• SquidGuard causes timeouts

    4
    0 Votes
    4 Posts
    892 Views
    N
    But btw, also tested a smaller subset, made no difference…
  • My Squid proxy

    9
    0 Votes
    9 Posts
    2k Views
    W
    Sorry it took so long to get back to you on the upgrade yes it was I forget what ver I started with it upgraded like two or three times I cant remember right now but yes it was up grade. I have taking the system back to the beginning of when I first got it up and running and am just doing with out the squid for now I am looking for new system to build or buy to redo pfsense I will be using the new ver I downloaded and burned to disk. I hope that fixes the problem. I  will keep you all up to date with my progress on getting it to work with new system. Thanks for the help so far though I would still be wondering around in the dark if it wasn’t for you folks so thank you so very much.
  • Pfsense and squid proxy certificate sha1 issue

    Locked
    17
    0 Votes
    17 Posts
    8k Views
    jimpJ
    @andikovaci: I try bat have an isue! pbi_add –no-checksig -f squid-3.5.3-amd64.pbi pbi_add: Command not found. pfSense 2.3 does not use PBIs, the information in this thread is for 2.2.x and perhaps 2.1.x. Your issue, whatever it may be, is unlikely to be related to this thread. Start a new thread stating your problem in detail and someone can attempt to help from there.
  • Lightsquid logs Timestamps

    2
    0 Votes
    2 Posts
    1k Views
    F
    i usually use the SquidAnalyzer for these types of reports, here in the forum have some tutorials for this purpose.
  • FTP client proxy can't use aliases.

    7
    0 Votes
    7 Posts
    1k Views
    K
    I'm confused, how can you put anything broken in an IP alias? It's literally a list of IP's you enter in the GUI. I did seem to see similar issues with aliases in some of my firewall rules, but 99.9% of them are still built around aliases and work. But in some of them I had to explicitly write IP's directly to get traffic to move.
  • 0 Votes
    6 Posts
    3k Views
    R
    Hello there, Having the same problem. Currently on 2.3.1 stable release, with squid 0.4.23_1 and squidGuard 1.14_4. I am using aliases as recommended above, but still have the problem. Sometimes squidGuard will simply stop filtering and allow everything, and cleaning the "Bypass Proxy for those source IP's" field and saving solves the problem. Couldn't really find a workout, have to constantly check if filtering is active and wipe the bypass proxy field if it doesn't. Maybe I should create a bug report? Thank you!
  • [SOLVED] HTTP and HTTPS backends switching

    9
    0 Votes
    9 Posts
    2k Views
    U
    Looks like the problem was indeed the name. Well thanks, didn't think that could be it, but I suppose the name isn't just for clarity, it must be used in the conf ! I'll probably replace all of this with haproxy soon anyway, but at least for now it's working.
  • Squid/Squidguard and commercial Antivirus

    4
    0 Votes
    4 Posts
    4k Views
    KOMK
    you wil definitely find answers to commercial antivirus products to run on FreeBSD/UNIX/Linux. Huh, I had no idea.  You learn something new every day. No it's not. If you're using a high end firewall with enough power, it will run. I would rather not have some PC-class desktop as my firewall just so I can scan for viruses and malware that I don't have.  Most of my clients are Android, Apple and Linux.  The Windows boxes have their local AV clients.  I tried ClamAV a few years ago and it was dreadfully slow.  I agree with you when it generally comes to layered security, but AV on the firewall is too much of a performance tradeoff for me.
  • Wpad problem

    6
    0 Votes
    6 Posts
    1k Views
    C
    As I like to explain, from my own viewpoint, WPAD is the very last step in term of configuration. you have to ensure that your proxy works when explicitly configured on your browser once this works, you deploy proxy.pac on some web server and ensure it works when manually configured browser side once and only once this works too, you can push WPAD using DNS, DHCP or whatever supported method. Following this approach, you may discover that WPAD step is the easiest one and most of the time, it works  ;)
  • Block HTTPS site without WPAD or installing a CA certificate.

