• Remove HAProxy and Configuration

    2
    0 Votes
    2 Posts
    1k Views
    V

    @s3v3nd34dly51ns
    When you forward the traffic, it cannot reach HAproxy anymore, no matter if it is installed and running or not.
    Port forwarding happens at the first level on the incoming packets.
    So HAproxy or even its settings might not be responsible for your issue at all.

    If you're in doubt, you can sniff the traffic on the inside interface.
    So there will be another reason for that. Best to investigate with packet capture to see, what's going on.

  • AFTER PFSENSE UPDATE TO 22.05 SQUID WILL NOT RESTART

    7
    0 Votes
    7 Posts
    2k Views
    A

    @myster_fr thank you, just ran into this issue and i confirm, it works.

  • 1 Votes
    5 Posts
    2k Views
    JonathanLeeJ

    @jonathanlee

    Screenshot 2023-02-10 at 6.32.55 PM.png

    I adapted this for testing and set it to stare all because of this statement on their website, "The following configuration obtains SNI by parsing TLS Client Hello (due to a matching peek rule at step1) and then either splices bank connections OR stares at the TLS Server Hello (due to a matching stare rule) and bumps non-bank connections (due to the default bump-after-stare rule)."

    It has a default bump after stare rule, so bump step 3 is not needed
    I am thinking. This also seemed to speed up everything.

    Ref:
    https://wiki.squid-cache.org/Features/SslPeekAndSplice

  • Outdated options in squid.conf

    1
    0 Votes
    1 Posts
    390 Views
    No one has replied
  • HAProxy not rendering SSL traffic properly

    8
    0 Votes
    8 Posts
    1k Views
    B

    @viragomann I tried looking into absolute path but then why did it work when it was published with TMG? Nothing changed in the backeend.

  • Squid Proxy seeing Urbanairship.com??

    1
    0 Votes
    1 Posts
    772 Views
    No one has replied
  • Our clamd service stops working

    1
    0 Votes
    1 Posts
    415 Views
    No one has replied
  • Synology Surveillance Station cannot be accessed when behind HAProxy

    4
    0 Votes
    4 Posts
    2k Views
    A

    @cyrus104

    I was able to make this work by adding following custom ACL:

    2M3tjblqot.png

  • Unable to access Outlook behind Squid Proxy

    3
    0 Votes
    3 Posts
    842 Views
    Y

    @michmoor Thank you for your reply

    The Squid logs doesn't show any activity concerning the Outlook application only web traffic through the browser. when i try to reach our webmail it fails with tcp:denied. i added 993 465 and 2096 (webmail port) to the list of safe ports. Now the webmail works but not Outlook.

    As i have stated the end users needs to be routed through the 172.26.2.1 router because of our provider but the network doesn't have internet connection. The sole purpose of installing pfSense was to implement the proxy so the end users can use the internet(with exceptions added to the proxy), it's not really acting as a router.

  • Automatic updates for squidguard blacklist

    Moved
    6
    1 Votes
    6 Posts
    4k Views
    JonathanLeeJ

    @dbmandrake
    799ecc95-da12-4329-8986-86e3b8bbb51d-image.png

    61216ded-5a50-4492-b951-3825dfab0c9d-image.png

    Thanks for the info, it's working great. 9:29 AM test ran automatically.

  • Work laptop disabling local network

    7
    0 Votes
    7 Posts
    1k Views
    chpalmerC

    It could be likely that your work laptop creates a VPN to your business network and thus would be invisible to other devices on your home network.. That is true of mine.

    That could be why other devices cannot ping it..

  • 3 Votes
    23 Posts
    3k Views
    JonathanLeeJ

    @dbmandrake thanks for the information on the auto update.

  • Squid Proxy - Whitelist domains - Any lists out there?

    21
    1 Votes
    21 Posts
    6k Views
    JonathanLeeJ

    @dbmandrake It did not work for me unless I included the ip address of the firewall and the loopbacks in an alias, the other way it would just fail for me.

  • Squid And Squidguard port allow

    1
    0 Votes
    1 Posts
    355 Views
    No one has replied
  • How to block http inbound connection by http header

    3
    1 Votes
    3 Posts
    556 Views
    johnpozJ

    @michmoor exactly... To be honest, that is DO - in what scenario would they ever need to be inbound to you?

    Block all of their ASNs

    NetRange: 165.22.0.0 - 165.22.255.255 CIDR: 165.22.0.0/16 NetName: DIGITALOCEAN-165-22-0-0

    pfblocker makes it easy to look up ASNs and put them into a alias and then block that completely from your services you don't want them to be able to talk to.. DO while is a big cloud provider - why would you have need of inbound traffic from them? They are not known for being to particular on how they allow their services to be used.

  • Squid access.log not incrementing each day

    1
    0 Votes
    1 Posts
    250 Views
    No one has replied
  • Netgate 2100-MAX and the recommended Hard Disk Cache System settings?

    1
    0 Votes
    1 Posts
    305 Views
    No one has replied
  • Websockets configuration in HAProxy

    Moved
    12
    0 Votes
    12 Posts
    12k Views
    M

    Thank you for this! Got my application to work. Much appreciated.

  • Squis works but after a while half of the webpages are gone??

    1
    0 Votes
    1 Posts
    273 Views
    No one has replied
  • Reloading SquidGuard increases number of processes with no limit ?

    1
    0 Votes
    1 Posts
    285 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.