• 0 Votes
    4 Posts
    7k Views
    A
    We have the same problem… we have installed a diladele webfilter on our pfsense using peek-n-splice for scanning ssl trafic. WPAD does not work with the iOS devices in our wlan. The clients have to install our CA-Cert if they want to use the wlan. The default browser on the mobile devices is using the crt and we can scan the traffic. But Apps like Facebook and Whatsapp does not use DNS - they use ips to connect to there services. If you enter these IPs into the "Bypass Proxy for These Destination IPs" field on the squid config page on the pfsense they will connect directly. But i think this is a bad solution to add all ips seperated by semikolon in this one line field... so i'm trying to add these direct to the squid conf... if you say the "alway_direct" acl does not work - there must be another ACL rule for this... anybody have an idea?
  • Suggestion for Haproxy ACL XOR syntax

    3
    0 Votes
    3 Posts
    1k Views
    N
    Hi PiBa, dang I thought I realised it that way myself on an 1.7 HaProxy Cluster but you're obviously right - it's still not supported.  :-X Maybe I suggest this one to the haproxy community so they'll implement it first.
  • Very weird Squid issue

    3
    0 Votes
    3 Posts
    1k Views
    A
    If Facebook now owns Instagram, could it be that some Instagram services are co-mingled with Facebook servers?  If you're blocking the "Facebook" domain, depending on how Instagram resolves, it may land on a blocked Facebook server.  Other times when pfSense is resolving Instagram it could resolve to a non-blocked (not Facebook) server.  I think I read that pfSense uses the first IP of a domain and it will re-resolve when it needs to. (?) Just a shot in the dark.
  • Adobe redirect issues?

    5
    0 Votes
    5 Posts
    760 Views
    A
    Ok found the issue, when you clear your cache and go to the SDK Download page it asks what country, you must select USA to not get the redirect issue. With downloading adobe AIR I do no know why they are just liking to the homepage.
  • Squid HTTPS/SSL question

    20
    0 Votes
    20 Posts
    19k Views
    B
    @RickTosch: Hi there, I hope my reply does not come across as a hijacking one. Similar scenario as LIGISTX. pfsense +squid in transparent more + SSL MITM. I just had to deploy certificates to Windows, Linux, iOS and android devices. My home environment consists of 10 machines so super tiny. I guess I wont see much of a caching benefit? The primary reason for squid for me was the use of built in Antivirus. I could not find HAVP in the package manager, like many guides reference too. Can I ask please how you installed on Android?  I've installed my certificates, but when I disconnect from my wifi my devices 'connect' but on the devices they say they have no IP address.  They work with transparent HTTP but screw up when I add HTTPS, so I have to add them to the bypass filter. Thanks in advance.
  • Squid Reverse Proxy alternating between destinations

    3
    0 Votes
    3 Posts
    1k Views
    P
    i know its been a while but i'll post my experience for future reference. i had the same issue for quite some time and i solved it by making sure no peer (web server) had spaces on the names, i switches all the spaces to underscores and it was solved. i can see you have a web server called "Win7 Test" … change that to "Win7_test" and that should do the trick. (at least it did it for me) i hope it can solve the issue for at least some of you guys. cheers.
  • Squid Reverse Proxy alternating between destinations - Squid3 Showstopper

    6
    0 Votes
    6 Posts
    3k Views
    P
    i know its been a while but i'll post my experience for future reference. i had the same issue for quite some time and i solved it by making sure no peer (web server) had spaces on the names, i switches all the spaces to underscores and it was solved. i hope it can solve the issue for at least some of you guys. cheers.
  • Squid constantly crashing

    6
    0 Votes
    6 Posts
    2k Views
    V
    It has nothing to do with your or somebody else settings. Its a Squid bug, http://bugs.squid-cache.org/show_bug.cgi?id=4606 I guess we have to wait when it is fixed by Squid team and then when new package will be built by pfSense team later. Interim solution will be to wait for pfSense team apply the patch (if there is patch that is confirmed functional and not causing any additional bugs)
  • HAPROXY issue - Transparent ClientIP breaks my ssl

    1
    0 Votes
    1 Posts
    944 Views
    No one has replied
  • Squid 0.4.36_# Blocking Transparent Proxy

    4
    0 Votes
    4 Posts
    1k Views
    V
    How is your traffic forwarded to Barracuda Cloud Content Filtering ? Please post your squid.conf here
  • 0 Votes
    6 Posts
    2k Views
    T
    @aGeekHere: https://forum.pfsense.org/index.php?topic=112335.0 thanks a lot! this consumed me so much time without realizing it is nothing from end. Thanks again!
  • SquidGuard blocking websites arbitrarily

    3
    0 Votes
    3 Posts
    1k Views
    jimpJ
    It will only block what you have told it to block. What you might find surprising is that when you go to a site like stackoverflow.com it most likely includes third-party libraries or content from Google, like analytics, and some of that might come from app.google.com. So you get redirected because the browser tried to load content from a site you told it to block. Enable logging in squidGuard and on the ACLs/Categories then check the squidGuard logs. You'll see exactly what triggered it. It's also possible that things not blocked are using HTTPS and you didn't configure it to catch HTTPS (e.g. didn't enable HTTPS interception / splice all properly)
  • Squid and squidGuard are not starting

    12
    0 Votes
    12 Posts
    10k Views
    D
    Read the post above!
  • Bug pfsense 2.3.2 squid transparent mode

    5
    0 Votes
    5 Posts
    1k Views
    M
    @doktornotor: @marcelloc: Didi you tried to do not select the loopback interface on squid transparent mode GUI config? That's not even available for obvious reasons. https://github.com/pfsense/FreeBSD-ports/blob/devel/www/pfSense-pkg-squid/files/usr/local/pkg/squid.xml#L263 Plus, the firewall rules have been redone with https://github.com/pfsense/FreeBSD-ports/pull/305 People just should not necropost. i tried and still didn't work , many thanks for your help
  • clamav cannot run

    3
    0 Votes
    3 Posts
    654 Views
    S
    TQ DUDE…SOVLE MY PROB...HEHHEHE
  • FTP Client Proxy in multi-wan

    2
    0 Votes
    2 Posts
    541 Views
    jimpJ
    No. There is no way to do that. It can only exit via the WAN with the firewall's default gateway.
  • Squid Reverse Proxy: exclude specific URI path?

    1
    0 Votes
    1 Posts
    502 Views
    No one has replied
  • SSL Bump Multiple Interfaces

    4
    0 Votes
    4 Posts
    1k Views
    B
    Ok thanks for your reply! But for me it is not clear which part of configuration i have to add in the custom field. Is it enough to insert the following lines: acl networkx src 172.16.0.0/16 ssl_bump splice network 1 ssl_bump bump all Or is it necessary to insert something like "ssl_bump splice whitelist" somewhere between? (to get default behaviour) Thanks!
  • Squid Caching Not Working

    1
    0 Votes
    1 Posts
    891 Views
    No one has replied
  • Problem - SquidGuard + shallalist + time rule.

    4
    0 Votes
    4 Posts
    1k Views
    D
    You'd be a whole lot better off testing the unofficial E2G package: https://forum.pfsense.org/index.php?topic=128116.0
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.