NAME="QUEST">How to ask a question not in How To?</a>
|
||||||
<p>
|
<p>
|
||||||
Ask it in <A HREF="https://github.com/z3APA3A/3proxy/issues">Github</A>.
|
Ask it in <A HREF="https://github.com/z3APA3A/3proxy/issues">Github</a>.
|
||||||
Please read this document before asking a question.
|
Please read this document before asking a question.
|
||||||
</ul>
|
</ul>
|
||||||
|
|
||||||
|
|||||||
@ -210,16 +210,16 @@
|
|||||||
<b>Управление службой через launchd:</b>
|
<b>Управление службой через launchd:</b>
|
||||||
<br>После установки через cmake службой можно управлять с помощью launchctl:
|
<br>После установки через cmake службой можно управлять с помощью launchctl:
|
||||||
<pre>
|
<pre>
|
||||||
# Загрузить и запустить службу
|
# Загрузить и запустить службу
|
||||||
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
sudo launchctl load /Library/LaunchDaemons/org.3proxy.3proxy.plist
|
||||||
|
|
||||||
# Остановить службу
|
# Остановить службу
|
||||||
sudo launchctl stop org.3proxy.3proxy
|
sudo launchctl stop org.3proxy.3proxy
|
||||||
|
|
||||||
# Запустить службу
|
# Запустить службу
|
||||||
sudo launchctl start org.3proxy.3proxy
|
sudo launchctl start org.3proxy.3proxy
|
||||||
|
|
||||||
# Выгрузить и отключить службу
|
# Выгрузить и отключить службу
|
||||||
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist</pre>
|
sudo launchctl unload /Library/LaunchDaemons/org.3proxy.3proxy.plist</pre>
|
||||||
Служба запускается от имени пользователя <code>proxy</code> (создаётся при установке).
|
Служба запускается от имени пользователя <code>proxy</code> (создаётся при установке).
|
||||||
Файл конфигурации: <code>/etc/3proxy/3proxy.cfg</code>
|
Файл конфигурации: <code>/etc/3proxy/3proxy.cfg</code>
|
||||||
@ -388,7 +388,7 @@
|
|||||||
-l@ident</pre>
|
-l@ident</pre>
|
||||||
соответствуют ведению журнала через syslog с идентификатором ident.
|
соответствуют ведению журнала через syslog с идентификатором ident.
|
||||||
<pre>
|
<pre>
|
||||||
log &connstring</pre>
|
log &connstring;</pre>
|
||||||
соответствует ведению журнала через ODBC, connstring задается в формате
|
соответствует ведению журнала через ODBC, connstring задается в формате
|
||||||
datasource,username,password (последние два параметра опциональны, если
|
datasource,username,password (последние два параметра опциональны, если
|
||||||
datasource не требует или уже содержит сведения для авторизации). При этом
|
datasource не требует или уже содержит сведения для авторизации). При этом
|
||||||
@ -614,17 +614,17 @@ tlspr поддерживает оба варианта: для implicit TLS хо
|
|||||||
опция -X заставляет tlspr говорить с клиентом на plaintext-фазе протокола (приветствие, команда STARTTLS) перед
|
опция -X заставляет tlspr говорить с клиентом на plaintext-фазе протокола (приветствие, команда STARTTLS) перед
|
||||||
поднятием TLS с обеих сторон. Пример:
|
поднятием TLS с обеих сторон. Пример:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# https (implicit)
|
# https (implicit)
|
||||||
tlspr -p443 -P443 -c1
|
tlspr -p443 -P443 -c1
|
||||||
# imaps (implicit)
|
# imaps (implicit)
|
||||||
tlspr -p993 -P993 -c1
|
tlspr -p993 -P993 -c1
|
||||||
# submissions (implicit)
|
# submissions (implicit)
|
||||||
tlspr -p465 -P465 -c1
|
tlspr -p465 -P465 -c1
|
||||||
# imap STARTTLS (explicit)
|
# imap STARTTLS (explicit)
|
||||||
tlspr -p143 -P143 -Ximap
|
tlspr -p143 -P143 -Ximap
|
||||||
# submission STARTTLS (explicit)
|
# submission STARTTLS (explicit)
|
||||||
tlspr -p587 -P587 -Xsmtp
|
tlspr -p587 -P587 -Xsmtp
|
||||||
# pop3 STLS (explicit)
|
# pop3 STLS (explicit)
|
||||||
tlspr -p110 -P110 -Xpop3
|
tlspr -p110 -P110 -Xpop3
|
||||||
</pre>
|
</pre>
|
||||||
<p>
|
<p>
|
||||||
