πŸ”— Source Repository: https://github.com/itexpatchina/Squid_Proxy_Setup_Tutorial

πŸ› οΈ 1st Step: Install Squid Proxy

Here’s how to install Squid on your system, depending on your Linux distribution:


🐧 For Debian/Ubuntu

sudo apt update
sudo apt install squid
  • Configuration file: /etc/squid/squid.conf
  • Service control:
    sudo systemctl start squid
    sudo systemctl enable squid
    sudo systemctl status squid
    

πŸ”΄ For CentOS/RHEL/Fedora

sudo yum install squid

Or on newer Fedora/RHEL:

sudo dnf install squid
  • Configuration file: /etc/squid/squid.conf
  • Service control:
    sudo systemctl start squid
    sudo systemctl enable squid
    sudo systemctl status squid
    

πŸ§ͺ For Arch Linux

sudo pacman -S squid
  • Configuration file: /etc/squid/squid.conf
  • Service control:
    sudo systemctl start squid
    sudo systemctl enable squid
    sudo systemctl status squid
    

πŸ” Verify Installation

After installation, check the version and test the config:

squid -v
squid -k parse

πŸ› οΈ 2nd Step: Install htpasswd

On Debian/Ubuntu:

sudo apt update
sudo apt install apache2-utils

On CentOS/RHEL/Fedora:

sudo yum install httpd-tools

On Arch Linux:

sudo pacman -S apache

βœ… Once Installed

You can create or update your password file like this:

htpasswd -c /etc/squid/htpasswd your_username
  • -c creates a new file (omit it when adding more users).
  • You’ll be prompted to enter a password.

You can add a 2nd user by omitting the ’-cβ€˜ option

htpasswd /etc/squid/htpasswd your_2nd_username
  • You’ll be prompted to enter a password again.

πŸ› οΈ 3rd Step: Prepare local.conf file in /etc/squid/conf.d/ folder


βœ… Content local.conf for Squid

# Listen on port 8080
http_port 8080

# Cache configuration
cache_dir ufs /var/spool/squid 100 16 256

# Authentication setup
auth_param basic program /usr/lib/squid/basic_ncsa_auth /etc/squid/htpasswd
auth_param basic realm "LAN Proxy Access"
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off

# ACL definitions
acl localnet src 192.168.0.0/24         # Internal LAN
acl all_ips src all                     # All IPs
acl authenticated proxy_auth REQUIRED   # Authenticated users

# Access rules
http_access allow localnet              # Allow LAN without auth
http_access allow authenticated         # Allow authenticated users
http_access deny all                    # Deny everything else

βœ… Verify Auentication is Functioning

You can use below command

/usr/lib/squid/basic_ncsa_auth /etc/squid/htpasswd

And then you type in the “username password” as input to verify successful autentication when it returns ‘OK’.

πŸ› οΈ 4th Step: Reboot Squid Service and Make Sure that Port 3128 and 8080 are Exposed

To reboot the Squid service and ensure that ports 3128 and 8080 are exposed and listening properly, follow these steps:


πŸ” 1. Reboot the Squid Service

Use systemctl to restart Squid:

sudo systemctl restart squid

Then verify its status:

sudo systemctl status squid

You should see active (running) in green.


πŸ”“ 2. Open Firewall Ports

If you use ufw (Ubuntu):

sudo ufw allow 3128/tcp
sudo ufw allow 8080/tcp

For firewalld (CentOS/Fedora):

sudo firewall-cmd --add-port=3128/tcp --permanent
sudo firewall-cmd --add-port=8080/tcp --permanent
sudo firewall-cmd --reload