* On 05/03/06 09:36 +0100, Henrik Nordstrom wrote: > sön 2006-03-05 klockan 11:07 +0300 skrev Odhiambo WASHINGTON: > > > acl walled_class src 172.16.0.0/24 > > acl AllowedSites dstdomain "/usr/local/etc/squid/allowed-sites" > > http_access allow walled_class AllowedSites > > http_access deny walled_class !AllowedSites > > > > > > Is this any closer to what I'd like to achieve? > > Should work. > > But you may want to simplify the last line to just > > http_access deny walled_class > > as this makes it more sane to extend/modify their "allow" rules later on > as additional criterias come up.. for example you may want to add a > referer_regex to allow downloads of banners etc linked from those > sites.. Thank you so much for all the advise. This appears to work in my test env. The main job of integrating it within the walled-garden concept itself now remains, which shouldn't be difficult. -Wash http://www.netmeister.org/news/learn2quote.html DISCLAIMER: See http://www.wananchi.com/bms/terms.php -- +======================================================================+ |\ _,,,---,,_ | Odhiambo Washington <wash@xxxxxxxxxxxx> Zzz /,`.-'`' -. ;-;;,_ | Wananchi Online Ltd. www.wananchi.com |,4- ) )-,_. ,\ ( `'-'| Tel: +254 20 313985-9 +254 20 313922 '---''(_/--' `-'\_) | GSM: +254 722 743223 +254 733 744121 +======================================================================+ We are all in the gutter, but some of us are looking at the stars. -- Oscar Wilde