• 503s on non-offloaded backends

    2
    0 Votes
    2 Posts
    305 Views
    senseivitaS
    Since I wrote this I kept testing and discovered that there's something wrong with the software itself--I think; I've been using de dev version (haproxy18-1.8.23-ish) since forever so I thought it was my own fault for not using the official one, but, I downgraded to the official version (haproxy17-1.7.12-ish) and it got worse. Now neither TLS termination/offloading nor SNI work. It shows something about the data not being complete: [image: 1580265548001-screen-shot-2020-01-28-at-19.33.44.png] Like if it were being corrupted somewhere. I tried different connections to the same result. I thought, maybe other tools like Suricata and ntopng were getting in the way but disabling them (and clearing the states) made no diff. I wanted to send logs to help out devs but I have none. I forgot to set them. My bad. :) When I switched back to the dev version things got working again but I've seen this tends to last like for a little while only. I've also observed that on the SNI front when all backends inevitably fail, the loopback backend (for the offloading front) is the only backend that works--as I mentioned earlier, offloading and http work fine. I'll set up a logging server for the next time. :)
  • https filter with https://http:/*

    18
    1 Votes
    18 Posts
    4k Views
    mguarientiM
    @jonathanp123 I gave up on transparent mode too. i'm still running without the wpad for a moment. But when blocking a website with HTTPS pfSense tries to resolve a host 'https://http*', like the error. With HTTP it displays the correct page.
  • SSL Filtering CA Missing

    6
    0 Votes
    6 Posts
    822 Views
    D
    @viktor_g Is updated... so SSL filtering works only in transparent proxy ?
  • squidguard url whitelist

    1
    0 Votes
    1 Posts
    395 Views
    No one has replied
  • https filter with https://http:/*

    6
    3 Votes
    6 Posts
    3k Views
    J
    I found this and haven't been able to test yet. SquidGuard is broken for https out of the box. You need configure Common ACL Target Rules List Default access [all] to Allow, save. Then click Apply in General settings tab. My best bet is that Default access has no block page configured for some reason. If anyone knows how to get Default access to deny working please let me know. Here is my working SquidGuard configuration step by step tested on pfSense 2.3.4-RELEASE-p1 (amd64): Download any blacklist - shallalist. for example. General Settings -> Blacklist options -> check to enable blacklist Put in Blacklist URL: shalla list Go to Blacklist tab. Hit download (Black list url is already there) Wait for it to finish downloading. 2. You need to configure your blacklist default to Allow state (The default state which is Deny all is what causes https://http/* error) Go to Common ACL Tab Hit plus button on Target Rules List Scroll down to Default access [all], set access to allow Set other categories that you want to be blocked to deny. Hit save at the bottom of the page. Go to General settings Tab. Click Apply at to Top of the page so your settings will be applied from Common ACL Tab. Check if https sites load properly now. Remember to clear cache from before playing with pfsense from your browser or it will show you old state of web filtering.
  • SSL_ERROR_RX_RECORD_TOO_LONG

    2
    0 Votes
    2 Posts
    691 Views
    P
    @kevdog Config seems to look fine.. The haproxy stats page does count your connection/request? And shows the server as 'up'? Testing from 'outside' ? Perhaps disable the transparent-client-ip feature until stuff starts working, then try enabling that again.?
  • Does HAproxy with pfsense support SSL Server and Bind Ciphers?

    2
    0 Votes
    2 Posts
    702 Views
    P
    @kevdog Yes openssl is 'build in'. Those settings should work alright.. Does it work without them? Do you get a 'error' or 'warning' when applying the settings?
  • Pimd a lightweight standalone PIM-SM/SSM v2 multicast routing daemon.

    Locked
    5
    13 Votes
    5 Posts
    2k Views
    jimpJ
    https://forum.netgate.com/topic/149909/new-package-pimd
  • Crash pfsense when squid is enable

    10
    0 Votes
    10 Posts
    864 Views
    GertjanG
    @nico1234 said in Crash pfsense when squid is enable: panic: ufs_dirbad == file system error. Ran fsck ?
  • ngix server available from OpenVPN remote server connection

    1
    0 Votes
    1 Posts
    250 Views
    No one has replied
  • haproxy | Browser says ERR_TOO_MANY_REDIRECTS

    3
    0 Votes
    3 Posts
    5k Views
    tn1rpi3T
    @tn1rpi3 said in haproxy | Browser says ERR_TOO_MANY_REDIRECTS: BOTTOM LINE: All sites are responsive now. However, apache2 does not yet redirect to the desired content. After some extensive trial and error with ACL settings I've come full circle. meaning that I added an "http-request set uri" action to my_site.com and under fmt I put "/subfolder_name" --> This finally sets the desired path on the server. Alas, now the error message "ERR_TOO_MANY_REDIRECTS" has returned. Since the initial cause of above error was solved, I will declare this topic as solved. I would appear appropriate to open another topic on this.
  • HAProxy, PfSense, Cloudflare. Consistently getting 502 error

    3
    0 Votes
    3 Posts
    1k Views
    K
    @tn1rpi3 I will try over at Cloudflare however previously I was passing all packets to the Apache reverse proxy/webserver and I wasn't receiving any 502 errors. Now that HA proxy is in the middle, things don't seem to be working.
  • SSL_ERROR on bloqued pages

    3
    0 Votes
    3 Posts
    462 Views
    M
    thanks for reply! nop, i dont read those info. i think that no transparent proxy is the next step.
  • How to bypass kakaotalk chat?

    1
    0 Votes
    1 Posts
    225 Views
    No one has replied
  • how to make pfsense work as multiple proxy server

    proxy route non-transparent
    1
    0 Votes
    1 Posts
    669 Views
    No one has replied
  • Transparent Proxy setup for Pfsense firewall

    Moved
    2
    0 Votes
    2 Posts
    328 Views
    stephenw10S
    There is a checkbox to enable transparent mode in Squid. Also see the hangout: https://youtu.be/xm_wEezrWf4
  • Cloudflare HTTP 522 with HaProxy

    6
    0 Votes
    6 Posts
    2k Views
    tn1rpi3T
    @tn1rpi3 Solved. Settings on pfsense haven proven quite correct thanks to PiBa's input. The router's correct IP address has been reassigned. Some misunderstanding on the ISP's side.. All good now.
  • Squidguard ldapcachetime and ldapusersearch ldaps://

    1
    0 Votes
    1 Posts
    206 Views
    No one has replied
  • Sending LOGS to GRAYLOG from SQUID PROXY / SQUIDGUARD

    6
    0 Votes
    6 Posts
    4k Views
    O
    @elcid Hello, I am trying to send the squidguard records to send them to graylog and then see them with grafana, can I do it? Greetings and thanks in advance
  • Squid SSL interception access log

    1
    0 Votes
    1 Posts
    259 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.