• Squid/Squidguard and commercial Antivirus

    4
    0 Votes
    4 Posts
    4k Views
    KOMK

    you wil definitely find answers to commercial antivirus products to run on FreeBSD/UNIX/Linux.

    Huh, I had no idea.  You learn something new every day.

    No it's not. If you're using a high end firewall with enough power, it will run.

    I would rather not have some PC-class desktop as my firewall just so I can scan for viruses and malware that I don't have.  Most of my clients are Android, Apple and Linux.  The Windows boxes have their local AV clients.  I tried ClamAV a few years ago and it was dreadfully slow.  I agree with you when it generally comes to layered security, but AV on the firewall is too much of a performance tradeoff for me.

  • Wpad problem

    6
    0 Votes
    6 Posts
    1k Views
    C

    As I like to explain, from my own viewpoint, WPAD is the very last step in term of configuration.

    you have to ensure that your proxy works when explicitly configured on your browser once this works, you deploy proxy.pac on some web server and ensure it works when manually configured browser side once and only once this works too, you can push WPAD using DNS, DHCP or whatever supported method.

    Following this approach, you may discover that WPAD step is the easiest one and most of the time, it works  ;)

  • Block HTTPS site without WPAD or installing a CA certificate.

    3
    0 Votes
    3 Posts
    1k Views
    C

    @dilu1:

    In Sophos i use an option to block websites (facebook, twitter), this works for http and https.
    https is configured as "URL filtering only", this has some disadvantages like no content or virus scanning on https sites but that doesn’t matter to much for this case,
    I am only interested in blocking websites which works.

    I'm very prone to learn how this would work  8)

  • [SOLVED] haproxy - how to avoid empty response with slow backend?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    D

    Thanks, that worked.

  • Squid and SquidGuard keeps stopping

    4
    0 Votes
    4 Posts
    1k Views
    KOMK

    Clearing the cache manually might have done the same thing for you.

  • Migrate Linux Squid + SquidGuard to pfSense box

    2
    0 Votes
    2 Posts
    538 Views
    KOMK

    squidGuard has one master config file that holds everything, so your Linux config should be pretty easy to read and reproduce in pfSense.  Linux config is probably in /etc/squidguard/squidguard.conf.

  • Squid makes false certificates on some pages

    10
    0 Votes
    10 Posts
    1k Views
    KOMK

    I don't know for sure, but I do know that transparent mode is more trouble than its worth.

  • Squid and squidGuard - monitor websites and block content

    17
    0 Votes
    17 Posts
    8k Views
    A

    Auto detect is enabled, but if I block those ports do I block them on the subinterface?
    Because when I do nothing works I can't browse only ping…

    EDIT: I got it working! It's logging everything - I'm not sure yet why but I'll check tomorrow and write back! Thanks again

  • Transparent proxy not working (CLOSED:SYN_SENT)

    1
    0 Votes
    1 Posts
    842 Views
    No one has replied
  • Cài đặt squid

    1
    0 Votes
    1 Posts
    541 Views
    No one has replied
  • Help with Skype and Squid Proxy

    2
    0 Votes
    2 Posts
    928 Views
    R

    Hi,
    look here
    https://forum.pfsense.org/index.php?topic=108370.msg617570#msg617570

  • Sqiud Configuration

    3
    0 Votes
    3 Posts
    884 Views
    H

    Hello,

    thanks for reply.

    Whitelist = I dont know where this option is
    Blacklist = I dont know where this option is
    blk_BL_adv: Deny = thrue
    default access all: allow = thrue
    Do not allow IP-addresses in URL: unticked = false –> Why not ticked?
    Proxy denied error: blank (you can insert a warning string here) = false –> we have a extern url
    Redirect mode: int error page = false –> we have a extern url
    redirect info: blank = false –> we have a extern url
    Use safeguard engine: unticked = false –> why?
    Rewrite: none = thrue
    Log: ticked = thrue

    squid-conf-1.PNG
    squid-conf-1.PNG_thumb
    squid-conf-2.PNG
    squid-conf-2.PNG_thumb
    squid-conf-3.PNG
    squid-conf-3.PNG_thumb

  • PfSense squidGuard Package Installation Issues

    3
    0 Votes
    3 Posts
    1k Views
    R

    @u3c307:

    squidguard_configurator.inc must contains after require section [ln 53..]:

    /* Allow additional execution time 0 = no limit. */
    ini_set('max_execution_time', '3600');
    ini_set('max_input_time', '3600');

    ini_set('memory_limit', '50M');

    Locate file under /usr/local/pkg

    Thank you for the reply and detailed direction on what to review for the future! Unfortunately, I do not have the ability to share whether or not these directions would have solved the problem because I rebuilt the router after being unable to find an answer online.

    Since I had a VERY brand new installation, I didn't lose much except for time in the rebuild. Even though I had to re-install the OS and get everything re-installed and configured, I'm happy for the experience and thus far the community cooperation and support.

    Thanks again - and I'll keep this saved in the event this happens again as I continue to refine my pfSense configuration.

    Additionally, for those that are curious - these are the default settings I found in the configuration file. Maybe I would need to bump up the amount to "200M" if this error comes up again?

    Allow additional execution time 0 = no limit –----------------------------------------------------------------------

    ini_set('max_execution_time', '3600');
    ini_set('max_input_time',    '3600');
    ini_set('memory_limit',      '100M');

  • Squid Shutting Down and Wont Restart

    17
    0 Votes
    17 Posts
    3k Views
    U

    Have you made sure that the pid for squid is down when your cron job run? Possible that the pid is still up that is why it is saying squid already exist.

  • [Solved] How to change the cipher for Squid reverse proxy?

    3
    0 Votes
    3 Posts
    2k Views
    C

    Please see: https://forum.pfsense.org/index.php?topic=119934.0

  • TCP_MISS/200

    4
    0 Votes
    4 Posts
    5k Views
    T

    Ok it means i need to get this SquidVideoBooster plug-in, for caching youtube videos and extras. it will cost $1000 per year for this. Not 100% open source smellin ios/mac  ;)

  • 0 Votes
    7 Posts
    19k Views
    danilosv.03D

    Hello guys,
    I am Brazilian and I am with this same problem, I am wanting to block this automatic download of Windows Update, and here I have some O.S Win7 and Win10, and wanted to make this block via squid. Could anyone help? Thanks for help.

  • Shattered Yahoo Mail contents with squid.

    2
    0 Votes
    2 Posts
    699 Views
    S

    There seems to be a problem with Yahoo sites - see http://lists.squid-cache.org/pipermail/squid-users/2016-June/011220.html (it is about flickr but the issues on all sites of yahoo)

  • How to console installation of squid proxy, clamav, icap

    1
    0 Votes
    1 Posts
    569 Views
    No one has replied
  • Squid err_empty_response

    3
    0 Votes
    3 Posts
    2k Views
    SoloamS

    Problem seams to be solved! I'll test with SquidGuard, but so far so good!

    Thank You KOM

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.