• Groups based access to certian websites

    2
    0 Votes
    2 Posts
    471 Views
    S
    any help in this regard ?
  • HAProxy 0.59_7 not working with SSL. :(

    8
    0 Votes
    8 Posts
    1k Views
    S
    @piba said in HAProxy 0.59_7 not working with SSL. :(: it does seem that backend-exch80_ipvANY isnt 'up' yet.. Have you checked what the stats page says in LastChk column That's the next thing I have to fix on the server side it seems. The server reports a 503 server when I do HTTP to it. I think in the past I had it setup to redirect to HTTPs but after CU10 it might have broke. So no worries right now. 443 works, so does the webserver on 443 and 80. autodiscover is on the same server as OWA so it too is broke on 80.
  • haproxy - not working with ProfileManager (certificate problem?)

    9
    0 Votes
    9 Posts
    1k Views
    R
    @PiBa Yes, I can at least access the macOS Server portal / Profile Manager externally now. SCEP device enrollment isn't working externally for me, though it is internally. I'm not sure how important that is--I think that's (mostly) an enroll once kind of deal. It looks like someone else beat me to experiencing this trouble, and found at least a sledge hammer style workaround. ;-) Thanks for all your help!
  • Need to block email attachment

    2
    0 Votes
    2 Posts
    434 Views
    GertjanG
    Hi, This is something that has to be implemented into the mail server. Every mail server. Thus impossible. Sending and retrieving mails is being done using SSL connections more and more often, so pfSense can't "see" in the data stream that it is an "email". And even if you pulled it off, people stopped using their fat mail client, to browse to their web mail, and then download or upload the attachment. All this will be done over https;//, leaving you out of the game completely. Read also, for example, https://security.stackexchange.com/questions/14120/open-source-tool-to-block-email-attachments edit : if you have people on your network(s) that are capable of downloading (or sending) unknown, potentially dangerous files as attachments, then you throw them on a captive portal and Wifi , using AP's with client isolating activated (== no more local network sharing) and if there is more then one AP, also enforce sharing among these AP's. Only then people (clients, visitors) can mess up badly, and only have their device being fckd up without exposing others on your local net(s).
  • Speed Test

    3
    0 Votes
    3 Posts
    551 Views
    D
    Ooohh. I see. Thank you, Periko
  • ICAP error casued by Squid AV

    Moved
    1
    1 Votes
    1 Posts
    296 Views
    No one has replied
  • odd problem with squidguard and lan ip addresses

    1
    0 Votes
    1 Posts
    410 Views
    No one has replied
  • Hard disk is getting full due to /var/log/c-icap/access.log

    Moved
    3
    0 Votes
    3 Posts
    703 Views
    N
    Hi periko, Thank you for the advise. I am able to clear the log with the command suggested and my hard disk is now at 60%.
  • Squid Transparent Mode MITM doubt?

    3
    0 Votes
    3 Posts
    593 Views
    perikoP
    clean and simple, thanks _neok.
  • squidguard URL filtering not working

    Moved
    4
    0 Votes
    4 Posts
    808 Views
    _neok_
    You need enable MIT feature. This link could be help you. https://turbofuture.com/internet/Intercepting-HTTPS-Traffic-Using-the-Squid-Proxy-in-pfSense Hand up if it was useful. Gabriel
  • HTTP Health check backend with HAProxy package via GET request

    3
    1
    0 Votes
    3 Posts
    2k Views
    K
    Hi, PiBa! Or perhaps you want to configure a 'port' option on the server to make it check on a different port than the regular traffic >>go's to? Could add that on the server-pass-thru option. This is exactly what I need! Thanks, it works for me with the server-pass-thru option :)
  • HAProxy OSCP stapling possibly broken

    15
    0 Votes
    15 Posts
    2k Views
    M
    Dear PiBa, Again, thank you very much! The complaint did not exist in previous versions. Your way does work. Placing the statement in the "Advanced pass thru" box does work also. I would not have understood this without your explanation! Regards, Michael
  • HAProxy reverse proxy with host headers

    11
    0 Votes
    11 Posts
    9k Views
    P
    @piba Thanks a lot for all your help.
  • Squid non-transparent mode: apple iphone siri problem

    5
    0 Votes
    5 Posts
    1k Views
    U
    I got Siri to work by adding the following to my wpad files: if (shExpMatch(url, "guzzoni.apple.com")) || shExpMatch(url, ".guzzoni-apple.com.akadns.net")) return "DIRECT"; Basically, it's bypassing the proxy but that's all I could find. This is where I found it: https://apple.stackexchange.com/questions/253843/siri-on-macos-behind-a-corporate-proxy#253947 and https://blog.mansshardt.net/siri-ios-macos-hinter-squid-proxy-zum-laufen-bringen/ You will need to use google translate unless you know how to read German.
  • HAProxy - Reverse proxy ssl error after config reload

    Moved
    6
    0 Votes
    6 Posts
    3k Views
    V
    @piba You were correct, I had to change the SSL checkbox for the wanhttps Now everything is working and I am back to the SSL Labs A+ rating (if that is worth anything)
  • Squid SSL Splice - intermittent errors

    3
    0 Votes
    3 Posts
    2k Views
    D
    @ageekhere In this case, do I keep the Proxy settings transparent with Splice All enabled?
  • 0 Votes
    3 Posts
    581 Views
    L
    [Solved] I found the log rotate check button for SquidGuard in the GUI. Thanks
  • HAProxy 1.7.10 - Intermittent 504 Errors

    3
    1 Votes
    3 Posts
    929 Views
    R
    I think I have cracked this. What you do is to upgrade in the package manager: To: haproxy net 0.59_4 The Reliable, High Performance TCP/HTTP(S) Load Balancer. This package implements the TCP, HTTP and HTTPS balancing features from haproxy. Supports ACLs for smart backend switching. That seems to pull the HAProxy 1.7.11 as an dependency at least it now claims to be running 1.7.11 and the first tests looks reassuring.
  • Torrent traffice Blocking in pfsense 2.4.4

    1
    0 Votes
    1 Posts
    343 Views
    No one has replied
  • 0 Votes
    1 Posts
    249 Views
    No one has replied
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.