@ -687,9 +687,7 @@ socks
|
|||||||
<p>
|
<p>
|
||||||
3. Использование tlspr с HTTP proxy для ACL по имени хоста TLS:
|
3. Использование tlspr с HTTP proxy для ACL по имени хоста TLS:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
allow * * * 80
|
allow * * * * HTTP_CONNECT
|
||||||
parent 1000 http 0.0.0.0 0
|
|
||||||
allow * * * 443
|
|
||||||
parent 1000 tls 0.0.0.0 0
|
parent 1000 tls 0.0.0.0 0
|
||||||
deny * * blocked.example.com
|
deny * * blocked.example.com
|
||||||
allow *
|
allow *
|
||||||
@ -716,15 +714,15 @@ nscache 65536
|
|||||||
nscache6 65536
|
nscache6 65536
|
||||||
dnspr -p53
|
dnspr -p53
|
||||||
|
|
||||||
# google
|
# google
|
||||||
nsrecord smtp.gmail.com 10.0.0.1
|
nsrecord smtp.gmail.com 10.0.0.1
|
||||||
nsrecord imap.gmail.com 10.0.0.1
|
nsrecord imap.gmail.com 10.0.0.1
|
||||||
nsrecord pop.gmail.com 10.0.0.1
|
nsrecord pop.gmail.com 10.0.0.1
|
||||||
# mail.ru
|
# mail.ru
|
||||||
nsrecord smtp.mail.ru 10.0.0.1
|
nsrecord smtp.mail.ru 10.0.0.1
|
||||||
nsrecord imap.mail.ru 10.0.0.1
|
nsrecord imap.mail.ru 10.0.0.1
|
||||||
nsrecord pop.mail.ru 10.0.0.1
|
nsrecord pop.mail.ru 10.0.0.1
|
||||||
# yandex.ru
|
# yandex.ru
|
||||||
nsrecord smtp.yandex.ru 10.0.0.1
|
nsrecord smtp.yandex.ru 10.0.0.1
|
||||||
nsrecord imap.yandex.ru 10.0.0.1
|
nsrecord imap.yandex.ru 10.0.0.1
|
||||||
nsrecord pop.yandex.ru 10.0.0.1
|
nsrecord pop.yandex.ru 10.0.0.1
|
||||||
@ -837,10 +835,10 @@ ssl_nocli
|
|||||||
<b>Создание удостоверяющего центра (CA):</b>
|
<b>Создание удостоверяющего центра (CA):</b>
|
||||||
<br>Для MITM или mTLS требуется CA. Сгенерируйте закрытый ключ CA и сертификат:
|
<br>Для MITM или mTLS требуется CA. Сгенерируйте закрытый ключ CA и сертификат:
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Генерация закрытого ключа CA
|
# Генерация закрытого ключа CA
|
||||||
openssl genrsa -out ca.key 4096
|
openssl genrsa -out ca.key 4096
|
||||||
|
|
||||||
# Генерация сертификата CA (действителен 10 лет)
|
# Генерация сертификата CA (действителен 10 лет)
|
||||||
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
||||||
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=My CA" \
|
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=My CA" \
|
||||||
-out ca.crt
|
-out ca.crt
|
||||||
@ -852,15 +850,15 @@ openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
|||||||
<b>Создание серверного сертификата для https:// прокси:</b>
|
<b>Создание серверного сертификата для https:// прокси:</b>
|
||||||
<br>Серверный сертификат должен иметь правильные альтернативные имена (SAN):
|
<br>Серверный сертификат должен иметь правильные альтернативные имена (SAN):
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Генерация закрытого ключа сервера
|
# Генерация закрытого ключа сервера
|
||||||
openssl genrsa -out server.key 2048
|
openssl genrsa -out server.key 2048
|
||||||
|
|
||||||
# Создание запроса на подпись сертификата (CSR)
|
# Создание запроса на подпись сертификата (CSR)
|
||||||
openssl req -new -key server.key \
|
openssl req -new -key server.key \
|
||||||
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=proxy.example.com" \
|
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=proxy.example.com" \
|
||||||
-out server.csr
|
-out server.csr
|
||||||
|
|
||||||
# Создание файла расширений для SAN
|
# Создание файла расширений для SAN
|
||||||
cat > server.ext << 'EOF'
|
cat > server.ext << 'EOF'
|
||||||
authorityKeyIdentifier=keyid,issuer
|
authorityKeyIdentifier=keyid,issuer
|
||||||
basicConstraints=CA:FALSE
|
basicConstraints=CA:FALSE
|
||||||
@ -874,7 +872,7 @@ DNS.2 = proxy
|
|||||||
IP.1 = 192.168.1.100
|
IP.1 = 192.168.1.100
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
# Подписание сертификата CA
|
