• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Squid/SquidGuard NONE/409 and DNS issue

Cache/Proxy
9
69
19.3k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    aGeekhere @shawn8888
    last edited by May 11, 2021, 12:00 AM

    @shawn8888 @shawn8888 You can always try the Wpad Unofficial package https://github.com/marcelloc/Unofficial-pfSense-packages/tree/master/pkg-wpad

    Never Fear, A Geek is Here!

    S 1 Reply Last reply May 11, 2021, 2:04 AM Reply Quote 0
    • S
      shawn8888 @aGeekhere
      last edited by May 11, 2021, 2:04 AM

      @ageekhere

      It doesn't install. :(

      login-to-view

      K 1 Reply Last reply May 11, 2021, 2:22 AM Reply Quote 0
      • K
        KOM @shawn8888
        last edited by May 11, 2021, 2:22 AM

        @shawn8888 I don't see any error. Did you look for the menu?

        S 1 Reply Last reply May 11, 2021, 2:29 AM Reply Quote 0
        • S
          shawn8888 @KOM
          last edited by May 11, 2021, 2:29 AM

          @kom
          The install command, the last one, finishes in less than a second
          I cannot find wpad in "Installed Packages" or any change on the menu.

          A 1 Reply Last reply May 11, 2021, 3:09 AM Reply Quote 0
          • A
            aGeekhere @shawn8888
            last edited by May 11, 2021, 3:09 AM

            @shawn8888 first follow this step https://github.com/marcelloc/Unofficial-pfSense-packages

            You have to first enable Unofficial pfSense packages

            Never Fear, A Geek is Here!

            S 1 Reply Last reply May 11, 2021, 3:13 AM Reply Quote 0
            • S
              shawn8888 @aGeekhere
              last edited by May 11, 2021, 3:13 AM

              @ageekhere

              I ran the command in ssh. No change. Then I reboot pfsense. still the same. I don't know what I did wrong.

              fetch -q -o /usr/local/etc/pkg/repos/Unofficial.conf https://raw.githubusercontent.com/marcelloc/Unofficial-pfSense-packages/master/Unofficial_25.conf
              
              A 1 Reply Last reply May 11, 2021, 7:10 AM Reply Quote 0
              • A
                aGeekhere @shawn8888
                last edited by May 11, 2021, 7:10 AM

                @shawn8888 https://forum.netgate.com/topic/116163/unofficial-wpad-package-for-pfsense-software?_=1620716861139

                Never Fear, A Geek is Here!

                1 Reply Last reply Reply Quote 0
                • S
                  SipriusPT
                  last edited by May 11, 2021, 11:18 AM

                  Well seems like I am not the only one in the neighborhood having the same issue, at least with dynamic websites, under a transparent proxy with MITM Splice All. In documentation they should mention the consequences of having this setup with dynamic https websites. The idea that pass is that it should work without any issue, if configured as mention, but its not true, at all.

                  1xSG-4860-1U
                  1xSG-3100
                  2xpfSense Virtual Machines

                  1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance
                    last edited by Mar 18, 2022, 1:56 PM

                    curious as to if there was ever a fix or a solution to this. I do have a bunch of NON/409 errors for various websites with Transparent Proxy configured. The solution is either to turn off the proxy and lose reporting or enable true MITM mode but for certain vlans where I can install the certificate thereby losing the effectiveness of the reporting

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    S 1 Reply Last reply Mar 31, 2022, 4:07 PM Reply Quote 1
                    • S
                      SipriusPT @michmoor
                      last edited by Mar 31, 2022, 4:07 PM

                      @michmoor I end up with a non transparent proxy, using an auto config proxy deployed through pfsense DHCP option 252, and that auto proxy config hosted in one Microsoft IIS, with a bunch of my pfsense IP gateways where squid is placed/responding.

                      On MacOS's I had to enable auto config proxy. Since than I didnt had any more issues. Squid cannot handle HTTPS well under transparent proxys.

                      Thinking in using a transparent proxy on pfsense through squid still gives me nightmares when I think about it....

                      1xSG-4860-1U
                      1xSG-3100
                      2xpfSense Virtual Machines

                      1 Reply Last reply Reply Quote 1
                      • J
                        JonathanLee @shawn8888
                        last edited by Apr 3, 2022, 9:55 PM

                        @shawn8888 have you tried to creat a NAT rule to force all users to use the firewall for DNS?

                        Like this ??

                        login-to-view

                        login-to-view

                        After it doesn't matter what the devices try to use the firewall choses the DNS just change it to what your DNS server is and forget about it.

                        Make sure to upvote

                        J 1 Reply Last reply Apr 3, 2022, 9:56 PM Reply Quote 0
                        • J
                          JonathanLee @JonathanLee
                          last edited by Apr 3, 2022, 9:56 PM

                          @jonathanlee make a alias with DNS ports

                          Make sure to upvote

                          J 1 Reply Last reply Apr 3, 2022, 9:57 PM Reply Quote 0
                          • J
                            JonathanLee @JonathanLee
                            last edited by Apr 3, 2022, 9:57 PM

                            @jonathanlee also set WPAD up on the firewall

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 0
                            • P
                              proggggger
                              last edited by Apr 13, 2023, 7:09 PM

                              maybe a bit late answer but i also find such problem. And little exploring gives me a good solution.

