• Home Network, just looking to test, coming from Untangle

    2
    0 Votes
    2 Posts
    527 Views
    D

    No, not ATM. https://redmine.pfsense.org/issues/1620

  • Why is a certificate needed for squid reverse https?

    4
    0 Votes
    4 Posts
    2k Views
    K

    A slightly longer answer is that any SSL/TLS endpoint that is going to decrypt and authenticate incoming HTTPS connections MUST have a certificate because it's the cryptographic identification and authentication of a peer. If an SSL/TLS server you're connecting to claims to be 'www.example.tld' it must present a certificate (preferably signed by a trusted third party so it verifies correctly) with a CN (common name) 'www.example.tld', otherwise the SSL/TLS handshake will be aborted if the server can not present such certificate.

  • Group acl on squidguard not working please help

    2
    0 Votes
    2 Posts
    1k Views
    G

    try this

    ldapusersearch ldap://dc1.domain.com.uy:3268/dc=domain,dc=com,dc=uy?sAMAccountName?sub?(&(sAMAccountName=%s)(memberOf=CN=Internet,OU=Grupos,dc=domain,dc=com,dc=uy))

    "Internet" is my AD group located at "OU=Grupos"

  • SquidGuard - can't download/extract blacklist

    3
    0 Votes
    3 Posts
    4k Views
    D

    All I can suggest here is starting a bounty for a complete package rewrite. Apparently noone will touch the current buggy code, since it's completely unreadable mess. Unfixable.

    Alternatively, get some blocklists in Squid's ACL format and use those.

  • "Bypass Proxy for These Source IPs" Bug

    3
    0 Votes
    3 Posts
    961 Views
    D

    (And, FWIW, about 99% sure this has completely nothing to do with "Bypass Proxy for These Source IPs" or any other Squid configuration. If you cleared whatever other fields, or simple re-saved the Squid config without doing any changes whatsoever, it'd have the same effect (restarting services, reloading firewall, working again until it breaks for god knows what reason…)

  • Squid/transparent proxy improperly intercepting SSL?

    3
    0 Votes
    3 Posts
    2k Views
    T

    @doktornotor:

    It is intercepting just fine. Recently discussed in the proper forum. If things break, use the manual config, or don't MITM.

    apologies if I wasn't clear in my post - I am not implementing MITM and have never enabled it.  It would appear that while all other SSL traffic bypasses the proxy just fine (as intended), this one API call with the :443 appended may indeed be SSL but is attempting to go through the proxy.

  • Modify SSL User Agent Header

    6
    0 Votes
    6 Posts
    2k Views
    ?

    that's correct.

  • How to remove Request denied by pfsense proxy

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ

    That block of text is configurable in squidGuard's options.

  • How Personalize reports on lightsquid

    1
    0 Votes
    1 Posts
    514 Views
    No one has replied
  • How do I change Blacklists settings in squid + squidguard?

    6
    0 Votes
    6 Posts
    4k Views
    S

    @doktornotor:

    @sprinteroz:

    I found the setting in pfblockerBg that you where talking about but i could not work out what you meant by Force Reload all.

    Click the Update tab.

    Ok thanks done… Just a quick question before i install squidguard again how do i change the lists in squadguard once its installed encase I would like to add or remover rules on the lists.

  • Besides lightsquid, any other better reporting tool for pfsense

    2
    0 Votes
    2 Posts
    894 Views
    D

    Not ATM, no. Offload it to a logserver and do whatever you want with that, perhaps. (ELK, …)

  • LightSquid, Captive Portal Codes as User

    1
    0 Votes
    1 Posts
    548 Views
    No one has replied
  • Help with HAProxy URL rewrite

    2
    0 Votes
    2 Posts
    980 Views
    N

    would you mind telling me the model of Sophos UTM that you have before?

  • FTP Client Proxy Restrictions

    1
    0 Votes
    1 Posts
    547 Views
    No one has replied
  • Mixed content warning when using SSL offloading in HAProxy

    5
    0 Votes
    5 Posts
    2k Views
    W

    Inspecting the blocked content it all seems local to me, can't see any other domain names in it than just the domain name the site is running.

  • LightSquid service not running

    5
    0 Votes
    5 Posts
    2k Views
    T

    Awesome. I can confirm that the lightsquid_web is now running after the update.

  • HAProxy randomly "failing", need to restart service to fix

    3
    0 Votes
    3 Posts
    612 Views
    P

    I would move webgui to a non-standard port like 1443 or something, and disable the webgui-redirect.. Then at least you wont unintentionally end up on the webgui when trying to visit the wan-ip.

  • Filtering HTTPS

    5
    0 Votes
    5 Posts
    1k Views
    D

    Content filtering == you can see the real content. Terminology mixup I guess. You cannot filter the content you do not see.

    http://wiki.squid-cache.org/Features/SslPeekAndSplice

  • MITM error with C-ICAP

    2
    0 Votes
    2 Posts
    586 Views
    D

    Sorry, there is no support for packages on pfSense on 2.2.x. Also, the Squid version plus related packages there are extremely outdated and not really offering any of the recent features.

  • Lightsquid not working on New update

    11
    0 Votes
    11 Posts
    4k Views
    D

    Well, at least things work now. (I certainly won't be able to debug any SIGSEGV issues there, my experience is that it was a HW issue ~95% of time. If not RAM, then CPU overheating, or bad PSU with unstable voltage.) If it's a bug with Squid, you'd need to move this to Squid mailing list or generally upstream, nothing pfSene specific there.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.