# Подписание сертификата CA
|
||||||
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out server.crt -days 365 -sha256 \
|
-CAcreateserial -out server.crt -days 365 -sha256 \
|
||||||
-extfile server.ext
|
-extfile server.ext
|
||||||
@ -885,27 +883,27 @@ openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
|||||||
<p>
|
<p>
|
||||||
<b>Создание клиентского сертификата для mTLS:</b>
|
<b>Создание клиентского сертификата для mTLS:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Генерация закрытого ключа клиента
|
# Генерация закрытого ключа клиента
|
||||||
openssl genrsa -out client1.key 2048
|
openssl genrsa -out client1.key 2048
|
||||||
|
|
||||||
# Создание CSR
|
# Создание CSR
|
||||||
openssl req -new -key client1.key \
|
openssl req -new -key client1.key \
|
||||||
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=client1" \
|
-subj "/C=RU/ST=Region/L=City/O=MyOrg/CN=client1" \
|
||||||
-out client1.csr
|
-out client1.csr
|
||||||
|
|
||||||
# Создание файла расширений
|
# Создание файла расширений
|
||||||
cat > client.ext << 'EOF'
|
cat > client.ext << 'EOF'
|
||||||
basicConstraints=CA:FALSE
|
basicConstraints=CA:FALSE
|
||||||
keyUsage = digitalSignature, nonRepudiation, keyEncipherment
|
keyUsage = digitalSignature, nonRepudiation, keyEncipherment
|
||||||
extendedKeyUsage = clientAuth
|
extendedKeyUsage = clientAuth
|
||||||
EOF
|
EOF
|
||||||
|
|
||||||
# Подписание CA
|
# Подписание CA
|
||||||
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in client1.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out client1.crt -days 365 -sha256 \
|
-CAcreateserial -out client1.crt -days 365 -sha256 \
|
||||||
-extfile client.ext
|
-extfile client.ext
|
||||||
|
|
||||||
# Создание PKCS#12 для импорта в браузер
|
# Создание PKCS#12 для импорта в браузер
|
||||||
openssl pkcs12 -export -out client1.p12 \
|
openssl pkcs12 -export -out client1.p12 \
|
||||||
-inkey client1.key -in client1.crt -certfile ca.crt
|
-inkey client1.key -in client1.crt -certfile ca.crt
|
||||||
</pre>
|
</pre>
|
||||||
@ -915,15 +913,15 @@ openssl pkcs12 -export -out client1.p12 \
|
|||||||
<p>
|
<p>
|
||||||
<b>Скрипт быстрой настройки для разработки/тестирования:</b>
|
<b>Скрипт быстрой настройки для разработки/тестирования:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# Создаёт CA, серверный и клиентский сертификаты для тестирования SSLPlugin
|
# Создаёт CA, серверный и клиентский сертификаты для тестирования SSLPlugin
|
||||||
|
|
||||||
# CA
|
# CA
|
||||||
openssl genrsa -out ca.key 4096
|
openssl genrsa -out ca.key 4096
|
||||||
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
openssl req -x509 -new -nodes -key ca.key -sha256 -days 3650 \
|
||||||
-subj "/CN=3proxy CA" -out ca.crt
|
-subj "/CN=3proxy CA" -out ca.crt
|
||||||
|
|
||||||
# Сервер
|
# Сервер
|
||||||
openssl genrsa -out server.key 2048
|
openssl genrsa -out server.key 2048
|
||||||
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
|
openssl req -new -key server.key -subj "/CN=localhost" -out server.csr
|
||||||
cat > server.ext << 'EOF'
|
cat > server.ext << 'EOF'
|
||||||
@ -935,7 +933,7 @@ EOF
|
|||||||
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
openssl x509 -req -in server.csr -CA ca.crt -CAkey ca.key \
|
||||||
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
|
-CAcreateserial -out server.crt -days 365 -sha256 -extfile server.ext
|
||||||
|
|
||||||
# Клиент
|
# Клиент
|
||||||
openssl genrsa -out client.key 2048
|
openssl genrsa -out client.key 2048
|
||||||
openssl req -new -key client.key -subj "/CN=client" -out client.csr
|
openssl req -new -key client.key -subj "/CN=client" -out client.csr
|
||||||
cat > client.ext << 'EOF'
|
cat > client.ext << 'EOF'
