• Squid upload blocking with multiple subnets

    2
    0 Votes
    2 Posts
    491 Views
    KOMK
    @vijay7 How are you doing the upload blocking?
  • HAProxy's ACLs not working as expected

    5
    0 Votes
    5 Posts
    1k Views
    H
    @rupesh According to the hint written in the IP Alias creation form, it does. Hint : Enter as many hosts as desired. Hosts must be specified by their IP address or fully qualified domain name (FQDN). FQDN hostnames are periodically re-resolved and updated. If multiple IPs are returned by a DNS query, all are used. An IP range such as 192.168.1.1-192.168.1.10 or a small subnet such as 192.168.1.16/28 may also be entered and a list of individual IP addresses will be generated. The thing is, when re-doing the DNS resolution, pfSense may be fooled by a DNS cache. If it probes a DNS that has the old record in cache and does not re-probe the SOA, the new IP will not be detected. As such, the delay after an IP address changed is : --Time for the client to update its records (can be as quick as instant or longer) --Time for the previous record to be purged from the cache in the DNS server probed by pfSense --Time for pfSense to renew the IP alias After all of these delays, then the alias will be updated. It can be very long, some DNS cache may last for 30 days, but at a certain moment, it will happen. Regards,
  • SquidGuard Error Redirect

    1
    0 Votes
    1 Posts
    220 Views
    No one has replied
  • Haproxy ACL combine

    3
    0 Votes
    3 Posts
    371 Views
    R
    @piba thankyou piba, you are a savior.
  • HaProxy with custom ACL

    1
    0 Votes
    1 Posts
    778 Views
    No one has replied
  • SSL Man in the middle Filtering / PFsense

    1
    0 Votes
    1 Posts
    477 Views
    No one has replied
  • Issue with squid cache download speed

    2
    0 Votes
    2 Posts
    643 Views
    A
    Ok after playing around with it and clearing the states a few times a rebooting it seems to be working now. Will see if the issue happens again
  • HAProxy is running, but backend is down in stats and cannot access server

    7
    0 Votes
    7 Posts
    5k Views
    H
    @TGill, HAProxy is testing over HTTP/1.0 while your curl is using HTTP/1.1. That may very well be the difference between the two tests and the two results. You can try something like HTTP/1.1\r\nHost:\ hostname.domain.lan in the "Http check version" box in your backend's configuration.
  • Squid Guard changes only apply after system reboot

    3
    0 Votes
    3 Posts
    512 Views
    B
    @kom That did the trick! I knew it was something simple I was overlooking. Thanks for the help!
  • 0 Votes
    1 Posts
    185 Views
    No one has replied
  • How to store Lim Light Squid Cache 4.14

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • HAProxy : Shared Frontend: SSL and Non-SSL Backends?

    3
    0 Votes
    3 Posts
    2k Views
    T
    @clarence I'm glad I found your post, maybe you can help me too. I also use Dynu.com and am trying to setup SSL from Let's Encrypt but I can't get it to work and I'm thinking it has to do with authentication through Dynu. I have one static IP address and want to be able to host 2 or 3 websites, all public. I also like to watch Tom's videos at Lawrence Systems and watched the video you linked before I got started but it wasn't clear enough for me. I found this video which walks the way through the creation of the setup. https://www.youtube.com/watch?v=FWodNSZXcXs Now I setup essentially the same configuration he put together. In Acme I created 1 wildcard cert from Let's Encrypt for my domain and one specific to one of the websites. They all completed successfully. His setup worked mine didn't. So I did more searching and found your post here. I did not know CAAs had to be created so I just added them to my Dynu DNS records. I also added your suggestion for the added security settings to my setup. Still my websites will connect through HAproxy but they still show "Not Secure". You mentioned you had to create txt records. What are they and where do they go? What infomation needs to be in them? Is this because of the way Dynu works? Any ideas what I could be missing.
  • Не получаю билет kerberos

    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
  • pot. Bug: special characters in description

    4
    0 Votes
    4 Posts
    603 Views
    viktor_gV
    Fixed in -devel: https://redmine.pfsense.org/issues/11680
  • krb5.conf

    2
    0 Votes
    2 Posts
    279 Views
    No one has replied
  • HAProxy: After upgrading 2.5.0 -> 2.5.1 no server entries in backend

    4
    0 Votes
    4 Posts
    692 Views
    D
    Ok, this was a side effect of this problem: https://forum.netgate.com/topic/162978/unbound-stop-working-on-127-0-0-1-after-2-5-1-upgrade
  • HAProxy truncating requests?

    1
    0 Votes
    1 Posts
    584 Views
    No one has replied
  • HAProxy with multiple connections

    2
    0 Votes
    2 Posts
    462 Views
    P
    @hannesk Put both of the 2 acl names behind the use_backend action.?
  • 0 Votes
    1 Posts
    369 Views
    No one has replied
  • It is safe to manually remove logs from Squid and SquidGuard?

    1
    0 Votes
    1 Posts
    203 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.