• Squid-3.5.27 SSL Custom works few minutes. MITM breakdown

    13
    0 Votes
    13 Posts
    2k Views
    P
    @denisk I've been waiting for the updates version on pfSense too. Squid 3.5 in my usage slowed down the Internet rather than helping it speed up through caching.
  • Squid-3.5 series became DEPRECATED with the release of Squid-4 series

    8
    0 Votes
    8 Posts
    1k Views
    jimpJ
    Will what be in 2.4.4? Squid 4.x? Unlikely. 3.5.28 will probably make it in eventually, but it's not in FreeBSD ports yet.
  • Squid redirect Page

    Moved
    8
    0 Votes
    8 Posts
    2k Views
    stephenw10S
    Try setting the redirect mode in Squidguard to ext url move. You will have to redirect to something, you might create a page for that. I hit that same error recently and that worked around it. Steve
  • [SOLVED] pfSense / Squid vs Untangle - SSL inspection

    6
    0 Votes
    6 Posts
    2k Views
    P
    @nadmax said in [SOLVED] pfSense / Squid vs Untangle - SSL inspection: I installed E2 Guardian last night - I must say it is a very complete package so there is a bit of a learning curve involved. Way more advanced than the Squid equivalent. Nevertheless, I achieved the results I wanted in about 30 minutes - it works exactly as per my expectations. I still have a lot of tuning to do but I have no doubt that I've found what I was looking for. Thanks! No problem at all! Glad I could help! :) If you have any questions, feel free to shoot them through into the E2 Guardian thread and we'll be more than happy to assist!
  • [SOLVED] How to filter HTTPS for wifi network (guests)

    proxy https wifi
    14
    0 Votes
    14 Posts
    5k Views
    P
    You can still do some filtering on HTTPS without the MITM. On E2 Guardian, I have multiple groups setup, some which have MITM enabled and some such as in your case that are for Guest Wi-Fi where I can't properly sneak in the CA. On Squid I believe this is referred to as Bump and Splice all. For my guest Wi-Fi setups, I just use the non-MITM method. This is where the proxy is able to see the domain name without the resource path at the end in order to decide if a website should be let through or not. MITM would obviously allow the proxy to look at the entire URL with the resource path and make a informed decision as to whether or not to allow a website through. I prefer it way more than DNS level filtering as it's more flexible. You can set it up for specific users while others can browse those sites just fine. If you've got sometime, I recommend you give E2 Guardian a shot. It worked out a lot better than Squid in my use case and it has the added benefit of actual phrase filtering.
  • Disable web GUI access when running Squid

    Moved
    6
    0 Votes
    6 Posts
    857 Views
    Mr_JinXM
    scratch that, clam av uses its FQDN, which is allowed to pass the clam av white list.
  • Issue with HAproxy Intermediate certificate

    Moved
    1
    0 Votes
    1 Posts
    635 Views
    No one has replied
  • 0 Votes
    6 Posts
    12k Views
    M
    @tazmo I have Pfsense with HAProxy installed in it .can u guide how to do load balance between two AWS EC2 Web server Instance with SSL. Even i have SSL purchased from the 3rd party tool.
  • WPAD not working

    8
    0 Votes
    8 Posts
    2k Views
    ExolonE
    @albtech See if this website can help WPAD PAC Proxy Configuration
  • Squid negative speed increase

    3
    0 Votes
    3 Posts
    875 Views
    L
    @periko said in Squid negative speed increase: ng the proxy? Did u use auth? This squid server serve about 1200 to 1500 Users. I don't use auth, no error found, dns google work normal.
  • SSL Man In the Middle Filtering error "WindowsUpdate_80072F8F"

    2
    0 Votes
    2 Posts
    594 Views
    L
    Hi guys! I understand that the solution to the current problem does not exist?
  • PfSense randomly blocking web sites

    5
    0 Votes
    5 Posts
    2k Views
    G
    All i can say, most possibly its your configuration.
  • Proxy and Traffic Graph

    2
    0 Votes
    2 Posts
    554 Views
    Raffi_R
    @dotslashniks I think you should still be able to see LAN addresses under the Status/Traffic Graph/. Make sure the Interface selected is LAN. I personally don't find the traffic graph extremely useful. Try installing the ntopng package. It's a great package for checking traffic. Look it up on YouTube, there are great tutorials on what it can do.
  • Landing Page for Pfsense Proxy after User Authentication

    Moved
    1
    0 Votes
    1 Posts
    236 Views
    No one has replied
  • HAProxy - Log host name

    3
    0 Votes
    3 Posts
    1k Views
    A
    @piba said in HAProxy - Log host name: @aeleus Use the 'Advanced pass thru' textbox to put that config setting into ? Thanks, Piba! That works.
  • This topic is deleted!

    Moved
    3
    0 Votes
    3 Posts
    229 Views
    No one has replied
  • Is it possible to use haproxy for DNS over TLS?

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    A client has to explicitly know it's using DNS over TLS, it isn't as simple as forwarding 53 to 853. Running that on 53 may just confuse clients. Even so I'm not sure HAProxy can be used to present a certificate and work with DNS over TLS. Maybe as a simple TCP frontend to a real DNS over TLS backend like Unbound. But if you want something local to answer on 53 and then send the requests out to an upstream DNS over TLS server, then the DNS Resolver on pfSense can handle that. It can also act directly as a DNS over TLS server. It's possible to do with the custom options for DNS Resolver but there are native GUI controls for it in 2.4.4.
  • Groups based access to certian websites

    2
    0 Votes
    2 Posts
    452 Views
    S
    any help in this regard ?
  • HAProxy 0.59_7 not working with SSL. :(

    8
    0 Votes
    8 Posts
    1k Views
    S
    @piba said in HAProxy 0.59_7 not working with SSL. :(: it does seem that backend-exch80_ipvANY isnt 'up' yet.. Have you checked what the stats page says in LastChk column That's the next thing I have to fix on the server side it seems. The server reports a 503 server when I do HTTP to it. I think in the past I had it setup to redirect to HTTPs but after CU10 it might have broke. So no worries right now. 443 works, so does the webserver on 443 and 80. autodiscover is on the same server as OWA so it too is broke on 80.
  • haproxy - not working with ProfileManager (certificate problem?)

    9
    0 Votes
    9 Posts
    1k Views
    R
    @PiBa Yes, I can at least access the macOS Server portal / Profile Manager externally now. SCEP device enrollment isn't working externally for me, though it is internally. I'm not sure how important that is--I think that's (mostly) an enroll once kind of deal. It looks like someone else beat me to experiencing this trouble, and found at least a sledge hammer style workaround. ;-) Thanks for all your help!
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.