|
||||||
@ -993,13 +991,13 @@ IP назначения, порты и т.д.), аналогичный кома
|
|||||||
<p>
|
<p>
|
||||||
<b>Примеры:</b>
|
<b>Примеры:</b>
|
||||||
</p><pre>
|
</p><pre>
|
||||||
# Блокировать запросы с определёнными ключевыми словами для некоторых пользователей
|
# Блокировать запросы с определёнными ключевыми словами для некоторых пользователей
|
||||||
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
|
pcre request deny "porn|sex" user1,user2,user3 192.168.0.0/16
|
||||||
|
|
||||||
# Блокировать ответы с определённым content-type
|
# Блокировать ответы с определённым content-type
|
||||||
pcre srvheader deny "Content-type: application"
|
pcre srvheader deny "Content-type: application"
|
||||||
|
|
||||||
# Замена содержимого в обоих направлениях (цензура)
|
# Замена содержимого в обоих направлениях (цензура)
|
||||||
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
|
pcre_rewrite clidata,srvdata dunno "porn|sex|pussy" "***" baduser
|
||||||
pcre_extend deny * 192.168.0.1/16
|
pcre_extend deny * 192.168.0.1/16
|
||||||
</pre>
|
</pre>
|
||||||
@ -1270,16 +1268,16 @@ pcre_extend deny * 192.168.0.1/16
|
|||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http 0.0.0.0 0
|
parent 1000 http 0.0.0.0 0
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
#перенаправить соединения по портам 80 и 8080-8088 в локальный
|
#перенаправить соединения по портам 80 и 8080-8088 в локальный
|
||||||
#http прокси. Вторая команда allow необходима, т.к. контроль доступа
|
#http прокси. Вторая команда allow необходима, т.к. контроль доступа
|
||||||
#осуществляется 2 раза - на уровне socks и на уровне HTTP прокси
|
#осуществляется 2 раза - на уровне socks и на уровне HTTP прокси
|
||||||
allow * * * 21,2121
|
allow * * * 21,2121
|
||||||
parent 1000 ftp 0.0.0.0 0
|
parent 1000 ftp 0.0.0.0 0
|
||||||
allow * * * 21,2121
|
allow * * * 21,2121
|
||||||
#перенаправить соединения по портам 21 и 2121 в локальный
|
#перенаправить соединения по портам 21 и 2121 в локальный
|
||||||
#ftp прокси
|
#ftp прокси
|
||||||
allow *
|
allow *
|
||||||
#пустить все соединения напрямую
|
#пустить все соединения напрямую
|
||||||
socks</pre>
|
socks</pre>
|
||||||
</p>
|
</p>
|
||||||
<li><a name="REDIINTER"><i>Q: Как взаимодействует с другими правилами в ACL?</i></a></li>
|
<li><a name="REDIINTER"><i>Q: Как взаимодействует с другими правилами в ACL?</i></a></li>
|
||||||
@ -1294,14 +1292,14 @@ pcre_extend deny * 192.168.0.1/16
|
|||||||
<pre>
|
<pre>
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http 0.0.0.0 0
|
parent 1000 http 0.0.0.0 0
|
||||||
#перенаправить во внутренний прокси
|
#перенаправить во внутренний прокси
|
||||||
allow * * $c:\3proxy\local.nets 80,8080-8088
|
allow * * $c:\3proxy\local.nets 80,8080-8088
|
||||||
#разрешить прямой web-доступ к сетям из local.nets
|
#разрешить прямой web-доступ к сетям из local.nets
|
||||||
allow * * * 80,8080-8088
|
allow * * * 80,8080-8088
|
||||||
parent 1000 http proxy.3proxy.ru 3128
|
parent 1000 http proxy.3proxy.ru 3128
|
||||||
#все остальные веб-запросы перенаправить на внешний прокси-сервер
|
#все остальные веб-запросы перенаправить на внешний прокси-сервер
|
||||||
allow *
|
allow *
|
||||||
#разрешить socks-запросы по другим портам</pre>
|
#разрешить socks-запросы по другим портам</pre>
|
||||||
</p>
|
</p>
|
||||||
</ul>
|
</ul>
|
||||||
<li><a name="ROUNDROBIN"><i>Как организовать балансировку между несоклькими каналами</i></a>
|
<li><a name="ROUNDROBIN"><i>Как организовать балансировку между несоклькими каналами</i></a>
|
||||||
|
|||||||
@ -192,9 +192,16 @@ or hostname, useful in case of dynamic DNS. <b><br>
|
|||||||
(<b>-ol</b>), connect back client (<b>-or</b>), connect back
|
