• Content Filtering HTTPS WITHOUT a Proxy?

    16
    0 Votes
    16 Posts
    24k Views
    W
    Plus One ! An article suggests tha SonicWall also uses MITM to block HTTPS content. https://www.sonicwall.com/en-us/support/knowledge-base/170505508942849 They call DPI-SSL but it seems like a MITM/SSL-Bump solution. Regards.
  • PfSense and Exchange / Dynamics CRM / ADFS

    1
    0 Votes
    1 Posts
    670 Views
    No one has replied
  • HAPROXY - stats showing green but not working

    1
    0 Votes
    1 Posts
    539 Views
    No one has replied
  • Squid HTTPS/SSL filtering 2017 [Is this it?]

    27
    0 Votes
    27 Posts
    21k Views
    S
    See alternative to SquidGuard and Dansguardian / e2. GUI is own though and harder to install than desired. https://docs.diladele.com/tutorials/filtering_https_traffic_squid_pfsense/index.html
  • Squid with HTTPS in transparent mode not working

    8
    0 Votes
    8 Posts
    9k Views
    J
    You have to import the CA into firefox manually. Its under options/advanced/certificates/view certificates/import.
  • 0 Votes
    4 Posts
    720 Views
    D
    You have two certificates there (webGUI + CA), or just one?
  • Squid HTTPS | Transparent Proxy | External CA

    2
    0 Votes
    2 Posts
    1k Views
    D
    No, absolutely NOT. You need to have your own CA so that Squid can issue certificates for arbitrary domains on the fly. Otherwise, use "Splice All".
  • Radius groups

    1
    0 Votes
    1 Posts
    677 Views
    No one has replied
  • 0 Votes
    6 Posts
    1k Views
    DerelictD
    That is generally not what people are asking for when they want "Inspection." But it does work pretty well.
  • Username instead of IP address

    2
    0 Votes
    2 Posts
    702 Views
    A
    Hello, did you find any solution?
  • Export letsencrypt certificates from config.conf to servers in the LAN

    1
    0 Votes
    1 Posts
    884 Views
    No one has replied
  • Squid not caching more than 4mb

    5
    0 Votes
    5 Posts
    1k Views
    KOMK
    Your cache settings look ok.  Perhaps related to the content you're trying to cache?  Reproduce the problem and then post your access.log.
  • SquidGuard breaks my DNS

    4
    0 Votes
    4 Posts
    858 Views
    P
    Im now able to access normal websites, i just have to fix it on https sites, thanks for the help.
  • TCP_REFRESH_FAIL_ERR/502 sometime access wp-admin?

    5
    0 Votes
    5 Posts
    1k Views
    D
    Just because you are getting a message from Squid when using Squid doesn't mean it's a Squid problem. Squid got a connection reset from the server (or from something else in the way). That's all. Go figure why the server is resetting the connections. Perhaps they use some "helpful" IDS/IPS in place doing this when someone accesses WP admin via a proxy (yes, I have seen those). Squid isn't doing anything here. It simply received RST before it expected that to happen. Another example: https://wiki.squid-cache.org/SquidFaq/TroubleShooting#What_does_.22sslReadClient:_FD_14:read_failure:.28104.29_Connection_reset_by_peer.22_mean.3F
  • Problem with Squid3 and outgoing email (SMTP)

    2
    0 Votes
    2 Posts
    2k Views
    C
    The reason why SMTP stopped working? I don't Know… How I solved it? In "Services" -> "Squid Proxy Server" -> "ACLs" i went to the field "Unrestricted IPs" and set my LAN net in CIDR Format (192.168.1.0/24), then I went to the field "ACL SSLPorts" and set this "2096 587 443 563" After saving, aplying and a reboot, the SMTP was working again. Greetings!
  • 0 Votes
    2 Posts
    649 Views
    KOMK
    It should work for all devices using pfSense as their gateway.  I assume you have tcp 80/443 blocked on all LANs to force the proxy use?  Your wireless network is on the same subnet as LAN?  Otherwise you might have to include that network in squid's ACLs - Allowed subnets section.
  • Squid proxy not resolving names of whitelisted sites dns name

    3
    0 Votes
    3 Posts
    3k Views
    D
    Read this: https://wiki.squid-cache.org/Features/CustomErrors?highlight=%2528faqlisted.yes%2529#Custom_error_pages_not_displayed_for_HTTPS https://redmine.pfsense.org/issues/6777#note-2 Not a Squid issue. This is how browsers are implemented.
  • How to whitelist long address?

    4
    0 Votes
    4 Posts
    768 Views
    D
    **.**windowsupdate.com P.S. Google the difference between URL and domain.
  • HAProxy - one domain three webservers.

    3
    0 Votes
    3 Posts
    728 Views
    A
    Good question! Ive been looking at HAProxy and reading some instructions I would like to find the same example for  Squid Reverse proxy!
  • Problem with Dansguardian and time based block

    1
    0 Votes
    1 Posts
    427 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.