                              (We a talking about Transparent Proxy + Splice all SSL mode)

                              So, first of all, the reason of such problem is one different addresses returned by DNS server

                              So, first of all Proxy should use the same DNS server as clients, so best way to do it is to use our firewall as DNS server (DNS Resolver turned on), so by DHCP we are setting primary DNS address of our firewall, also will be good to redirect all DNS requests to firewall address and block DoH (here article about DNS redirection "Redirecting Client DNS Requests"

                              And after this step lot of people says that it does not help, but why? the answer is simple, DNS RoundRobin, we are getting random ip address fore some websites even if we are using cache you can simply check it, if nslookup (for example for google.com, or twitch.tv or some other site which is not working) gives every time different address you will get 409 error.

                              So how to fix this part? we need to go to DNS Resolver settings, open custom options and add rrest-roundrobin:no which disables randomization of DNS entries. (it should be disabled by default but on pfsense looks like it's enabled)

                              J 2 Replies Last reply Apr 13, 2023, 10:02 PM Reply Quote 3
                              • J
                                JonathanLee @proggggger
                                last edited by Apr 13, 2023, 10:02 PM

                                @proggggger

                                Thanks for the reply,

                                I just tested this and I got a error,

                                login-to-view

                                Just to confirm rrest-roundrobin:no inside of the custom area.

                                This is the error I got kicked back.

                                Make sure to upvote

                                P 1 Reply Last reply Apr 14, 2023, 6:07 AM Reply Quote 0
                                • J
                                  JonathanLee @proggggger
                                  last edited by JonathanLee Apr 13, 2023, 10:09 PM Apr 13, 2023, 10:08 PM

                                  @proggggger Another fix to issues with devices that have no option to configure a proxy is to configure DHCP option 252
                                  This hands the proxy out also when it hands out the dhcp ip addresses. Make sure you have the proxy set up on wpad for this to work.
                                  Example:

                                  https://192.168.1.1:8080/wpad.dat

                                  is handed out with the dhcp address again if your wpad is set up to also hand out the dns server this fixes a lot of issues.

                                  login-to-view

                                  Make sure to upvote

                                  1 Reply Last reply Reply Quote 3
                                  • P
                                    proggggger @JonathanLee
                                    last edited by proggggger Apr 14, 2023, 6:11 AM Apr 14, 2023, 6:07 AM

                                    @proggggger said in Squid/SquidGuard NONE/409 and DNS issue:

                                    open custom options and add rrest-roundrobin:no which disables randomization of DNS entries.

                                    @proggggger @jonathanlee Oh, sorry, i've misstyped a little of course command is rrset-roundrobin:no, (i've also misstyped first time and get this error, here is detailed description of all options (Unboud conf man)

                                    @jonathanlee said in Squid/SquidGuard NONE/409 and DNS issue:

                                    This is the error I got kicked back.
                                    thanks for noticing this

                                    J 1 Reply Last reply Apr 14, 2023, 6:31 PM Reply Quote 0
                                    • J
                                      JonathanLee @proggggger
                                      last edited by Apr 14, 2023, 6:31 PM

                                      @proggggger Thanks for the reply, I have also read online that roundrobin is enabled by default because it is more secure, what are your thoughts about the security concerns that roundrobin addresses?

                                      Make sure to upvote

                                      P 1 Reply Last reply Apr 14, 2023, 9:09 PM Reply Quote 1
                                      • P
                                        proggggger @JonathanLee
                                        last edited by Apr 14, 2023, 9:09 PM

                                        @jonathanlee of course roundrobin can have some security and reliability impact, and one o it's main goals is to distribute load between different servers but for not big networks i think this impact will be minimal (if you check the rr algorithm, you'll se it just randomizes order of addresses). (maybe it's need to be tested, but for now i don't have possibility to rebuild a network, so i only planing and exploring functions with virtual machines0

                                        M 1 Reply Last reply Jul 26, 2023, 12:22 AM Reply Quote 1
                                        • M
                                          michmoor LAYER 8 Rebel Alliance @proggggger
                                          last edited by Jul 26, 2023, 12:22 AM

                                          @proggggger After disabling roundrobin the amount of /409 errors did decrease significantly. I will monitor for a bit more and if its resolved then im going to submit a redmine for a documentation update. This is a long standing problem.

                                          Firewall: NetGate,Palo Alto-VM,Juniper SRX
                                          Routing: Juniper, Arista, Cisco
                                          Switching: Juniper, Arista, Cisco
                                          Wireless: Unifi, Aruba IAP
                                          JNCIP,CCNP Enterprise

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.