(<b>-ol</b>), connect back client (<b>-or</b>), connect back
|
||||||
listening (<b>-oR</b>) sockets. Options like TCP_CORK,
|
listening (<b>-oR</b>) sockets. Options like TCP_CORK,
|
||||||
TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS,
|
TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS,
|
||||||
USE_TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT,
|
TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT,
|
||||||
SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE,
|
SO_EXCLUSIVEADDRUSE, SO_PORT_SCALABILITY,
|
||||||
SO_DONTROUTE may be supported depending on OS. <b><br>
|
SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be
|
||||||
|
supported depending on OS. SO_REUSEADDR and SO_REUSEPORT are
|
||||||
|
set on the listening socket by default on Unix. On Windows
|
||||||
|
SO_REUSEADDR is not set: it is not required to rebind a
|
||||||
|
listening port and it only lets another local process bind
|
||||||
|
the same address and port. Use SO_EXCLUSIVEADDRUSE (Windows)
|
||||||
|
on the listening socket (<b>-ol</b>) to prevent that.
|
||||||
|
<b><br>
|
||||||
-H</b> (for all services) Expect HAProxy PROXY protocol v1
|
-H</b> (for all services) Expect HAProxy PROXY protocol v1
|
||||||
header on incoming connection. This allows the proxy to
|
header on incoming connection. This allows the proxy to
|
||||||
receive real client IP address from HAProxy or other load
|
receive real client IP address from HAProxy or other load
|
||||||
@ -205,9 +212,16 @@ be sent before any protocol-specific data. <b><br>
|
|||||||
delay GRACE_DELAY milliseconds before polling if average
|
delay GRACE_DELAY milliseconds before polling if average
|
||||||
polling size is below GRACE_TRAFF bytes and GRACE_NUM read
|
polling size is below GRACE_TRAFF bytes and GRACE_NUM read
|
||||||
operations in a single direction are detected within 1
|
operations in a single direction are detected within 1
|
||||||
second. Useful to minimize polling <b>-s</b> <br>
|
second. Useful to minimize polling <b><br>
|
||||||
|
-s</b> <br>
|
||||||
(for admin) secure, allow only secure operations, currently
|
(for admin) secure, allow only secure operations, currently
|
||||||
only traffic counters view without ability to reset. <br>
|
only traffic counters view without ability to reset. <br>
|
||||||
|
(for TCP services, Linux) enable splice(). splice() is not
|
||||||
|
built by default and is disabled even when built, because
|
||||||
|
current Linux does not implement SPLICE_F_MOVE, so no real
|
||||||
|
zero-copy takes place and the read/write path is faster for
|
||||||
|
most traffic. Rebuild with -DWITHSPLICE to make -s
|
||||||
|
available, -s0 disables it explicitly. <br>
|
||||||
(for dnspr) simple, do not use resolver and 3proxy cache,
|
(for dnspr) simple, do not use resolver and 3proxy cache,
|
||||||
always use external DNS server. <br>
|
always use external DNS server. <br>
|
||||||
(for udppm) singlepacket, expect only one packet from both
|
(for udppm) singlepacket, expect only one packet from both
|
||||||
@ -762,8 +776,8 @@ service (with -s parameter). <b><br>
|
|||||||
ha</b> send HAProxy PROXY protocol v1 header to the next
|
ha</b> send HAProxy PROXY protocol v1 header to the next
|
||||||
parent proxy (or to the destination if <b>ha</b> is used
|
parent proxy (or to the destination if <b>ha</b> is used
|
||||||
alone). Place <b>ha</b> before the parent that should
|
alone). Place <b>ha</b> before the parent that should
|
||||||
receive the header; after the header is sent, negotiation
|
receive the header; after the header is sent, negotiation of
|
||||||
of that parent protocol continues (SOCKS, CONNECT, etc.).
|
that parent protocol continues (SOCKS, CONNECT, etc.).
