服务器: 243 配置
http_port 80 transparent icp_port 3130 cache_peer 192.168.1.241 sibling 80 3130 proxy-only dns_nameservers 202.103.224.68 202.103.225.68 visible_hostname beihai365_nat cache_dir ufs /var/spool/squid 2048 16 256 cache_mem 1000 MB cache_mgr [email protected] redirect_children 30 cache_access_log /var/log/squid/access.log cache_log /var/log/squid/cache.log cache_store_log /var/log/squid/store.log #cache_peer www.beihai365.com parent 80 0 no-query originserver name=edns #cache_peer 222.216.28.226 parent 80 0 no-query originserver name=img #cache_peer_domain edns www.beihai365.com #cache_peer_domain edns .beihai365.com acl webserver dstdomain .beihai365.com acl localhost src 127.0.0.1/255.255.255.255 acl icprule src 192.168.1.241 icp_access allow icprule http_access allow localhost http_access allow webserver
服务器: 241 配置
http_port 80 transparent icp_port 3130 cache_peer 192.168.1.243 sibling 80 3130 proxy-only dns_nameservers 202.103.224.68 202.103.225.68 visible_hostname beihai365 cache_dir ufs /var/spool/squid 2048 16 256 cache_mem 1000 MB cache_mgr [email protected] redirect_children 30 cache_access_log /var/log/squid/access.log cache_log /var/log/squid/cache.log cache_store_log /var/log/squid/store.log #cache_peer www.beihai365.com parent 80 0 no-query originserver name=edns #cache_peer 222.216.28.226 parent 80 0 no-query originserver name=img #cache_peer_domain edns www.beihai365.com #cache_peer_domain edns .beihai365.com acl webserver dstdomain .beihai365.com acl localhost src 127.0.0.1/255.255.255.255 acl icprule src 192.168.1.243 icp_access allow icprule http_access allow localhost http_access allow webserver
DNS 配置:
$TTL 600 @ IN SOA ns.365.com huithe ( 33 60 14400 720000 86400 ) @ IN NS ns.beihai365.com. @ IN NS ns2.beihai365.com. ns IN A 192.168.1.243 ns2 IN A 192.168.1.241 www IN A 192.168.1.243 img IN CNAME www ad IN A 222.216.28.226 plus IN A 116.252.185.22 devsvn IN A 202.103.215.203 db IN A 222.216.28.169 job IN A 192.168.1.241 * IN A 222.216.28.180
使用 transparent 模式 是因为我想偷懒,不想在 dns 这边 过多的对 不同的二级域名绑定到不同的主机上~~ 而是把 所有的请求工作指定到 squid 由 squid 的 透明代理功能全部帮我去请求了。。。偷懒做法 哈哈
使用 icp 集群 要注意的是:
acl icprule src 192.168.1.243
icp_access allow icprule
这个规则要指定 否则日志就可以看到 UDP 拒绝的。
看下 sibling 命中的 日志 服务器的日志。。
1300261577.291 9 192.168.1.238 TCP_MISS/200 53884 GET http://img.beihai365.com/bbs/forumid_60/20100921_aa5d9a78001b2ca53b839qa1soo1Kwb6.jpg - SIBLING_HIT/192.168.1.241 imag e/jpeg 1300261577.296 12 192.168.1.238 TCP_MISS/200 41192 GET http://img.beihai365.com/bbs/forumid_60/20100921_c3c1f0c426c6ce8924ccrA3Zr5480p57.jpg - SIBLING_HIT/192.168.1.241 imag e/jpeg 1300261577.301 5 192.168.1.238 TCP_MISS/200 25248 GET http://img.beihai365.com/bbs/forumid_60/20100921_533af868a2ef45127f79qxUUYbjByfhl.jpg - SIBLING_HIT/192.168.1.241 imag e/jpeg