access
ip/proxy/access
Type: Directory
Rules that allow, deny, redirect or change the requests of proxy clients, HTTP and HTTPS (CONNECT) requests alike. The proxy checks the rules from top to bottom, and the first matching rule decides. A request that matches no rule is allowed. A rule without matchers matches every request. Prefix a matcher value with ! to negate it, for example src-address=!192.168.88.0/24. For examples, see Web Proxy.
| Flag | Name | Description |
|---|---|---|
| X | disabled | disabled. The rule is not used. New rules are created enabled. |
| Argument | Type | Description |
|---|---|---|
| src-address | super { ! , range: alt { ip4: ipRange , ip6: ip6Prefix } } | Address of the client: an IPv4 address, range or prefix, or an IPv6 prefix. |
| dst-address | super { ! , range: alt { ip4: ipRange , ip6: ip6Prefix } } | Address of the server the proxy connects to, which is the resolved address of the host name in the request. Same format as src-address. |
| dst-port | super { ! , ports: multi { ports: range [ .. 65535] } } | Port of the server, for HTTPS requests the port of the CONNECT tunnel. A port, a range or a comma-separated list, for example dst-port=!443. |
| local-port | super { ! , port: num [0 .. 65535] } | Port of the proxy the request arrived on. Use it when port in /ip/proxy lists several ports. |
| dst-host | super { ! , host: string } | Host name of the request, for HTTPS requests the host of the
|
| path | super { ! , path: string } | Path of the requested URL, including the query string, for example
|
| method | super { ! , method: enum (GET | HEAD | POST | PUT | CONNECT | OPTIONS | DELETE | TRACE) } | HTTP method of the request: GET, HEAD, POST, PUT, CONNECT, OPTIONS, DELETE or TRACE. Clients of the proxy request HTTPS pages with CONNECT. The methods are defined in RFC 9110. |
| action | enum (allow | deny | redirect | url-append) | What the proxy does with a matching request.
|
| action-data | string | redirect URL/append URL. With action=redirect, the URL the client is sent to, for example https://intranet.example.com/blocked.html. With action=url-append, the text added to the end of the requested URL, as it is, without a separator. |
| Read-only Argument | Type | Description |
|---|---|---|
| hits | num | Number of requests the rule matched. Reset it with reset-counters or reset-counters-all. |