|
||||||
Useful for passing client IP information to the parent
|
Useful for passing client IP information to the parent
|
||||||
proxy. Example: <br>
|
proxy. Example: <br>
|
||||||
parent 1000 ha 0.0.0.0 0 <br>
|
parent 1000 ha 0.0.0.0 0 <br>
|
||||||
@ -1048,7 +1062,17 @@ experience 3proxy crash on request processing, try to set
|
|||||||
some positive value. You may start with stacksize 65536 and
|
some positive value. You may start with stacksize 65536 and
|
||||||
then find the minimal value for the service to work. If you
|
then find the minimal value for the service to work. If you
|
||||||
experience memory shortage, you can try to experiment with
|
experience memory shortage, you can try to experiment with
|
||||||
negative values.</p>
|
negative values. <br>
|
||||||
|
With SQL logging (log &ODBC_string) the value is
|
||||||
|
automatically raised to 32768 if it is smaller, because ODBC
|
||||||
|
drivers require more stack. A <b>stacksize</b> command
|
||||||
|
placed after the <b>log</b> command overrides this. <br>
|
||||||
|
The base stack size the value is added to is 49152. On
|
||||||
|
FreeBSD, NetBSD, OpenBSD and DragonFly it is 65536, because
|
||||||
|
libc functions such as vfprintf() called by syslog() use
|
||||||
|
significantly more stack there. The result is never lowered
|
||||||
|
below PTHREAD_STACK_MIN, so a large negative value can not
|
||||||
|
disable the thread stack.</p>
|
||||||
|
|
||||||
<h2>PLUGINS
|
<h2>PLUGINS
|
||||||
<a name="PLUGINS"></a>
|
<a name="PLUGINS"></a>
|
||||||
|
|||||||
@ -178,7 +178,8 @@ connect to given remote HOST:port instead of listening local connection on -p or
|
|||||||
.br
|
.br
|
||||||
.B -oc\fIOPTIONS\fB, -os\fIOPTIONS\fB, -ol\fIOPTIONS\fB, -or\fIOPTIONS\fB, -oR\fIOPTIONS\fR
|
.B -oc\fIOPTIONS\fB, -os\fIOPTIONS\fB, -ol\fIOPTIONS\fB, -or\fIOPTIONS\fB, -oR\fIOPTIONS\fR
|
||||||
options for proxy-to-client (\fB-oc\fR), proxy-to-server (\fB-os\fR), proxy listening (\fB-ol\fR), connect back client (\fB-or\fR), connect back listening (\fB-oR\fR) sockets.
|
options for proxy-to-client (\fB-oc\fR), proxy-to-server (\fB-os\fR), proxy listening (\fB-ol\fR), connect back client (\fB-or\fR), connect back listening (\fB-oR\fR) sockets.
|
||||||
Options like TCP_CORK, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS, USE_TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be supported depending on OS.
|
Options like TCP_CORK, TCP_NODELAY, TCP_DEFER_ACCEPT, TCP_QUICKACK, TCP_TIMESTAMPS, TCP_FASTOPEN, SO_REUSEADDR, SO_REUSEPORT, SO_EXCLUSIVEADDRUSE, SO_PORT_SCALABILITY, SO_REUSE_UNICASTPORT, SO_KEEPALIVE, SO_DONTROUTE may be supported depending on OS.
|
||||||
|
SO_REUSEADDR and SO_REUSEPORT are set on the listening socket by default on Unix. On Windows SO_REUSEADDR is not set: it is not required to rebind a listening port and it only lets another local process bind the same address and port. Use SO_EXCLUSIVEADDRUSE (Windows) on the listening socket (\fB-ol\fR) to prevent that.
|
||||||
.br
|
.br
|
||||||
.B -H
|
.B -H
|
||||||
(for all services) Expect HAProxy PROXY protocol v1 header on incoming connection.
|
(for all services) Expect HAProxy PROXY protocol v1 header on incoming connection.
|
||||||
|
|||||||
@ -1,6 +1,6 @@
|
|||||||
[Unit]
|
[Unit]
|
||||||
Description=3proxy tiny proxy server
|
Description=3proxy tiny proxy server
|
||||||
Documentation=man:3proxy(1)
|
Documentation=man:3proxy(8) man:3proxy.cfg(5)
