With this setup -- acl ur_foo url_regex www.foobar.org http_access allow ur_foo http_access deny all -- my users can bypass the access entries requesting www.notallowed.com/?www.foobar.org the clear solution for me is to force the string www.foobar.org to be at the beggining of the request acl ur_foo url_regex ^www.foobar.org but that way I can't access www.foobar.org. Do exists a workaround for this? Regards, maykel