• SquidGuard 1.16.18_15 does't filter content in mixed auth mode

    7
    0 Votes
    7 Posts
    888 Views
    C

    @viktor_g Updated, category filtering now works well.
    But still there is something broken:
    In the past, when I add/remove user from group ACL, it was enough just press Save&Apply.
    But now I have to restart SquidGuard service to apply new membership.

  • E2guardian does not iniciate service

    Moved
    1
    0 Votes
    1 Posts
    333 Views
    No one has replied
  • SquidGuard Disable "Groups ACL" no work, bug?

    23
    3 Votes
    23 Posts
    2k Views
    Z

    @viktor_g Updated this morning and tested now, so far is working fine as it was in 2.4.5, thanks @viktor_g .

  • Bug when importing backup

    Moved
    1
    0 Votes
    1 Posts
    256 Views
    No one has replied
  • HAProxy SSL setup plus filtering URLs

    3
    0 Votes
    3 Posts
    731 Views
    M

    @piba
    Okay, thank you for confirming. I will go with decoding and encoding the traffic. Blocking the traffic at the first possible stop and having one central place for the configuration seems the better option (for me).

  • HAProxy + Laravel Socialite (Google/Facebook)

    1
    0 Votes
    1 Posts
    386 Views
    No one has replied
  • Call of webserver and/or nextcloud server blocked in LAN/WLAN

    Moved
    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ

    What is your phone using for dns.. If not resolving the public fqdn your using?

    doh - dns over http, you been sleeping in a cave the last couple of years? You hear about the global pandemic? ;)

    doh and dot (dns over tls) are the latest craze to get you to send your dns to the big players, while telling you its more secure.. Because that big bad isp of yours won't see your dns queries.. Oh my gawd - they know you looked up amazon.com ;) Even though they still know you went to ip of amazon, and hey your https connection sent and sni that told them you going to amazon.. But oh my goodness - lets hide the dns query from them.. Anyhoo - browsers like to turn it on by default.. Phones for sure do, etc..

    So if your phone is doing that it wouldn't be using your local pfsense dns to even see your host overrides. Also phones like to not use your local dns - android big on this.. you know they know better and even though you tell them via dhcp to use pfsense IP for dns, they like to use 8.8.8.8 anyway. If that is the case and not doing doh, you can just redirect the dns query going to 8.8.8.8 to pfsense.

    https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html

    One way or the other you really need to pick your poison here.. Do you want haproxy to send the traffic.. So your clients use the public IP to try and access. If your doing that you do not use nat reflection.. Nat reflection is for port forwards, not reverse proxies..

    Either or - if your using host overrides - devices on your local network using your local dns, would never hit your wan/public IP to either be reflected or proxied.

    So your phone is on your wifi - right? And this is not behind some nat router doing your wifi? its on one of your lan1 or lan2 networks? Also why are you hiding rfc1918 addresses? Nobody gives 2 shits if your using 192.168.1 or 192.168.23.. They are all private.. They don't tell anyone where your at, Sure and the hell can not get to your network via that address.. I use 192.168.9/24 on my lan, and my current pc is 192.168.9.100.. Does that tell anything that you could use to do anything to me, or find out where I am, or anything?

    I use 192.168.9/24, and 192.168.3/24 for my dmz network - hey I have ntp server open to the public on 192.168.3.32.. There is zero reason to hide or obfuscate rfc1918 space.. My nas is at 192.168.9.10, and I also using 192.168.2 and .4 and .5 and .6 and .7 for other vlans.. And I also have a 192.168.10 network I use as san between my pc and nas that uses 2.5gbps interfaces.. But since I do not have a 2.5gbps switch I have that setup as a san.. Does any of that info really give away anything? Its rfc1918 - everyone on the planet is using it.. It doesn't route over the public internet.

    Is your wan of pfsense actually public, ie not a rfc1918 IP? 10/8, 192.168/16, 172.16/12 - pick your poison.. If your using haproxy there is little need for host overrides pointing public fqdn to your rfc1918 IP..

  • HAProxy service delayed start after switching to Backup server

    2
    0 Votes
    2 Posts
    360 Views
    P

    @dr1m
    Running on memory here.. afaik haproxy is 'subscribed' to carp events, and as such should be able to start soon after becoming master..
    https://github.com/pfsense/FreeBSD-ports/blob/084b4ad9f65198720720f84d04eeed7c441ed49c/net/pfSense-pkg-haproxy/files/usr/local/pkg/haproxy.xml#L52

    dont have time to check why that might fail now.. way past bedtime already here..

    As for having haproxy run on both nodes, there isn't much of a downside besides that 'healthchecks' will be fired from both haproxy instances and might increase the load of the webserver a little bit..

  • Get A+ on ssl labs test?

    10
    1 Votes
    10 Posts
    1k Views
    kiokomanK

    @johnpoz
    yup, i had the default 2048, bumped to 4096

  • Saving HAProxy config causes config restore

    Moved
    3
    0 Votes
    3 Posts
    543 Views
  • Pfsense, HAProxy, Remote Desktop Gateway - Frustrating

    Moved
    2
    0 Votes
    2 Posts
    547 Views
    N

    Please elaborate.
    Noone would be able to help if the problem isn't well described.

  • pfSense + HAProxy + Layer 4

    1
    0 Votes
    1 Posts
    486 Views
    No one has replied
  • HAproxy Settings error

    12
    0 Votes
    12 Posts
    7k Views
    G

    @piba

    Thanx for the help man!

    Now, yesterday I have already tested a bit with a backend and frontend, but I ran into problems...I will create a new issue to explain what I want to achieve and what errors I ran into

    (whithout above settings and rules, I guess beside safety this doesn't affect the workability of ACME/HAproxy ?)

  • Only releases WhatsWeb for some users

    1
    0 Votes
    1 Posts
    240 Views
    No one has replied
  • Can't do http, only https works Squid reverse proxy

    1
    0 Votes
    1 Posts
    201 Views
    No one has replied
  • HAProxy - Block All But one web directory

    2
    0 Votes
    2 Posts
    443 Views
    P

    @vito
    So what did you configure to attempt to get to above goal?

  • Transparent https proxy with ssl_bump only record ip address in logs

    1
    0 Votes
    1 Posts
    309 Views
    No one has replied
  • Best way to redirect HTTP to HTTPS

    3
    0 Votes
    3 Posts
    565 Views
    C

    @orionis Any feedback?

  • securiteinfo AV update failed

    4
    0 Votes
    4 Posts
    672 Views
    viktor_gV

    @simbad please create a bugreport https://docs.netgate.com/pfsense/en/latest/development/bug-reports.html

  • Port 25 (SMTP) through PFSense + HAProxy to specific email server

    1
    0 Votes
    1 Posts
    585 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.