|
||||||
After=network.target
|
After=network.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
@ -13,8 +13,15 @@ ExecReload=/bin/kill -SIGUSR1 $MAINPID
|
|||||||
KillMode=process
|
KillMode=process
|
||||||
Restart=on-failure
|
Restart=on-failure
|
||||||
RestartSec=60s
|
RestartSec=60s
|
||||||
LimitNOFILE=65536
|
# 3proxy uses one thread and two descriptors per connection (four for ftppr),
|
||||||
LimitNPROC=32768
|
# so it reaches these limits much earlier than event driven servers. They are
|
||||||
|
# ceilings only: the actual number of connections is governed by 'maxconn' in
|
||||||
|
# the configuration file. TasksMax must be set explicitly, systemd's
|
||||||
|
# DefaultTasksMax (15% of kernel.threads-max, e.g. ~9000) otherwise caps the
|
||||||
|
# number of threads, and thus connections, regardless of LimitNPROC.
|
||||||
|
LimitNOFILE=1048576
|
||||||
|
LimitNPROC=infinity
|
||||||
|
TasksMax=infinity
|
||||||
RuntimeDirectory=3proxy
|
RuntimeDirectory=3proxy
|
||||||
RuntimeDirectoryMode=0755
|
RuntimeDirectoryMode=0755
|
||||||
|
|
||||||
|
|||||||
@ -24,9 +24,19 @@ if [ -f /etc/init.d/functions ]; then
|
|||||||
. /etc/init.d/functions
|
. /etc/init.d/functions
|
||||||
fi
|
fi
|
||||||
|
|
||||||
|
# SysV init does not apply limits.conf consistently: start-stop-daemon does not
|
||||||
|
# open a PAM session, so pam_limits is not involved and the daemon inherits the
|
||||||
|
# limits of init. 3proxy needs two descriptors per connection (four for ftppr),
|
||||||
|
# so raise them here. Adjust to match 'maxconn' in the configuration file.
|
||||||
|
set_limits() {
|
||||||
|
ulimit -n 65536 2>/dev/null || ulimit -n 4096 2>/dev/null || true
|
||||||
|
ulimit -u 32768 2>/dev/null || true
|
||||||
|
}
|
||||||
|
|
||||||
case "$1" in
|
case "$1" in
|
||||||
start)
|
start)
|
||||||
echo -n "Starting 3Proxy: "
|
echo -n "Starting 3Proxy: "
|
||||||
|
set_limits
|
||||||
|
|
||||||
if [ ! -d /var/run/3proxy ]; then
|
if [ ! -d /var/run/3proxy ]; then
|
||||||
mkdir -p /var/run/3proxy
|
mkdir -p /var/run/3proxy
|
||||||
|
|||||||
@ -190,7 +190,7 @@ struct extparam conf = {
|
|||||||
.paused = 0,
|
.paused = 0,
|
||||||
.archiverc = 0,
|
.archiverc = 0,
|
||||||
.demon = 0,
|
.demon = 0,
|
||||||
.maxchild = 500,
|
.maxchild = DEFAULT_MAXCHILD,
|
||||||
.backlog = 0,
|
.backlog = 0,
|
||||||
.needreload = 0,
|
.needreload = 0,
|
||||||
.timetoexit = 0,
|
.timetoexit = 0,
|
||||||
|
|||||||
@ -2025,7 +2025,7 @@ void freeconf(struct extparam *confp){
|
|||||||
#endif
|
#endif
|
||||||
*SAFAMILY(&confp->intsa) = AF_INET;
|
*SAFAMILY(&confp->intsa) = AF_INET;
|
||||||
*SAFAMILY(&confp->extsa) = AF_INET;
|
*SAFAMILY(&confp->extsa) = AF_INET;
|
||||||
confp->maxchild = 100;
|
confp->maxchild = DEFAULT_MAXCHILD;
|
||||||
confp->backlog = 0;
|
confp->backlog = 0;
|
||||||
resolvfunc = NULL;
|
resolvfunc = NULL;
|
||||||
numservers = 0;
|
numservers = 0;
|
||||||
|
|||||||
@ -34,6 +34,7 @@
|
|||||||
#define MAXUSERNAME 128
|
#define MAXUSERNAME 128
|
||||||
#define _PASSWORD_LEN 256
|
#define _PASSWORD_LEN 256
|
||||||
#define MAXNSERVERS 5
|
#define MAXNSERVERS 5
|
||||||
|
#define DEFAULT_MAXCHILD 500
|
||||||
|
|
||||||
#define TCPBUFSIZE 65536
|
#define TCPBUFSIZE 65536
|
||||||
#define SRVBUFSIZE (param->srv->bufsize?param->srv->bufsize:((param->service == S_UDPPM)?UDPBUFSIZE:TCPBUFSIZE))
|
#define SRVBUFSIZE (param->srv->bufsize?param->srv->bufsize:((param->service == S_UDPPM)?UDPBUFSIZE:TCPBUFSIZE))
|
||||||
|
|||||||
@ -149,6 +149,20 @@ void * threadfunc (void *p) {
|
|||||||
}
|
}
|
||||||
#undef param
|
#undef param
|
||||||
|
|
||||||
|
#ifdef _WIN32
|
||||||
|
/* Present since Windows 7 (SO_PORT_SCALABILITY) and Windows 10 / Server 2019
|
||||||
|
(SO_REUSE_UNICASTPORT), define them if the SDK is older so the options can
|
||||||
|
still be requested. setsockopt() just fails on a system which does not
|
||||||
|
support them and the failure is ignored.
