• Adding Certificate Authority for SquidGuard MITM

    2
    0 Votes
    2 Posts
    349 Views
    DaddyGoD
    @mare said in Adding Certificate Authority for SquidGuard MITM: I get the error message that the certificate is self-signed. That might help, because Chrome is always smart ...hmmmm.... from version 58, the self-signed certificate must have the right domain name in the SAN... https://stackoverflow.com/questions/7580508/getting-chrome-to-accept-self-signed-localhost-certificate
  • Squid Guard Target Categories

    2
    0 Votes
    2 Posts
    189 Views
    A
    Hi, I'm not expert about Pfsense, but the Target Categories are filled by you. Or, are you talking about the black lists? In that case, you can decompress and open with a notepad every list.
  • Two certificate in the reverse proxy squid

    1
    0 Votes
    1 Posts
    159 Views
    No one has replied
  • Best way to reverse proxy ssl traffic (as distinct from https traffic)

    3
    0 Votes
    3 Posts
    302 Views
    johnpozJ
    Yeah haproxy would be better choice for sure. And with 2.5 and the update to openssl 1.1.1 you should be able to update to tls 1.3 even.
  • HAproxy local log size

    2
    0 Votes
    2 Posts
    376 Views
    P
    @nandoiin The log log-unixsocket and logfiles are managed by the syslog service. As such how big the logfiles are made is controlled in the generic pfSense logging settings. Though if your really interested in the logs for longer periods you should probably log them to a remote syslog server.
  • 2 Nginx Virtual Servers on one physical server behind HAPROXY

    1
    0 Votes
    1 Posts
    195 Views
    No one has replied
  • Haproxy works outside the network but not on LAN/LAGG

    7
    0 Votes
    7 Posts
    1k Views
    VioletDragonV
    Update, Fixed the problem had to do some tweaking on the NextCloud Server also on the other Servers. Tweak on Nextcloud Server 'overwriteprotocol' => 'https', also had to change upload File Size.
  • Squid Guard are installed, but no showing in Services

    1
    0 Votes
    1 Posts
    109 Views
    No one has replied
  • Is possible give additional rights for access users to site?

    1
    0 Votes
    1 Posts
    180 Views
    No one has replied
  • HAProxy multiple sites on one fronted www and non-www redirection

    1
    0 Votes
    1 Posts
    156 Views
    No one has replied
  • HAproxy with Vmware Remote Console (VMRC) forwarding multiple ports

    1
    0 Votes
    1 Posts
    3k Views
    No one has replied
  • Cannot operate with transparent option

    10
    0 Votes
    10 Posts
    766 Views
    DaddyGoD
    @nikpony said in Cannot operate with transparent option: DNS Forwarding or Resolve? I definitely recommend the Unbound resolver
  • Help with edit squid.conf

    1
    0 Votes
    1 Posts
    166 Views
    No one has replied
  • Squid's new SslBump Peek and Splice for https caching?

    7
    0 Votes
    7 Posts
    3k Views
    GertjanG
    @aGeekhere said in Squid's new SslBump Peek and Splice for https caching?: maybe QoS3 If the server, some proxy device and the client (browser) all install the needed modules .... It would become one hack of a standard before such a thing gets implemented. Typically, this will be needing 3 admins implementing software on their side,as end users often don't know what a 'proxy' is. @High_Voltage said in Squid's new SslBump Peek and Splice for https caching?: to scan with clamav the data in the ssl transmission, NOT just to cache it. That would be my main reason to centralize (== cache ?) downstream data. As far as I know, only 'mails' are handled like this these days. That is, if you run your own mail server (like running some proxy). This takes down a huge security issue already. Btw : You're happy, you control all your devices. Those you don't : they go into the non trusted network. When these need access to local trusted resources like NAS : it will be a case by case consideration.
  • 0 Votes
    7 Posts
    2k Views
    High_VoltageH
    @aGeekhere said in squid blocking things I want to access (access denied for inter-LAN devices): you can get the refresh patten here https://github.com/mmd123/squid-cache-dynamic_refresh-list/pulls I know, I'm the one that made that repo xD No, the problem is I forgot it needs to be run in custom MITM mode to actually work with caching things properly, and by the time I realized that last night it was like 2am, so I went to sleep, I'll be back to work on it later today @aGeekhere
  • HAproxy prevent sending back correct CN, when not sent.

    1
    0 Votes
    1 Posts
    319 Views
    No one has replied
  • Haproxy + letsenrypt. hostname directs to another port

    1
    0 Votes
    1 Posts
    188 Views
    No one has replied
  • HAProxy Certificate Question

    1
    0 Votes
    1 Posts
    245 Views
    No one has replied
  • HAproxy multi-wan

    1
    0 Votes
    1 Posts
    270 Views
    No one has replied
  • hAproxy hands over client IP to apache2 logs [SOLVED]

    Moved
    16
    0 Votes
    16 Posts
    3k Views
    noplanN
    @Derelict i think not tested yet but on the toDo list that the problem was that apache log format was not changed. so that either the gui option nor the advanced option was processed by apache so next step is to check if its workin without advanced setting. keep you posted NP
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.