• Redirect HTTPS trafic from Internal LAN

    Moved
    16
    0 Votes
    16 Posts
    1k Views
    johnpozJ
    @llinty If your forwarding on your hypervisor - that is where you would have to put in the nat reflection its that simple.. Not sure how you expect the haproxy to proxy traffic it is never seeing.. Put in a host override in pfsense so you client resolves the fqdn to whatever pfsense actual wan IP is where the haproxy is listening.
  • 0 Votes
    3 Posts
    691 Views
    M
    @jimp Perfect, thanks for the explaination :)
  • [SOLVED] HaProxy forward client IP

    Moved
    11
    0 Votes
    11 Posts
    18k Views
    B
    @braunerroei Then your frontend config looks like this? [image: 1667605762622-196c1e01-1e74-49f5-87c8-4d22eb7bf590-image.png] That's the SSL Offloading I was talking about. If you don't check that box, then pfSense won't negotiate SSL. I was worried that you might be processing unencrypted. In any event, I resolved my 503 problems. I'm not using the default port 443 for this new connection. Therefore, the value of the "Host Matches" ACL entry needed to be my.host.com:6407. I had used my.host.com with no port. I had assumed that HAProxy would tack the port number on to the value because the port number is specified in the external address table. I see now it can't do that. The External Address table may contain multiple entries. It follows that the ACL match routine has no way to know your intentions unless you specify the port number in the ACL. Thanks for the help. Your answers got me questioning my own configuration which turned out to be in error.
  • Enabling CORS in HAProxy

    7
    0 Votes
    7 Posts
    6k Views
    CreationGuyC
    Here's what worked for me. I did have to add the lua script to files, however, see my screen shot for the CORS settings. Once I read the lua documentation I was able to add what I needed to get my CORS data to work properly. [image: 1667359059584-screenshot-2022-11-01-at-23-13-27-thewall.jrfam.net-services-haproxy-frontend-edit.png] Not that I did remove my domain for privacy. It's .mydomain.com. I used the . to include all subdomains.
  • Direct access to pfsense ip address and haproxy

    1
    0 Votes
    1 Posts
    414 Views
    No one has replied
  • HAProxy - Slow "Establishing Secure Connection" ??

    4
    0 Votes
    4 Posts
    685 Views
    CreationGuyC
    @creationguy Any further ideas?
  • Cannot change squidguard blacklist URL

    2
    1
    0 Votes
    2 Posts
    563 Views
    D
    Answering my own question... I had forgotten that the URL was originally configured in Squid Guard -> General Settings -> Blacklist options at the bottom of the page. Saving the new value here makes it permanent. I'm not really sure why there is the option to enter a different URL in the Blacklist update page - that seems like a confusing UI design decision.
  • Squid ClamAV antivirus not working properly

    squid clamav antivirus
    14
    2
    0 Votes
    14 Posts
    11k Views
    A
    My problem with this is the need of a whitelist. I curruntly don't know how to have something like "whitelist all except blacklist and pages scaned with a virus" I don't use squidguard but PFBLockerng-devel witch is in my opinion better. It should be a regex like ^.* minus blacklist but I don't see anything on how to do this properly. I have a thread about this: https://forum.netgate.com/topic/175557/squid-clamav-mitm-custom-setting?_=1667128733894
  • mqtts ssl/tls offloading with HAproxy

    Moved
    4
    0 Votes
    4 Posts
    977 Views
    stephenw10S
    I think you may need to use the development version. MQTT support appears to have been added in HAProxy 2.4. Steve
  • HAProxy & ACME - Site not loading

    3
    4
    0 Votes
    3 Posts
    558 Views
    CreationGuyC
    @creationguy said in HAProxy & ACME - Site not loading: HAProxy / Frontend [image: 1666844101428-screenshot-2022-10-27-at-00-14-45-thewall.jrfam.lan-services-haproxy-frontend-edit.png] I selected Proxmox address as the site is on a VM in Proxmox server (10.20.20.3) on the VLAN, that server (10.20.20.4) is Ubuntu Server with Portainer running a docker for an intranet dashboard. 9455 is the port that the docker container uses for the intranet. This particular docker container does not ship with HTTPS. An Update: The front end configuration was the problem, the port needs to be 443. Also, just to note, on the backend, if the site does NOT have SSL, then you need to uncheck Encrypt(SSL) on the BACKEND. HAProxy / Backend intranet.mydomain.com [image: 1666844031139-screenshot-2022-10-27-at-00-13-35-thewall.jrfam.lan-services-haproxy-backend-edit.png] Everything is now working. Unfortunately, if I go to https://crt.sh/ and check my domain, I have a BUNCH of SSL certs. Oh well. Question: How does this tool auto-update my public IP with Cloudflare so that my @ record is always up to date?
  • Http proxy over ssh for redirect all traffic

    1
    0 Votes
    1 Posts
    219 Views
    No one has replied
  • squid error

    5
    0 Votes
    5 Posts
    753 Views
    S
    Dear Periko Yes I enabled DNS Resolver option as Services tab - DNS-resolver-General options. In Network interfaces - LAN Selected while in outgoing Network Interfaces, I selected WAN interface. version of pfsense is 2.6.0-release (amd64).
  • Lightsquid ip resolve method dns not working

    1
    1 Votes
    1 Posts
    247 Views
    No one has replied
  • 0 Votes
    2 Posts
    1k Views
    C
    No ideas or suggestions?
  • Client certificate authentication only for certain backends

    4
    0 Votes
    4 Posts
    855 Views
    S
    @sensewolf anybody got this working?
  • meetinvr.com

    9
    0 Votes
    9 Posts
    991 Views
    M
    @gertjan thanks i will do that
  • squidGuard: allowlist and subdomains

    2
    2
    0 Votes
    2 Posts
    952 Views
    M
    @mrit Okay, figured it out myself (and with the help of the WayBackMachine). Turns out, subdomains are only included for a domain if the domain is the only entry in the domain list. So makes it very hard for me, to also add subdomains (as wildcard) to my allowlist. Maybe it works using regular expressions... Source: https://web.archive.org/web/20210727190453/http://www.squidguard.org/Doc/aboutblocking.html
  • Website Access Problems

    5
    0 Votes
    5 Posts
    954 Views
    F
    @periko Good morning, My whitelist I put https://secweb.procergs.com.br https://assinador.ac.rs.gov.br https://www.ac.rs.gov.br http://crl.globalsign.net https://www.alphassl.com http://ocsp.globalsign.com These were the addresses I put.
  • Squid FATAL check failed

    2
    1 Votes
    2 Posts
    348 Views
    D
    @jonathanlee not sure
  • Fixing HAProxy permisions

    1
    0 Votes
    1 Posts
    227 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.