• HAProxy - Dynamic selection of backend based on subdomain

    1
    0 Votes
    1 Posts
    326 Views
    No one has replied
  • CA not appearing under Squid's SSL filtering dropdown

    1
    0 Votes
    1 Posts
    340 Views
    No one has replied
  • Error installing Squid on pfSense 23.01-DEVELOPMENT

    1
    0 Votes
    1 Posts
    318 Views
    No one has replied
  • Allow telegram on squid pfsense

    1
    0 Votes
    1 Posts
    308 Views
    No one has replied
  • Redirect HTTPS trafic from Internal LAN

    Moved
    16
    0 Votes
    16 Posts
    1k Views
    johnpozJ
    @llinty If your forwarding on your hypervisor - that is where you would have to put in the nat reflection its that simple.. Not sure how you expect the haproxy to proxy traffic it is never seeing.. Put in a host override in pfsense so you client resolves the fqdn to whatever pfsense actual wan IP is where the haproxy is listening.
  • 0 Votes
    3 Posts
    702 Views
    M
    @jimp Perfect, thanks for the explaination :)
  • [SOLVED] HaProxy forward client IP

    Moved
    11
    0 Votes
    11 Posts
    18k Views
    B
    @braunerroei Then your frontend config looks like this? [image: 1667605762622-196c1e01-1e74-49f5-87c8-4d22eb7bf590-image.png] That's the SSL Offloading I was talking about. If you don't check that box, then pfSense won't negotiate SSL. I was worried that you might be processing unencrypted. In any event, I resolved my 503 problems. I'm not using the default port 443 for this new connection. Therefore, the value of the "Host Matches" ACL entry needed to be my.host.com:6407. I had used my.host.com with no port. I had assumed that HAProxy would tack the port number on to the value because the port number is specified in the external address table. I see now it can't do that. The External Address table may contain multiple entries. It follows that the ACL match routine has no way to know your intentions unless you specify the port number in the ACL. Thanks for the help. Your answers got me questioning my own configuration which turned out to be in error.
  • Enabling CORS in HAProxy

    7
    0 Votes
    7 Posts
    6k Views
    CreationGuyC
    Here's what worked for me. I did have to add the lua script to files, however, see my screen shot for the CORS settings. Once I read the lua documentation I was able to add what I needed to get my CORS data to work properly. [image: 1667359059584-screenshot-2022-11-01-at-23-13-27-thewall.jrfam.net-services-haproxy-frontend-edit.png] Not that I did remove my domain for privacy. It's .mydomain.com. I used the . to include all subdomains.
  • Direct access to pfsense ip address and haproxy

    1
    0 Votes
    1 Posts
    427 Views
    No one has replied
  • HAProxy - Slow "Establishing Secure Connection" ??

    4
    0 Votes
    4 Posts
    706 Views
    CreationGuyC
    @creationguy Any further ideas?
  • Cannot change squidguard blacklist URL

    2
    1
    0 Votes
    2 Posts
    574 Views
    D
    Answering my own question... I had forgotten that the URL was originally configured in Squid Guard -> General Settings -> Blacklist options at the bottom of the page. Saving the new value here makes it permanent. I'm not really sure why there is the option to enter a different URL in the Blacklist update page - that seems like a confusing UI design decision.
  • Squid ClamAV antivirus not working properly

    squid clamav antivirus
    14
    2
    0 Votes
    14 Posts
    12k Views
    A
    My problem with this is the need of a whitelist. I curruntly don't know how to have something like "whitelist all except blacklist and pages scaned with a virus" I don't use squidguard but PFBLockerng-devel witch is in my opinion better. It should be a regex like ^.* minus blacklist but I don't see anything on how to do this properly. I have a thread about this: https://forum.netgate.com/topic/175557/squid-clamav-mitm-custom-setting?_=1667128733894
  • mqtts ssl/tls offloading with HAproxy

    Moved
    4
    0 Votes
    4 Posts
    998 Views
    stephenw10S
    I think you may need to use the development version. MQTT support appears to have been added in HAProxy 2.4. Steve
  • HAProxy & ACME - Site not loading

    3
    4
    0 Votes
    3 Posts
    586 Views
    CreationGuyC
    @creationguy said in HAProxy & ACME - Site not loading: HAProxy / Frontend [image: 1666844101428-screenshot-2022-10-27-at-00-14-45-thewall.jrfam.lan-services-haproxy-frontend-edit.png] I selected Proxmox address as the site is on a VM in Proxmox server (10.20.20.3) on the VLAN, that server (10.20.20.4) is Ubuntu Server with Portainer running a docker for an intranet dashboard. 9455 is the port that the docker container uses for the intranet. This particular docker container does not ship with HTTPS. An Update: The front end configuration was the problem, the port needs to be 443. Also, just to note, on the backend, if the site does NOT have SSL, then you need to uncheck Encrypt(SSL) on the BACKEND. HAProxy / Backend intranet.mydomain.com [image: 1666844031139-screenshot-2022-10-27-at-00-13-35-thewall.jrfam.lan-services-haproxy-backend-edit.png] Everything is now working. Unfortunately, if I go to https://crt.sh/ and check my domain, I have a BUNCH of SSL certs. Oh well. Question: How does this tool auto-update my public IP with Cloudflare so that my @ record is always up to date?
  • Http proxy over ssh for redirect all traffic

    1
    0 Votes
    1 Posts
    222 Views
    No one has replied
  • squid error

    5
    0 Votes
    5 Posts
    772 Views
    S
    Dear Periko Yes I enabled DNS Resolver option as Services tab - DNS-resolver-General options. In Network interfaces - LAN Selected while in outgoing Network Interfaces, I selected WAN interface. version of pfsense is 2.6.0-release (amd64).
  • Lightsquid ip resolve method dns not working

    1
    1 Votes
    1 Posts
    251 Views
    No one has replied
  • 0 Votes
    2 Posts
    1k Views
    C
    No ideas or suggestions?
  • Client certificate authentication only for certain backends

    4
    0 Votes
    4 Posts
    871 Views
    S
    @sensewolf anybody got this working?
  • meetinvr.com

    9
    0 Votes
    9 Posts
    1k Views
    M
    @gertjan thanks i will do that
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.