• HAProxy fails a backend as DOWN even when check is disabled

    3
    0 Votes
    3 Posts
    3k Views
    A
    @NickyDoes The issue is likely the same as in https://forum.netgate.com/topic/178348/haproxy-backend-port-changes-are-not-applied/ Try adding load-server-state-from-file none to the Advanced Settings > Backend pass thru section of each backend.
  • pfSense to support true dynamic server-template ?

    1
    1
    0 Votes
    1 Posts
    253 Views
    No one has replied
  • 0 Votes
    3 Posts
    3k Views
    D
    Retested on 24.11-RELEASE (amd64) all seems to work. So it seems right to file a bug for this issue.
  • HaProxy ip alias dropdown ?

    1
    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 1 Votes
    10 Posts
    5k Views
    JonathanLeeJ
    @JonathanLee said in UNOFFICIAL GUIDE: Have Package Logs Record to a secondary SSD drive Snort Syslog Squid and or Squid cache system: ln -s -F /nvme/LOGS_Optane/snort /var/log/snort Also you can do this with suricata. /var/log/suricata remove this mkdir /nvme/LOGS_Optane/suricata ln -s -F /nvme/LOGS_Optane/suricata /var/log/suricata
  • HAProxy Cookie Persistance SameSite

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • 0 Votes
    18 Posts
    6k Views
    JonathanLeeJ
    This is a better WPAD file server.modules = ( "mod_access", "mod_staticfile", "mod_expire", "mod_setenv" ) server.document-root = "/var/www/html" server.errorlog = "/var/log/lighttpd/error.log" server.pid-file = "/run/lighttpd.pid" server.username = "www-data" server.groupname = "www-data" server.port = 80 server.bind = "192.168.1.6" server.tag = "" server.range-requests = "disable" server.max-connections = 10 connect-timeout = 2 server.max-keep-alive-idle = 2 server.max-keep-alive-requests = 1 server.max-read-idle = 2 server.max-write-idle = 2 dir-listing = "disable" $HTTP["request-method"] =~ "^(TRACE|TRACK)$" { url.access-deny = ( "" ) } # Cache WPAD and proxy PAC files for 1 day (good practice) expire.url = ( "/wpad.dat" => "access plus 1 day", "/proxy.pac" => "access plus 1 day" ) # Disable access logs to reduce SD card wear (optional) accesslog = "" $HTTP["url"] =~ "^/(wpad\.dat|proxy\.pac)$" { setenv.add-response-header = ( "X-Content-Type-Options" => "nosniff", "X-Frame-Options" => "DENY", "Content-Security-Policy" => "default-src 'none';", "Cache-Control" => "public, max-age=86400", "Referrer-Policy" => "no-referrer", "X-Download-Options" => "noopen", "X-Permitted-Cross-Domain-Policies" => "none" ) # Allow only GET and HEAD methods $HTTP["request-method"] !~ "^(GET|HEAD)$" { url.access-deny = ( "" ) } # Restrict access by IP subnets $HTTP["remoteip"] == "192.168.1.0/27" { } else $HTTP["remoteip"] == "2001:470:8052:a::/64" { } else { url.access-deny = ( "" ) } } # Deny all other URL requests $HTTP["url"] !~ "^/(wpad\.dat|proxy\.pac)$" { url.access-deny = ( "" ) } # Strict URL parsing for security and consistency server.http-parseopts = ( "header-strict" => "enable", "host-strict" => "enable", "host-normalize" => "enable", "url-normalize-unreserved"=> "enable", "url-normalize-required" => "enable", "url-ctrls-reject" => "enable", "url-path-2f-decode" => "disable", "url-path-2f-reject" => "enable", "url-path-dotseg-remove" => "disable", "url-path-dotseg-reject" => "enable", ) url.access-deny = ( "~", ".inc" ) static-file.exclude-extensions = ( ".php", ".pl", ".fcgi" ) # Add WPAD MIME type for correct browser handling mimetype.assign = ( ".dat" => "application/x-ns-proxy-autoconfig", ".pac" => "application/x-ns-proxy-autoconfig" )
  • Squid has officially released 7.0.2 beta if anyone wants to test

    6
    0 Votes
    6 Posts
    3k Views
    JonathanLeeJ
    @brcuewayne DiagnosticsCommand Prompt Shell Output - ls -l /usr/local/sbin/dhcpleases6 ls: /usr/local/sbin/dhcpleases6: No such file or directory Execute Shell Command
  • HAProxy with IP Alias

    5
    0 Votes
    5 Posts
    3k Views
    P
    @viragomann Damn i completely forgot that i could use the current LAN CARP i have..!! Yeah that works for me !! Thank you very much !!!
  • HAProxy Custom ACL with Firewall Alias now working

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HA-Proxy on pfSense 2.8 disable proxy buffering for one backend

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • HA-Proxy| 503 Service Unavailable

    2
    0 Votes
    2 Posts
    3k Views
    V
    @pradeep-sl Check if the backend is shown up as online on the FS stats page.
  • Unofficial Squid Custom Refresh Patterns

    4
    0 Votes
    4 Posts
    3k Views
    JonathanLeeJ
    @aGeekhere said in Unofficial Squid Custom Refresh Patterns: https://github.com/mmd123/squid-cache-dynamic_refresh-list I added them thanks.
  • Jitsi Meet behind HAProxy

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • Force traffic through a proxy

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
  • haproxy not responding

    10
    10
    0 Votes
    10 Posts
    4k Views
    T
    @viragomann "Host Matches" in my Case works only when also setting to "use defaults"
  • phpMyAdmin behind HAProxy

    2
    2
    0 Votes
    2 Posts
    586 Views
    C
    I was able to solve the issue by shifting the redirect rules for phpmyadmin to the frontend instead of trying to path it out on the backend. This resolved the issue for me. Front End [image: 1749176745146-e80ffba8-07fd-4520-8b54-abf5e3bdff8e-image.png] [image: 1749177376791-dd4aa560-b111-4f7a-8489-ef46975a5039-image.png] Since the pathing now happens in the front end, I was able to clean up the backend and it's just a simple passthrough in the case of phpmyadmin. Hopefully, this helps someone else out too. There's probably a more elegant way to solve this, but it did the trick for me.
  • ACL with multi Action

    2
    1
    0 Votes
    2 Posts
    3k Views
    V
    @jonny190 said in ACL with multi Action: in to one rule, i can get the first line in just not the seccond So add a second one. The original config has also two rule for what you want. BTW: the original rule looks a bit different than yours. It seems, to also replace the last octet of the IP.
  • Sqstat Issue

    Moved
    17
    0 Votes
    17 Posts
    8k Views
    N
    @anemacuore 2.8.0 is work (update)
  • Squid error

    1
    0 Votes
    1 Posts
    2k Views
    No one has replied
Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.