|
||||||
|
*/
|
||||||
|
#ifndef SO_PORT_SCALABILITY
|
||||||
|
#define SO_PORT_SCALABILITY 0x3006
|
||||||
|
#endif
|
||||||
|
#ifndef SO_REUSE_UNICASTPORT
|
||||||
|
#define SO_REUSE_UNICASTPORT 0x3007
|
||||||
|
#endif
|
||||||
|
#endif
|
||||||
|
|
||||||
struct socketoptions sockopts[] = {
|
struct socketoptions sockopts[] = {
|
||||||
#ifdef TCP_NODELAY
|
#ifdef TCP_NODELAY
|
||||||
{TCP_NODELAY, "TCP_NODELAY"},
|
{TCP_NODELAY, "TCP_NODELAY"},
|
||||||
@ -171,6 +185,9 @@ struct socketoptions sockopts[] = {
|
|||||||
#ifdef SO_REUSEPORT
|
#ifdef SO_REUSEPORT
|
||||||
{SO_REUSEPORT, "SO_REUSEPORT"},
|
{SO_REUSEPORT, "SO_REUSEPORT"},
|
||||||
#endif
|
#endif
|
||||||
|
#ifdef SO_EXCLUSIVEADDRUSE
|
||||||
|
{SO_EXCLUSIVEADDRUSE, "SO_EXCLUSIVEADDRUSE"},
|
||||||
|
#endif
|
||||||
#ifdef SO_PORT_SCALABILITY
|
#ifdef SO_PORT_SCALABILITY
|
||||||
{SO_PORT_SCALABILITY, "SO_PORT_SCALABILITY"},
|
{SO_PORT_SCALABILITY, "SO_PORT_SCALABILITY"},
|
||||||
#endif
|
#endif
|
||||||
@ -794,8 +811,15 @@ int MODULEMAINFUNC (int argc, char** argv){
|
|||||||
if(*SAFAMILY(&srv.intsa) != AF_UNIX)
|
if(*SAFAMILY(&srv.intsa) != AF_UNIX)
|
||||||
#endif
|
#endif
|
||||||
{
|
{
|
||||||
|
/* SO_REUSEADDR is not set on Windows: it is not needed to rebind a listening
|
||||||
|
port there, and it only allows another local process to bind the same
|
||||||
|
address and port, with undefined behaviour as to which socket receives the
|
||||||
|
connections. Use -olSO_EXCLUSIVEADDRUSE to prevent that instead.
|
||||||
|
*/
|
||||||
|
#ifndef _WIN32
|
||||||
opt = 1;
|
opt = 1;
|
||||||
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
|
if(srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int)))perror("setsockopt()");
|
||||||
|
#endif
|
||||||
#ifdef SO_REUSEPORT
|
#ifdef SO_REUSEPORT
|
||||||
opt = 1;
|
opt = 1;
|
||||||
srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
|
srv.so._setsockopt(srv.so.state, sock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
|
||||||
@ -911,8 +935,10 @@ int MODULEMAINFUNC (int argc, char** argv){
|
|||||||
freesrvstrings(&srv, cbc_string, cbl_string);
|
freesrvstrings(&srv, cbc_string, cbl_string);
|
||||||
return -6;
|
return -6;
|
||||||
}
|
}
|
||||||
|
#ifndef _WIN32
|
||||||
opt = 1;
|
opt = 1;
|
||||||
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int));
|
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEADDR, (char *)&opt, sizeof(int));
|
||||||
|
#endif
|
||||||
#ifdef SO_REUSEPORT
|
#ifdef SO_REUSEPORT
|
||||||
opt = 1;
|
opt = 1;
|
||||||
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
|
srv.so._setsockopt(srv.so.state, srv.cbsock, SOL_SOCKET, SO_REUSEPORT, (char *)&opt, sizeof(int));
|
||||||
|
|||||||
Loading…
Reference in New Issue
Block a user