Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Pfsense sequence of execution

    Scheduled Pinned Locked Moved General pfSense Questions
    6 Posts 4 Posters 5.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O Offline
      ozlecz
      last edited by

      how does pfsense execute config if there is squidguard

      -squidguard then firewall rules

      OR

      -firewall rules then squidguard

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        They're not really related, but if you don't have a firewall rule to allow access from LAN (which is there by default unless you have changed it) then squidguard isn't going to do much for you.  What is the actual issue you're dealing with?

        1 Reply Last reply Reply Quote 0
        • K Offline
          kpa
          last edited by

          Traffic that enters the system via an interface always goes to the packet filter/address rewriting first. Any proxy or similar service is then fed from the "feed" that comes in trough the interface, usually with an rdr rule that redirects any traffic to a particular listening port.

          1 Reply Last reply Reply Quote 0
          • O Offline
            ozlecz
            last edited by

            say i have used pfblocker to enumerate all the ASN of google and allow in the rules but i should block youtube.com,  chrome.google.com/  and some google parts and doing that part in target rules under squidguard just dont work for me…i just did it in dns resolver

            1 Reply Last reply Reply Quote 0
            • H Offline
              Harvy66
              last edited by

              By default, PFBlocker won't be able to block Squid from anything. FreeBSD blocks incoming states from being created, that is how it blocks traffic. Quid runs directly on PFSense, which means there is never an incoming state because the state is going to Squid, not YouTube. What you need is a firewall rule that blocks outgoing states or a rule in Squid that blocks those DNS entries.

              1 Reply Last reply Reply Quote 0
              • O Offline
                ozlecz
                last edited by

                ive used pfblocker to resolve all the google asn numbers via whois and used it in the rules to allow this ASN destinations…not to block...

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.