• Squid ssl filter CA issues certificates for ip, not domain

    27
    0 Votes
    27 Posts
    6k Views
    reza3swR

    @doktornotor:

    Well I don't get the question really… that's the whole purpose of the feature. If you don't want it, do NOT make the proxy transparent (or whitelist stuff that's not supposed to get proxied).

    Again thanks for the guidance

    But to control some sites, I need to enable this option, and on the other hand, I have the problem

  • Enable eui squid

    2
    0 Votes
    2 Posts
    590 Views
    D

    Unsupported hack: https://forum.pfsense.org/index.php?topic=121387.msg670943#msg670943

  • SQUID SSL HTTPS AND Transparet Proxy

    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • 0 Votes
    5 Posts
    654 Views
    D

    Well it simply never worked in pfSense, no idea whether it ever worked in FreeBSD but the 7+ years old hints about rdr don't produce any working result for anyone who tried.

  • Squid in a virtual machine and VPN

    1
    0 Votes
    1 Posts
    615 Views
    No one has replied
  • Haproxy redirecting 80 traffic to the management gui

    3
    0 Votes
    3 Posts
    1k Views
    M

    yes that was the problem. After I disabled it, it worked fine. Thank you

  • Is squid actually caching? Logs look strange.

    8
    0 Votes
    8 Posts
    2k Views
    H

    Thanks for your input KOM,

    Much appreciated!

    If anyone else can shed some light that would be fantastic!

    Cheers,
    Nick.

  • Squid with Proxy Authenticated users

    2
    0 Votes
    2 Posts
    470 Views
    D

    You cannot mess with squid.conf directly. There are at least 3 advanced fields for custom ACLs in the GUI (General tab, click the Show Advanced Options button) – may I suggest investigating the GUI configuration more thoroughly?

  • Caching a sharepoint library with HTTPS reverse proxy

    4
    0 Votes
    4 Posts
    973 Views
    O

    Found the right configuration with the help of the Squid Users mailing list.
    I had to add different options to ignore cache control and force the cache to keep and serve the content.
    But it's working now.
    For the record, I'm posting the working Squid Configuration below.

    http_port 10.10.10.10.108:3128 icp_port 0 digest_generation off dns_v4_first on pid_filename /var/run/squid/squid.pid cache_effective_user squid cache_effective_group proxy error_default_language en icon_directory /usr/local/etc/squid/icons visible_hostname pfSense Firewall cache_mgr pfsense@virtualdesk.cloud access_log /var/squid/logs/access.log cache_log /var/squid/logs/cache.log cache_store_log none netdb_filename /var/squid/logs/netdb.state pinger_enable on pinger_program /usr/local/libexec/squid/pinger logfile_rotate 7 debug_options rotate=7 shutdown_lifetime 3 seconds forwarded_for on uri_whitespace strip refresh_pattern -i \.(jpg|gif|png|txt|docx|xlsx|pdf) 30240 100% 43800 override-expire ignore-private ignore-reload store-stale cache_mem 128 MB maximum_object_size_in_memory 20480 KB memory_replacement_policy lru cache_replacement_policy lru minimum_object_size 0 KB maximum_object_size 50 MB cache_dir ufs /var/squid/cache 100 16 256 offline_mode on cache_swap_low 90 cache_swap_high 95 cache allow all # Add any of your own refresh_pattern entries above these. refresh_pattern ^ftp:    1440  20%  10080 refresh_pattern ^gopher:  1440  0%  1440 refresh_pattern -i (/cgi-bin/|\?) 0  0%  0 refresh_pattern .    0  20%  4320 #ACL allow all acl allsrc src all http_access allow allsrc request_body_max_size 0 KB delay_pools 1 delay_class 1 2 delay_parameters 1 -1/-1 -1/-1 delay_initial_bucket_level 100 delay_access 1 allow allsrc # Reverse Proxy settings https_port 10.10.10.10.108:443 accel cert=/usr/local/etc/squid/599eae0080989.crt key=/usr/local/etc/squid/599eae0080989.key defaultsite=tenant.sharepoint.com vhost # cache_peer 13.107.6.151 parent 443 0 ignore-cc no-query no-digest originserver login=PASSTHRU connection-auth=on round-robin ssl sslflags=DONT_VERIFY_PEER front-end-https=auto name=rvp_sharepoint
  • Squid3 transparent proxy - commodo cert?

    21
    1 Votes
    21 Posts
    4k Views
    A

    Try this

    https://datalogus.blogspot.com/2016/06/pfsense-231-security-explicit-squid.html

  • Squid fatal error with SSL interception

    2
    0 Votes
    2 Posts
    5k Views
    D

    Noone read the GUI descriptions these days? Sigh…

    Stop ticking that checkbox or configure a valid CA certificate created in Cert. Manager.

  • Squid is blocking some sites.

    3
    0 Votes
    3 Posts
    1k Views
    NeoDudeN

    Disregard, turns out these sites were being blocked by Snort.

  • Squid doesn't is working with downloads files

    1
    0 Votes
    1 Posts
    415 Views
    No one has replied
  • Squid 0.4.38 And Dashboard Issues

    11
    0 Votes
    11 Posts
    1k Views
    D

    @tman222:

    What changes were made between 0.4.39 and 0.4.40?

