• Manual for fastest browsing setup.

    5
    0 Votes
    5 Posts
    547 Views
    johnpozJ
    His point is caching of http or https traffic in the hope of speeding it up for local access is pretty pointless. Unless your doing mitm on your https, there is nothing to cache. And http is pretty much gone anyway - and even if just http, its dynamic generated sites.. There is really nothing to actually cache. The browser caches stuff anyway that can be cached - since its on the end of the https tunnel.. Other than filtering traffic, there isn't much to thinking your going to cache all that much data with your proxy these days. Its not like the client is going to be downloading the 20KB logo image of some website 100 times a day.. The browser will cache that, etc.
  • deny Internet connection for LAN

    12
    0 Votes
    12 Posts
    937 Views
    KOMK
    Go to Diagnostics - States and reset your states. Existing states are not affected by a block rule change.
  • Steam Caching

    8
    0 Votes
    8 Posts
    2k Views
    X
    @hcurren Why not configure the IP of the docker machine as DNS server for the DHCP pool?
  • Load balancing and SSL certs

    Moved
    3
    0 Votes
    3 Posts
    348 Views
    DerelictD
    @nateliv Stay away from the Load Balancer because: https://redmine.pfsense.org/issues/9386 If you must have your load balancer on pfSense, HAProxy is the way forward. You can put one certificate on the front end and it can load balance X backends.
  • squid proxy blocking soundhound searches

    6
    0 Votes
    6 Posts
    640 Views
    A
    Which device has the issue? PC, android or iPhone?
  • HaProxy Postfix ssl offloading

    4
    0 Votes
    4 Posts
    3k Views
    P
    @rainbowHash said in HaProxy Postfix ssl offloading: where to configure the haproxy backend on Pfsense to enable the send-proxy option You can manually write such a option in the advanced server pass-tru options text field. Either per server separately if you edit a server and expand the extra options part of each server. Or in the the box that applies 'to all servers' in that backend.
  • Possibility Antivirus Gdata?

    3
    0 Votes
    3 Posts
    367 Views
    K
    Thanks i was just wondering
  • How to enter these redirects in Squidguard

    7
    0 Votes
    7 Posts
    3k Views
    A
    not for https sites as far as i know. does duckduckgo have a dns safe mode?
  • Squid not saving cache to disk

    6
    0 Votes
    6 Posts
    1k Views
    M
    @kiokoman Thanks!
  • Squid address

    11
    0 Votes
    11 Posts
    1k Views
    kiokomanK
    under windows you can also modify C:\Windows\System32\drivers\etc\hosts and add it there
  • Squid cache VPN

    13
    0 Votes
    13 Posts
    1k Views
    A
    @KOM Thank You for the effort. At least I know it can't be done.
  • 0 Votes
    1 Posts
    218 Views
    No one has replied
  • Pfsense 2.4.4 squid, squid guard, Outlook and office 365 disconnects

    5
    0 Votes
    5 Posts
    1k Views
    A
    Try this setup a WPAD (make web browser use it ) Manual configure any device that cannot use a WPAD Use transparent proxy with MITM splice all to catch the rest https://forum.netgate.com/topic/100342/guide-to-filtering-web-content-http-and-https-with-pfsense-2-3/178
  • Blocking youtube application from android

    2
    0 Votes
    2 Posts
    430 Views
    KOMK
    You need to monitor it, see where it's really going and then block that.
  • HAProxy leaving IPFW rule after removing backend or uninstall

    haproxy
    2
    0 Votes
    2 Posts
    730 Views
    P
    @lido14 'Normally' IPFW is not running when only pfSense is used without captive-portal.. The quickest fix is probably to give pfSense a reboot.. Haproxy loads and configures IPFW if it 'needs' transparent-client-ip with its current config settings.. If none of the backends require this the IPFW related configuration code is likely completely skipped. It does not remember that it still needs to disable the old ipfw settings.... I guess i need to set a little 'flag' that transparent-client-ip was used and check that to remove the last rules if the current config doesn't use it anymore.. I'm not sure if unloading ipfw itself is possible.. i think there was a issue there...
  • HAProxy, Letsencrypt and synology

    haproxy letsencrypt
    13
    1 Votes
    13 Posts
    5k Views
    V
    Will be nice to learn how to do it both ways - using haproxy and just using the internal CAs as @johnpoz proposes. I went the haproxy route and couldnt get it to work. I have the certs issued and haproxy setup. Perhaps @Renat you can provide a guide how to do it and I will see if that can get me over the hump since I have already done most of the steps? ( some screenshots of haproxy setup). Also anything has to be done on the synology side?
  • Nextcloud/Collabora behind PFsense with SSL Offloading

    1
    0 Votes
    1 Posts
    490 Views
    No one has replied
  • igmpproxy fail to route after old multicast group is removed from table

    1
    0 Votes
    1 Posts
    378 Views
    No one has replied
  • after update SquidGuard dont block adsense ads

    1
    0 Votes
    1 Posts
    225 Views
    No one has replied
  • pfSense 2.4.4, Squid, SquidGuard: Outlook and Office365 - Disconnected.

    12
    0 Votes
    12 Posts
    2k Views
    KOMK
    It shouldn't cause any problems, but if you're unsure then wait until there is low traffic and then try it. It's easy enough to revert.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.