• Squid stripping domain from URL with port forwarding

    11
    0 Votes
    11 Posts
    7k Views
    G

    I had this same issue with squid 2.7.9.  This worked for me:

    Set squid proxy to listen on port 3129 (or any port you choose, the GUI wouldn't allow me to leave it blank)
    Add custom option: http_port 3128 transparent

    Port forward on LAN:
    Traffic TCP Src * Srcport * Dest * Destport HTTP(80) TargetIP pfsensebox IP Targetport 3128

    My guess is that on the GUI without the transparent box checked, squid was not operating transparently on port 3128 until specifically defined to do so.

    Unfortunately my ultimate goal was to use this rule to apply limiters to the traffic but apparently there is a bug with limiters and squid in transparent mode that I can't seem to get around!

  • Squid Reverse Proxy

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid Monitoring and Lightsquid "fix" on pfSense 2.2

    11
    0 Votes
    11 Posts
    10k Views
    jimpJ

    https://doc.pfsense.org/index.php/Lightsquid_Troubleshooting

  • Weird problem in squid guard - Partial access to the Internet

    14
    0 Votes
    14 Posts
    7k Views
    F

    Try running Firefox on the XP box and see if that is any different.

    I'll try

    Clarification
    the computer is old old
    the operating system is old

    Update from yesterday
    But it was already too late and I turned off my computer

    The computer in question was one hour ahead

    I set the computer time and date accurate
    And now

    Only two sites inaccessible
    And show the same message as before

  • Haproxy-devel 1.5.9 pkg v0.20 won't start after upgrade 2.1.5 to 2.2 i386

    3
    0 Votes
    3 Posts
    1k Views
    P

    f.y.i. in (somewhat) recent versions of the package its possible to create multiple 'binds' using the normal webgui options. So its possible to have 1 frontend listen on both :443(with ssl-offloading) and :80. So you don't need the bind in 'advanced pass through' anymore.

  • Squid is not working

    3
    0 Votes
    3 Posts
    1k Views
    KOMK

    Have you looked in your SquidGuard filter log?

  • Squidguard-squid3 systempatch for use with squid3-dev

    59
    0 Votes
    59 Posts
    49k Views
    F

    Hi, :)
    So with ssl filtering, windows update does not want to do this. There in there a manipulation to do to solve this problem.
    Sorry for my bad english  ;D

  • Can Squid be limited to IP instead of subnet?

    5
    0 Votes
    5 Posts
    2k Views
    A

    @Derelict:

    Don't use transparent mode and only hosts set to use it as a proxy will use it.

    Alright I will try doing that, thank you.

  • Squidguard redirect error page

    4
    0 Votes
    4 Posts
    2k Views
    KOMK

    So what was the solution???

  • Squid moaning about /tmp/rules.test.packages syntax error under pfSense 2.2

    Locked
    23
    0 Votes
    23 Posts
    15k Views
    S

    Locking this thread as the original issue is resolved; it was caused by me not associating any interfaces and leaving transparent mode enabled.

    Transparent mode isn't working on i386 and marcelloc has confirmed this is due to a build configuration issue which will be resolved shortly.

    Steve

  • Man in the middle work around for squid?

    9
    0 Votes
    9 Posts
    5k Views
    J

    You are running into the application cert pinning I think, I've seen this on a few IOS/android apps but makes sense here as well, and I've confirmed that is what they are doing as well in the following link:

    http://googleonlinesecurity.blogspot.com/2013/05/changes-to-our-ssl-certificates.html

    At this time, Google Drive's PC application does not support SNI and performs some degree of certificate pinning for transfers.  (This is going to cause you a lot of issues with SSL MITM setups).

    One fairly easy way to work around this is with a DNS based filter and with pfSense you can easily control what DNS server a client is using.

    Thanks,
    Adam

  • 0 Votes
    10 Posts
    6k Views
    1

    thanks for your response, I will look and review what you say, I'm hoping to solve this problem, otherwise im gonna give a shot with lusca.

  • Monitor Squid Status

    Locked
    36
    0 Votes
    36 Posts
    103k Views
    G

    thanks …
    tutorials that you provide goes well
    even now I'm dizzy reading the information provided  ;D

    but I still have one question, how to give a password when accessing cachemgr ?

    thanks a lot

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.