• SSL Intercept

    6
    0 Votes
    6 Posts
    2k Views
    johnpozJ
    @reeko said in SSL Intercept: Blocking things with DNS is not efficient at all I have no idea why you would think that.. Its pretty simple to grab lists or create lists of blocked stuff. But here you go if your wanting to try it. https://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit Intercept HTTPS CONNECT messages with SSL-Bump Clients do not send connect messages when in "transparent' mode of interception of the traffic.. You could try this https://turbofuture.com/internet/Intercepting-HTTPS-Traffic-Using-the-Squid-Proxy-in-pfSense Good luck.. Maybe someone else will chime that does this.. Its not a common practice for sure. I haven't actually used proxy to try and do such filtering in many years. Not a fan of any sort of messing with any ssl traffic. If was going to do it, would use explict pointing to the proxy and use sslbump.. You will have to trust your CA you create - there is no way to use a cert from 3rd party for such a thing because there is no way to create certs on the fly for www.somedomain.tld from already trusted CA.. So devices that can not be set to trust your CA will not work..
  • How to direct connect some website?

    1
    0 Votes
    1 Posts
    359 Views
    No one has replied
  • Generic HAProxy Question (home lab)

    1
    0 Votes
    1 Posts
    377 Views
    No one has replied
  • Unofficial E2guardian package for pfSense

    1k
    3 Votes
    1k Posts
    2m Views
    P
    @periko said in Unofficial E2guardian package for pfSense: Hello marcelloc or other e2guardian users, does e2guardian is already support for pfsense 2.5.2? Regards!!! I've been using it on 2.5.2 for months now, no issues.
  • Squidguard Group Layering

    1
    0 Votes
    1 Posts
    517 Views
    No one has replied
  • haproxy e log

    2
    0 Votes
    2 Posts
    661 Views
    P
    please help me, thanks
  • Save changes in Haproxy causing Crash report

    1
    0 Votes
    1 Posts
    422 Views
    No one has replied
  • HAProxy Backend Problem since upgrade

    2
    0 Votes
    2 Posts
    644 Views
    V
    UPDATE: This is a HA Proxy Dev problem it appears We had Dev on 2.4.5 prior to 21.0x When updating, HA Proxy dev went to a different version which is now not working with SSL backends. From what research we have seen and tried, it is a SSL handshake problem. We tried, reduced SSL settings, real trusted certs...and so on. The only fix was to uninstall HA Dev and install the normal HA Proxy Package Same config, works fine. (old 2.4.5 HA Dev is Current 21.05.1 Prod HA Proxy...or close) Not sure what changed in the versions to break our setup. Any insight would be appreciated if you have seen this behavior
  • Squid https filtering squidguard acl target list - erratic behaviour

    1
    0 Votes
    1 Posts
    371 Views
    No one has replied
  • unable to verify the first certificate

    1
    0 Votes
    1 Posts
    727 Views
    No one has replied
  • SquidGuard Filter Whitelist: Domains work, URLs and RegExp Don't

    1
    1
    0 Votes
    1 Posts
    1k Views
    No one has replied
  • Squid reverse proxy https----->http

    2
    6
    0 Votes
    2 Posts
    644 Views
    M
    the error is 503
  • adservx in URL

    1
    0 Votes
    1 Posts
    476 Views
    No one has replied
  • Haproxy redirect to subdomain

    3
    0 Votes
    3 Posts
    2k Views
    O
    @blasta Just want to say thank you!
  • Groups ACL Client (source)

    squidguard group acl client source host name
    2
    0 Votes
    2 Posts
    922 Views
    W
    @hadiaghajani Hello, I'm trying to do the same thing ... without success. But i'm not able like you to filter by IP adresses. See my post with scheme : https://forum.netgate.com/topic/166308/squid-reverse-proxy-firewall-rules Regards,
  • SQUIDE ERR The requested URL could not be found

    2
    1
    0 Votes
    2 Posts
    468 Views
    KOMK
    @khalildg That's a lovely screenshot you've got there.
  • HaProxy and Blue Iris - Only JPG Streams work

    1
    1
    0 Votes
    1 Posts
    293 Views
    No one has replied
  • Squid Reverse Proxy - Firewall rules ?

    2
    0 Votes
    2 Posts
    865 Views
    W
    Hello, I did a sheme to see what rules i'm trying to do. [image: Ticket-PFsense.jpg]
  • HAProxy x-forward-for

    1
    0 Votes
    1 Posts
    559 Views
    No one has replied
  • When using Wireguard I cant access internal web sites over port 443

    1
    0 Votes
    1 Posts
    387 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.