#auth_param digest program <uncomment and complete this line>
#auth_param digest children 5
#auth_param digest realm Squid proxy-caching web server
#auth_param digest nonce_garbage_interval 5 minutes
#auth_param digest nonce_max_duration 30 minutes
#auth_param digest nonce_max_count 50
#auth_param ntlm program /usr/local/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp
auth_param ntlm program /usr/local/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp --require-membership-of=DOMAIN+internet
auth_param ntlm children 5
auth_param ntlm max_challenge_reuses 0
auth_param ntlm max_challenge_lifetime 2 minutes
#auth_param ntlm use_ntlm_negotiate off
#auth_param basic program /usr/local/bin/ntlm_auth --helper-protocol=squid-2.5-basic
auth_param basic program /usr/local/bin/ntlm_auth --helper-protocol=squid-2.5-ntlmssp --require-membership-of=DOMAIN+internet
auth_param basic children 5
auth_param basic realm Squid proxy-caching web server
auth_param basic credentialsttl 2 hours
auth_param basic casesensitive off
####################
acl NTLMauth proxy_auth REQUIRED
acl NTLMauth_url url_regex -i "/usr/local/etc/squid/default-urls"
external_acl_type Domain_Group ttl=60 concurrency=5 %LOGIN /usr/local/libexec/squid/wbinfo_group.pl
acl Obizi external Domain_Group obizi
acl Obizi_url url_regex -i "/usr/local/etc/squid/obizi-urls"
acl Full external Domain_Group full
acl Buh-nalog external Domain_Group buh-nalog
acl Buh-nalog_url url_regex -i "/usr/local/etc/squid/buh-nalog-urls"
acl Deny_url url_regex -i "/usr/local/etc/squid/deny-urls"
acl all src 192.7.7.0/255.255.255.0
acl manager proto cache_object
acl localhost src 127.0.0.1/255.255.255.255
acl to_localhost dst 127.0.0.0/8
acl SSL_ports port 443 563
acl Safe_ports port 80 # http
acl Safe_ports port 20 21 # ftp
acl Safe_ports port 443 563 # https, snews
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1024-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
http_access allow NTLMauth NTLMauth_url
http_access deny NTLMauth_url
http_access deny Full Deny_url
http_access deny Deny_url
http_access allow Full
http_access allow Obizi Obizi_url
http_access deny Obizi_url
http_access allow Buh-nalog Buh-nalog_url
http_access deny Buh-nalog_url
http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
#http_access allow full_access
http_access deny all
icp_access allow all
##########Buh_nalog_url###########
kontur-extern.ru
217.107.217.246
217.107.217.240
###################################
##########default-urls#############
ixbt.com
###################################
##########deny-urls################
mail.rambler.ru
hotbox.ru
front.ru
hotbox.com
krovatka.net
land.ru
.mail15.com
.mail333.com
pisem.net
pochtamt.ru
pop3.ru
rbcmail.ru
smtp.ru
####################################