Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Combo squid + OVPN routing question

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 516 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      oldschoolrouterjockey
      last edited by

      So Ive got multiple LANs, a "secure" one and and insecure one for IOT. For the secure lan I have a port natted connection to the WAN. This secure lan also has a squid transparent proxy set up for a few of the clients on that secure lan to use that also get sent out that port natted WAN . The insecure/IOT lan routes out to the internet via a port natted OVPN connection; this is done by an inbound route on that insecure lan interface to route all inbound traffic out to a GW I have set up on that OVPN connection, where that OVPN connection also has an interface assigned to it. Things are great.

      Except now I have a requirement for one of these secure lan devices that uses the proxy, to have certain destinations also to be routed out that OVPN connection.

      Is this possible?

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        I have not seen that work. It's relatively easy to set the interface Squid uses for outbound connections.
        It should be possible to set outbound connections based on inbound ACLs in squid but I've never actually seen that work as expected. YMMV!

        Steve

        1 Reply Last reply Reply Quote 1
        • O
          oldschoolrouterjockey
          last edited by

          OK I think this is probably my best bet for now - Ive changed the proxy's outbound interface to my cyberghost interface but then proxy users cannot get out to the internet. I thought it may be b/c those connections arent getting NATted like I had to set up for users of that insecure/iot lan. So I made a duplicate NAT rule and then changed the source to be "this firewall" but then those proxy users still couldnt get out.

          What else am I missing here? I cant think of what it may be?

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Traffic from the proxy should not be NAT'd outbound. It uses the the OpenVPN interface IP dircetly, no need to NAT anything.

            O 1 Reply Last reply Reply Quote 0
            • O
              oldschoolrouterjockey @stephenw10
              last edited by

              ah it was a dumb mistake. I took that NAT out, and then realized on my client it was set for socks not https and now im in business, thanks!!

              1 Reply Last reply Reply Quote 1
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.