Differences
This shows you the differences between two versions of the page.
Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
en:dpi:dpi_options:opt_filtration:filtration_settings [2020/02/05 17:29] – ↷ Page moved from en:dpi:dpi_options:base_functionality:opt_filtration:filtration_settings to en:dpi:dpi_options:opt_filtration:filtration_settings lexx26 | en:dpi:dpi_options:opt_filtration:filtration_settings [2024/09/30 11:15] (current) – atereschenko | ||
---|---|---|---|
Line 1: | Line 1: | ||
- | ====== | + | ====== Configuration ====== |
+ | {{indexmenu_n> | ||
+ | <note warning> | ||
+ | |||
+ | You can configure the option or turn it off by configuration file **/ | ||
+ | |||
+ | ===== Filtering service configuration ===== | ||
+ | |||
+ | < | ||
+ | (0 - disables)</ | ||
+ | |||
+ | The lists received from clouds are placed to the directory **/ | ||
+ | |||
+ | **blcache.bin** - URL dictionary to block HTTP\\ | ||
+ | **blcachecn.bin** - names' dictionary to block HTTPS by certificates\\ | ||
+ | **blcacheip.bin** - IP addresses dictionary to block HTTPS by IP\\ | ||
+ | **blcachesni.bin** - dictionary to block HTTPS by SNI | ||
+ | |||
+ | <note important> | ||
+ | |||
+ | This behaviour can be modified. The browser can be redirected to a special operator' | ||
+ | |||
+ | Page setup for redirect: | ||
+ | < | ||
+ | |||
+ | The black list update period can be configured. It is 60 minutes by default: | ||
+ | |||
+ | < | ||
+ | <note important> | ||
+ | |||
+ | The service has to load modified parameters after configuration changes. One can do it by the following instructions (([[en: | ||
+ | |||
+ | To update modified " | ||
+ | < | ||
+ | |||
+ | To update all parameters by the service' | ||
+ | < | ||
+ | :!: The short break (less than 1 second) in service is caused by restart, if the Bypass is not supported. | ||
+ | |||
+ | < | ||
+ | The " | ||
+ | You can find more details here: [[en: | ||
+ | </ | ||
+ | |||
+ | ===== Custom lists configuration ===== | ||
+ | |||
+ | <note important> | ||
+ | |||
+ | The operator can attach his own black list. | ||
+ | |||
+ | < | ||
+ | custom_url_black_list=http:// | ||
+ | |||
+ | #Names dictionary for blocking HTTPS by certificate | ||
+ | custom_cn_black_list=http:// | ||
+ | |||
+ | #IP addresses dictionary for blocking HTTPS by IP | ||
+ | custom_ip_black_list=http:// | ||
+ | |||
+ | #Hosts names dictionary for blocking HTTPS by SNI (Server Name Indication) | ||
+ | custom_sni_black_list=http:// | ||
+ | </ | ||
+ | |||
+ | URL field can be used to specify ftp protocol and authentication parameters. | ||
+ | |||
+ | The lists downloaded from the specified URL are stored in / | ||
+ | |||
+ | **blcustom.bin** - the URL dictionary to block HTTP\\ | ||
+ | **blcustomcn.bin** - the name's dictionary to block HTTPS by certificate\\ | ||
+ | **blcustomip.bin** - the IP addresses' | ||
+ | **blcustomsni.bin** - the IP addresses' | ||
+ | |||
+ | |||
+ | ===== Additional Information ===== | ||
+ | '#' | ||
+ | |||
+ | In case the service is used to filter by black list only, we advise to switch off the analysis of protocols rather than HTTP. It helps increase productivity and reduces CPU load: | ||
+ | < | ||
+ | |||
+ | If the black lists are created on the same computer that runs DPI: you can just put them to **/ | ||
+ | <note warning> | ||
+ | |||
+ | ===== Switching off the custom lists ===== | ||
+ | |||
+ | To switch off additional (operator' | ||
+ | |||
+ | Comment out or remove the parameters from configuration file **/ | ||
+ | < | ||
+ | </ | ||
+ | |||
+ | To remove local lists: | ||
+ | < | ||
+ | rm / | ||
+ | rm / | ||
+ | rm / | ||
+ | rm / | ||
+ | </ | ||
+ | |||
+ | Here's the translation of the blocking settings: | ||
+ | |||
+ | =====Blocking Settings===== | ||
+ | Add the parameter '' | ||
+ | |||
+ | Values: | ||
+ | * 1 — block regardless of the presence of SNI | ||
+ | * 2 — block all ports on the address | ||
+ | * 4 — block all of IPv6 (when the [[en: | ||
+ | * 8 — do not generate RST packets for blocking and redirection for `inet–> |