    3
    0 Votes
    3 Posts
    2k Views
    C
    @dilu1: In Sophos i use an option to block websites (facebook, twitter), this works for http and https. https is configured as "URL filtering only", this has some disadvantages like no content or virus scanning on https sites but that doesn’t matter to much for this case, I am only interested in blocking websites which works. I'm very prone to learn how this would work  8)
  • [SOLVED] haproxy - how to avoid empty response with slow backend?

    Locked
    3
    0 Votes
    3 Posts
    3k Views
    D
    Thanks, that worked.
  • Squid and SquidGuard keeps stopping

    4
    0 Votes
    4 Posts
    1k Views
    KOMK
    Clearing the cache manually might have done the same thing for you.
  • Migrate Linux Squid + SquidGuard to pfSense box

    2
    0 Votes
    2 Posts
    558 Views
    KOMK
    squidGuard has one master config file that holds everything, so your Linux config should be pretty easy to read and reproduce in pfSense.  Linux config is probably in /etc/squidguard/squidguard.conf.
  • Squid makes false certificates on some pages

    10
    0 Votes
    10 Posts
    1k Views
    KOMK
    I don't know for sure, but I do know that transparent mode is more trouble than its worth.
  • Squid and squidGuard - monitor websites and block content

    17
    0 Votes
    17 Posts
    8k Views
    A
    Auto detect is enabled, but if I block those ports do I block them on the subinterface? Because when I do nothing works I can't browse only ping… EDIT: I got it working! It's logging everything - I'm not sure yet why but I'll check tomorrow and write back! Thanks again
  • Transparent proxy not working (CLOSED:SYN_SENT)

    1
    0 Votes
    1 Posts
    854 Views
    No one has replied
  • Cài đặt squid

    1
    0 Votes
    1 Posts
    541 Views
    No one has replied
  • Help with Skype and Squid Proxy

    2
    0 Votes
    2 Posts
    932 Views
    R
    Hi, look here https://forum.pfsense.org/index.php?topic=108370.msg617570#msg617570
  • Sqiud Configuration

    3
    0 Votes
    3 Posts
    902 Views
    H
    Hello, thanks for reply. Whitelist = I dont know where this option is Blacklist = I dont know where this option is blk_BL_adv: Deny = thrue default access all: allow = thrue Do not allow IP-addresses in URL: unticked = false –> Why not ticked? Proxy denied error: blank (you can insert a warning string here) = false –> we have a extern url Redirect mode: int error page = false –> we have a extern url redirect info: blank = false –> we have a extern url Use safeguard engine: unticked = false –> why? Rewrite: none = thrue Log: ticked = thrue [image: squid-conf-1.PNG] [image: squid-conf-1.PNG_thumb] [image: squid-conf-2.PNG] [image: squid-conf-2.PNG_thumb] [image: squid-conf-3.PNG] [image: squid-conf-3.PNG_thumb]
  • PfSense squidGuard Package Installation Issues

    3
    0 Votes
    3 Posts
    1k Views
    R
    @u3c307: squidguard_configurator.inc must contains after require section [ln 53..]: /* Allow additional execution time 0 = no limit. */ ini_set('max_execution_time', '3600'); ini_set('max_input_time', '3600'); ini_set('memory_limit', '50M'); Locate file under /usr/local/pkg Thank you for the reply and detailed direction on what to review for the future! Unfortunately, I do not have the ability to share whether or not these directions would have solved the problem because I rebuilt the router after being unable to find an answer online. Since I had a VERY brand new installation, I didn't lose much except for time in the rebuild. Even though I had to re-install the OS and get everything re-installed and configured, I'm happy for the experience and thus far the community cooperation and support. Thanks again - and I'll keep this saved in the event this happens again as I continue to refine my pfSense configuration. Additionally, for those that are curious - these are the default settings I found in the configuration file. Maybe I would need to bump up the amount to "200M" if this error comes up again? Allow additional execution time 0 = no limit –---------------------------------------------------------------------- ini_set('max_execution_time', '3600'); ini_set('max_input_time',    '3600'); ini_set('memory_limit',      '100M');
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.