    Nothing except for the widget.

  • Haproxy with SSL offloading error

    6
    0 Votes
    6 Posts
    2k Views
    C

    Thanks that worked.

    cjb

  • Caching not working, screenshots attached

    18
    0 Votes
    18 Posts
    2k Views
    KOMK

    I dont understand what the point of running defaults is?

    After looking back over my settings, it appears that i had this selected!..

    ** cough **

  • Squidguard stopped filtering over night

    2
    0 Votes
    2 Posts
    619 Views
    D

    Config

    <squidguard><logdir>/var/squidGuard/log</logdir> <dbhome>/var/db/squidGuard</dbhome> <ldap_enable></ldap_enable> <ldapbinddn></ldapbinddn> <ldapbindpass></ldapbindpass> <ldapversion>3</ldapversion> <stripntdomain></stripntdomain> <striprealm></striprealm> <binpath>/usr/local/bin</binpath> <workdir>/usr/local/etc/squidGuard</workdir> <sgxml_file>/usr/local/etc/squidGuard/squidguard_conf.xml</sgxml_file> <enabled>on</enabled> <blacklist_enabled>on</blacklist_enabled> <blacklist_url>http://www.shallalist.de/Downloads/shallalist.tar.gz</blacklist_url> <destinations><name>FileExtension</name> <domains></domains> <expressions>(.*\/.*\.(asf|wm|wma|wmv|cab|mp3|avi|mpg|swf|mpeg|mp.|mpv|mp3|wm.|vpu|exe))</expressions> <redirect_mode>rmod_none</redirect_mode> <log>on</log> <name>DomainWhitelist</name> <domains>wellsfargo.com bankofamerica.com googleadservices.com skypeassets.com 23.73.247.53 23.2.99.20 23.11.250.157 apps.skypeassets.com skype.com</domains> <redirect_mode>rmod_none</redirect_mode></destinations> <rewrites><name>safesearch</name> <log>on</log> <targeturl>(google\..*/search?.*q=.*)</targeturl> <replaceto>\1\&safe=active</replaceto> <mode>i</mode> <targeturl>(google\..*/images.*q=.*)</targeturl> <replaceto>\1\&safe=active</replaceto> <mode>i</mode> <targeturl>(google\..*/groups.*q=.*)</targeturl> <replaceto>\1\&safe=active</replaceto> <mode>i</mode> <targeturl>(google\..*/news.*q=.*)</targeturl> <replaceto>\1\&safe=active</replaceto> <mode>i</mode> <targeturl>(yandex\..*/yandsearch?.*text=.*)</targeturl> <replaceto>\1\&fyandex=1</replaceto> <mode>i</mode> <targeturl>(search\.yahoo\..*/search.*p=.*)</targeturl> <replaceto>\1\&vm=r&v=1</replaceto> <mode>i</mode> <targeturl>(search\.live\..*/.*q=.*)</targeturl> <replaceto>\1\&adlt=strict</replaceto> <mode>i</mode> <targeturl>(search\.msn\..*/.*q=.*)</targeturl> <replaceto>\1\&adlt=strict</replaceto> <mode>i</mode> <targeturl>(\.bing\..*/.*q=.*)</targeturl> <replaceto>\1\&adlt=strict</replaceto> <mode>i</mode></rewrites> <default><name>default</name> <disabled></disabled> <timename></timename> <redirect_mode>rmod_int</redirect_mode> <rewritename>safesearch</rewritename> <log>on</log> <notallowingip></notallowingip> <destname>!FileExtension ^DomainWhitelist !blk_BL_aggressive !blk_BL_alcohol !blk_BL_anonvpn !blk_BL_chat !blk_BL_dating !blk_BL_drugs !blk_BL_fortunetelling !blk_BL_jobsearch !blk_BL_models !blk_BL_music !blk_BL_podcasts !blk_BL_porn !blk_BL_radiotv !blk_BL_religion !blk_BL_ringtones !blk_BL_sex_education !blk_BL_sex_lingerie !blk_BL_spyware !blk_BL_tracker !blk_BL_violence !blk_BL_warez !blk_BL_weapons blk_BL_webphone !blk_BL_webradio !blk_BL_webtv all</destname></default> <enablelog>on</enablelog> <enableguilog>off</enableguilog> <logrotation>off</logrotation> <adv_blankimg>off</adv_blankimg> <current_lan_ip>192.168.0.254</current_lan_ip> <squid_transparent_mode>on</squid_transparent_mode> <current_gui_protocol>http</current_gui_protocol></squidguard>
  • Cache statistics

    7
    0 Votes
    7 Posts
    2k Views
    P

    Ok, thx… that is not solution I am trying to find...

    Anyway I can check that squid + dynamic caching is working with tail -f command but I am trying to find solution in the long term and I am interested what kind of "savings" I can achieve... Also it would be nice to know what installation packets / images I can found from cache...

  • Log get queries

    1
    0 Votes
    1 Posts
    348 Views
    No one has replied
  • Squid error accessing local dns domain

    1
    0 Votes
    1 Posts
    395 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.