• SquidGuard: Common ACL vs. Groups ACL

    1
    0 Votes
    1 Posts
    804 Views
    No one has replied
  • Who's here using squid with multiwan?

    9
    0 Votes
    9 Posts
    3k Views
    S
    To reiterate: the simple solution is to use an additional Squid proxy instance on a seperate machine, and setup that instance as a parent proxy for the pfSense Squid instance. I've implemente it like that because I wanted the Squid on pfSense to act as a transparent proxy. For multi-WAN, just use policy based routing (gateway groups). This leaves DNS as the only potential issue when the default gateway goes down I think, and that can probably be solved by using an additional Unbound instance on a seperate machine. I didn't test that yet, though, because my default gateway is pretty stable.
  • SSL filtering

    5
    0 Votes
    5 Posts
    2k Views
    A
    I have resolved the issue. I set the DHCP Server to use the interface as the DNS Server. I then applied the same server addresses into squid "use alternate DNS servers" IP addresses vary depending on your network scope. ex: LAN=192.168.1.1 use this as the DNS server applied to DHCP clients. Configure in DHCP Server>Servers>DNS Servers. Then enter the same DNS server(s) IP in Squid Proxy Server>General>Use Alternate DNS Servers for the Proxy Server. HTTPS filtering should work flawlessly using Splice All. And block only the sites set in Squidguard rules.
  • SquidGuard Proxy Filter - safesearch

    1
    0 Votes
    1 Posts
    384 Views
    No one has replied
  • How to add header request in squid.conf

    2
    0 Votes
    2 Posts
    1k Views
    D
    Hello Ashima, Did you find the solution for this case? tks, Santoro
  • Pfsense + Squid HTTPS Transparent

    5
    0 Votes
    5 Posts
    4k Views
    D
    You CANNOT use ACME cert!!! You need your own cert. authority!!!
  • Squid tmg upstream

    4
    0 Votes
    4 Posts
    829 Views
    KOMK
    Services - Squid Proxy Server - Remote Cache?
  • SQSTAT with SQUID 3.x

    2
    0 Votes
    2 Posts
    776 Views
    L
    Anyone?
  • Howto filter https with squidguard regular expressions

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • HAProxy, IIS and Let's Encrypt

    2
    0 Votes
    2 Posts
    2k Views
    G
    For anybody who would have the same problems. I had the website already running for a while over NAT before it was changed to HAProxy. I let let's encrypt create new Certificates and changed the forwarding (http to https) to HAProxy, not the IIS anymore. Now it's working. Clear your cache before you try though!
  • Delay on HAproxy

    1
    0 Votes
    1 Posts
    752 Views
    No one has replied
  • SQUIDGUARD Times- date range bug?

    7
    0 Votes
    7 Posts
    1k Views
    D
    Nice, thanks. ;)
  • Logs Denied by SquidGuard in squid (log)

    3
    0 Votes
    3 Posts
    3k Views
    F
    @Digital_ADHD: I have searched, but has this been resolved? I don't know where to put this.. $sge_prefix = (preg_match("/\?/", $cl['u']) ? "&" : "?"); $str[] = '< iframe > src="'. $cl['u'] . $sge_prefix . 'sgr=ACCESSDENIED" width="1" height="1" > < /iframe >'; I wanna know too!
  • 0 Votes
    1 Posts
    436 Views
    No one has replied
  • Help!!! SquidGuard barring Installs

    14
    0 Votes
    14 Posts
    2k Views
    KOMK
    What version of pfSense are you running?  This might be helpful: http://squid-web-proxy-cache.1019090.n4.nabble.com/TCP-DENIED-407-with-SSL-Sites-but-the-site-is-accessible-td2340748.html I can't be more specific since I don't have user auth for my squid and I've never seen this problem before.
  • Ladp filter search - pfsense 2.3.4

    9
    0 Votes
    9 Posts
    988 Views
    R
    Still no luck.. Is there any suggestion to my issue?
  • Custom SGerror Page

    2
    0 Votes
    2 Posts
    756 Views
    KOMK
    Replace /usr/local/www/sgerror.php with your own.
  • Manipulating user agents in squid

    1
    0 Votes
    1 Posts
    954 Views
    No one has replied
  • HAProxy Frontend saving edits issue - pfsense 2.3.4-RELEASE-p1 (amd64)

    2
    0 Votes
    2 Posts
    653 Views
    P
    Issue resolved by adding a secondary front-end that piggybacks on the backend configurations of the primary frontend. Although this is a workaround we should not the pfsense has a limit of 121 entries in HAProxy front-end ACL section.
  • Content Filtering HTTPS WITHOUT a Proxy?

    16
    0 Votes
    16 Posts
    24k Views
    W
    Plus One ! An article suggests tha SonicWall also uses MITM to block HTTPS content. https://www.sonicwall.com/en-us/support/knowledge-base/170505508942849 They call DPI-SSL but it seems like a MITM/SSL-Bump solution. Regards.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.