• HAProxy config changes not loaded/pfsense restart needed

    7
    0 Votes
    7 Posts
    3k Views
    I
    Ok it seems that some time pfsense automatically generates a state file that temporary changes "survive" a reload / restart of haproxy: /tmp/haproxy_server_state If i delete the state file via CLI and then restart haproxy the config is loaded correctly.
  • New Secure Squid version 6.6 status page issues NAT Questions

    2
    0 Votes
    2 Posts
    467 Views
    JonathanLeeJ
    @JonathanLee said in New Secure Squid version 6.6 status page issues NAT Questions: cache_object I went as far as to add an any any rule to see if the ACL blocking port 80 caused this issue however it does not... Same result..
  • Squid 6.6 Status page

    2
    0 Votes
    2 Posts
    235 Views
    JonathanLeeJ
    Also squidclient -h 192.168.1.1:3128 mgr:info@PASSWORD squidclient -h 127.0.0.1 mgr:info@PASSWORD Gives the following error Embedding a password in a cache manager command requires providing a username with -U: mgr:info@PASSWORD Also squidclient -h 192.168.1.1:3128 /squid-internal-mgr/info@PASSWORD squidclient http://127.0.0.1:3128/squid-internal-mgr/info@PASSWORD squidclient http://192.168.1.1:3128/squid-internal-mgr/info@PASSWORD squidclient -h http://127.0.0.1/squid-internal-mgr/info@PASSWORD How can we access the status page currently?
  • SQUID_TLS_ERROR_ACCEPT

    7
    1 Votes
    7 Posts
    755 Views
    JonathanLeeJ
    @cavouto have you created a new certificate yet non rsa? I needed one that ECDSA with prime256v sha256 and not RSA anymore that solved my errors The error is gone when this cert is used :)
  • HAProxy backend ACL won't save

    1
    0 Votes
    1 Posts
    152 Views
    No one has replied
  • 0 Votes
    10 Posts
    2k Views
    johnpozJ
    @JonathanLee tls 1.3 has been used for quite some time.. Any time I bother to look at the connection to pretty much anything its tls 1.3.. This connection to the forums is using tls 1.3 ensi is dead but long live ech, that could be problematic I would bet.. But again I don't do any sort of mitm, its not good practice - I want my ssl/tls to be end to end.. As the internet gods intended it to be ;) I have no need or desire to run a proxy.. If I want to block someting I would filter on IP or DNS.. Yes I block the bane of filtering doh and dot. I run a reverse proxy, but not as a filtering method or as a way to do mitm.. But as a way to offload the ssl connection because the actual services have no ssl support at all, or are a pain to setup. These connections are tls 1.3.. And I don't even allow 1.2, if your not using 1.3 then your not accessing it. And use strict sni - so if you don't send the valid sni your not being proxied in either. This keeps rando port scanners from being able to actually get to the sites interface. And I block most of the known scanners from talking to any of my forwards anyway, and only allow access into my forwards if your coming from US IP, etc.
  • Squid StoreID and Facebook plus caching Windows updates

    13
    0 Votes
    13 Posts
    2k Views
    JonathanLeeJ
    This seems to improve speeds http_upgrade_request_protocols websocket allow all accept_filter httpready accept_filter dataready collapsed_forwarding on half_closed_clients off pipeline_prefetch 6
  • HAProxy forwardfor

    6
    0 Votes
    6 Posts
    481 Views
    V
    @viragomann said in HAProxy forwardfor: @varazir You can see the http headers in the capture? yes, strange is that it's only for Authelia I don't get the header set. I think I'm going to remove it. Using wireguard to connect to my home network.
  • 0 Votes
    16 Posts
    2k Views
    JonathanLeeJ
    So generation 2 proxy technology can help if its built right...
  • Any experience with HAproxy 3.0 ?

    3
    0 Votes
    3 Posts
    249 Views
    Sergei_ShablovskyS
    @JonathanLee said in Any experience with HAproxy 3.0 ?: Sorry, could You be so please to explain Your reply? I asking because some improvements and new features in HAproxy 3.0 are really great (and some of them - was so long asking for). Of coarse, in hi-loading environment would be better to using SEPARATE HAproxy-balanser (no matter containerized or on bare metal) from pfSense . But the same time this not mean not to updating HAproxy to 3.0 in pfSense+ or CE. Am I wrong with this? @Sergei_Shablovsky Did you see you can run it in a docker container now? Sorry no time to seeking for right video, but this one probably not need the translation. @Sergei_Shablovsky is that the high availability software for running two different firewalls? As I know, One short example...., and another one. The last from this two examples are the "best pair" HAproxy+Keepalived that used widely and successfully from 2020-2024. And I personally know a bunch of projects (both hiload and enterprise) with implement, orcestrate and monitoring this HAproxy+Keepalived pair sucsessfuly
  • Squid.conf.documented mix up

    tls-default-ca default-ca squid
    1
    0 Votes
    1 Posts
    198 Views
    No one has replied
  • Squid and Squidguard speed issues

    1
    0 Votes
    1 Posts
    119 Views
    No one has replied
  • SquidGuard Target Categories and Groups ACL Sorting Problem

    7
    1 Votes
    7 Posts
    587 Views
    C
    @w-hackl said in SquidGuard Target Categories and Groups ACL Sorting Problem: put on top of the list I can confirm that, it didnt happen in 2.6.x ver and appear on 2.7.x
  • Haproxy Layer6 Issues - Intermittent Logging

    help haproxy ssl letsencrypt
    1
    0 Votes
    1 Posts
    340 Views
    No one has replied
  • Squid and IPv6

    he.net ipv6 squid certificates
    1
    0 Votes
    1 Posts
    329 Views
    No one has replied
  • Squid trying to use IPv6 address when it shouldn't

    2
    0 Votes
    2 Posts
    192 Views
    JonathanLeeJ
    try an acl http_access deny to_ipv6 http_access deny from_ipv6
  • Magento2 after pfsense and haproxy ssl offload

    2
    0 Votes
    2 Posts
    192 Views
    V
    @Tony-Soprano Does the site load correctly if you access it directly? How do you access it? Is the site running in a virtual directory? With the debugging mode enabled in the browser, are there any failures to see?
  • Haproxy: HTTP Auth?

    2
    0 Votes
    2 Posts
    198 Views
    M
    @oguruma You can do it now via the custom options. You just need to know the HA Proxy syntax. Might want to openAI that.. But there is no GUI option if that is what you are looking for.
  • HAProxy: Adding a Path in Backend Config

    7
    0 Votes
    7 Posts
    1k Views
    Gamienator 0G
    @viragomann Thanks! I‘ll set it up tomorrow and report
  • Squid Coredump logs

    3
    0 Votes
    3 Posts
    307 Views
    JonathanLeeJ
    I am suppose to enable sysctl -w kern.sugid_coredump=1
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.