• SquidGuard Disable "Groups ACL" no work, bug?

    23
    3 Votes
    23 Posts
    3k Views
    Z
    @viktor_g Updated this morning and tested now, so far is working fine as it was in 2.4.5, thanks @viktor_g .
  • Bug when importing backup

    Moved
    1
    1
    0 Votes
    1 Posts
    274 Views
    No one has replied
  • HAProxy SSL setup plus filtering URLs

    3
    0 Votes
    3 Posts
    847 Views
    M
    @piba Okay, thank you for confirming. I will go with decoding and encoding the traffic. Blocking the traffic at the first possible stop and having one central place for the configuration seems the better option (for me).
  • HAProxy + Laravel Socialite (Google/Facebook)

    1
    0 Votes
    1 Posts
    431 Views
    No one has replied
  • Call of webserver and/or nextcloud server blocked in LAN/WLAN

    Moved
    10
    0 Votes
    10 Posts
    1k Views
    johnpozJ
    What is your phone using for dns.. If not resolving the public fqdn your using? doh - dns over http, you been sleeping in a cave the last couple of years? You hear about the global pandemic? ;) doh and dot (dns over tls) are the latest craze to get you to send your dns to the big players, while telling you its more secure.. Because that big bad isp of yours won't see your dns queries.. Oh my gawd - they know you looked up amazon.com ;) Even though they still know you went to ip of amazon, and hey your https connection sent and sni that told them you going to amazon.. But oh my goodness - lets hide the dns query from them.. Anyhoo - browsers like to turn it on by default.. Phones for sure do, etc.. So if your phone is doing that it wouldn't be using your local pfsense dns to even see your host overrides. Also phones like to not use your local dns - android big on this.. you know they know better and even though you tell them via dhcp to use pfsense IP for dns, they like to use 8.8.8.8 anyway. If that is the case and not doing doh, you can just redirect the dns query going to 8.8.8.8 to pfsense. https://docs.netgate.com/pfsense/en/latest/recipes/dns-redirect.html One way or the other you really need to pick your poison here.. Do you want haproxy to send the traffic.. So your clients use the public IP to try and access. If your doing that you do not use nat reflection.. Nat reflection is for port forwards, not reverse proxies.. Either or - if your using host overrides - devices on your local network using your local dns, would never hit your wan/public IP to either be reflected or proxied. So your phone is on your wifi - right? And this is not behind some nat router doing your wifi? its on one of your lan1 or lan2 networks? Also why are you hiding rfc1918 addresses? Nobody gives 2 shits if your using 192.168.1 or 192.168.23.. They are all private.. They don't tell anyone where your at, Sure and the hell can not get to your network via that address.. I use 192.168.9/24 on my lan, and my current pc is 192.168.9.100.. Does that tell anything that you could use to do anything to me, or find out where I am, or anything? I use 192.168.9/24, and 192.168.3/24 for my dmz network - hey I have ntp server open to the public on 192.168.3.32.. There is zero reason to hide or obfuscate rfc1918 space.. My nas is at 192.168.9.10, and I also using 192.168.2 and .4 and .5 and .6 and .7 for other vlans.. And I also have a 192.168.10 network I use as san between my pc and nas that uses 2.5gbps interfaces.. But since I do not have a 2.5gbps switch I have that setup as a san.. Does any of that info really give away anything? Its rfc1918 - everyone on the planet is using it.. It doesn't route over the public internet. Is your wan of pfsense actually public, ie not a rfc1918 IP? 10/8, 192.168/16, 172.16/12 - pick your poison.. If your using haproxy there is little need for host overrides pointing public fqdn to your rfc1918 IP..
  • HAProxy service delayed start after switching to Backup server

    2
    0 Votes
    2 Posts
    422 Views
    P
    @dr1m Running on memory here.. afaik haproxy is 'subscribed' to carp events, and as such should be able to start soon after becoming master.. https://github.com/pfsense/FreeBSD-ports/blob/084b4ad9f65198720720f84d04eeed7c441ed49c/net/pfSense-pkg-haproxy/files/usr/local/pkg/haproxy.xml#L52 dont have time to check why that might fail now.. way past bedtime already here.. As for having haproxy run on both nodes, there isn't much of a downside besides that 'healthchecks' will be fired from both haproxy instances and might increase the load of the webserver a little bit..
  • Get A+ on ssl labs test?

    10
    1
    1 Votes
    10 Posts
    2k Views
    kiokomanK
    @johnpoz yup, i had the default 2048, bumped to 4096
  • Saving HAProxy config causes config restore

    Moved
    3
    0 Votes
    3 Posts
    580 Views
    viktor_gV
    Redmine issue created: https://redmine.pfsense.org/issues/11680
  • Pfsense, HAProxy, Remote Desktop Gateway - Frustrating

    Moved
    2
    0 Votes
    2 Posts
    620 Views
    N
    Please elaborate. Noone would be able to help if the problem isn't well described.
  • pfSense + HAProxy + Layer 4

    1
    0 Votes
    1 Posts
    542 Views
    No one has replied
  • HAproxy Settings error

    12
    0 Votes
    12 Posts
    8k Views
    G
    @piba Thanx for the help man! Now, yesterday I have already tested a bit with a backend and frontend, but I ran into problems...I will create a new issue to explain what I want to achieve and what errors I ran into (whithout above settings and rules, I guess beside safety this doesn't affect the workability of ACME/HAproxy ?)
  • Only releases WhatsWeb for some users

    1
    0 Votes
    1 Posts
    291 Views
    No one has replied
  • Can't do http, only https works Squid reverse proxy

    1
    0 Votes
    1 Posts
    214 Views
    No one has replied
  • HAProxy - Block All But one web directory

    2
    0 Votes
    2 Posts
    509 Views
    P
    @vito So what did you configure to attempt to get to above goal?
  • Transparent https proxy with ssl_bump only record ip address in logs

    1
    0 Votes
    1 Posts
    325 Views
    No one has replied
  • Best way to redirect HTTP to HTTPS

    3
    0 Votes
    3 Posts
    574 Views
    C
    @orionis Any feedback?
  • securiteinfo AV update failed

    4
    0 Votes
    4 Posts
    763 Views
    viktor_gV
    @simbad please create a bugreport https://docs.netgate.com/pfsense/en/latest/development/bug-reports.html
  • Port 25 (SMTP) through PFSense + HAProxy to specific email server

    1
    0 Votes
    1 Posts
    648 Views
    No one has replied
  • Unable to redirect from https to https or http on squidguard

    1
    0 Votes
    1 Posts
    188 Views
    No one has replied
  • Signatures from Malwarepatrol

    1
    0 Votes
    1 Posts
    464 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.