Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    squid + squidguard + captive portal issue

    Scheduled Pinned Locked Moved Cache/Proxy
    11 Posts 3 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      heras
      last edited by

      Hello,

      I'm searching for a solution to authenticate users and logs their trafic with the ip and the username.
      For now i have a functionnal captive portal that authenticate users (i'm force to use a custom one since i have multiple connections possibilities)
      I have squid + squidguard functionnal in transparent mode but only logging trafic by ip
      When i select "captive portal" in authenticate mode in squid, squid crash at every start with error "The external_acl_type helpers are crashing too rapidly".

      Unfortunatly its for a public wifi so i can't pass on every device to set proxy neither use GPO (and i feel like WPAD is not user-friendly enough)
      I'm looking for a solution that would be transparent-like for users
      I already tried to do a port forward to squid proxy with no success (can come from a personnal error)

      Do you have idea to solve my problem?

      Thanks

      H G 3 Replies Last reply Reply Quote 0
      • H
        heras @heras
        last edited by

        @heras
        nobody have ideas? :/

        1 Reply Last reply Reply Quote 0
        • G
          greenlight @heras
          last edited by

          @heras said in squid + squidguard + captive portal issue:

          When i select "captive portal" in authenticate mode in squid

          how you can do that? because when i access to squid authentication page i see on the first line

          "Authentication cannot be enabled while transparent proxy mode is enabled"

          H 1 Reply Last reply Reply Quote 0
          • G
            greenlight @heras
            last edited by

            @heras To put it simply, a system can be created for this using pfsense + squid + squidguard + lightsquid + captive portal + freeradius.

            User management can even be done with some ready-made scripts. You can obtain traffic logs by storing files on var/squid/logs.

            1 Reply Last reply Reply Quote 0
            • H
              heras @greenlight
              last edited by

              @greenlight said in squid + squidguard + captive portal issue:

              Authentication cannot be enabled while transparent proxy mode is enabled

              yes i saw that after, that might be the reason of crashs

              Is there a way (maybe with redirection) to enable squid with authentication, so without transparent mode, but to force uses of it on pfsense without need of having a hand on user's devices?

              @greenlight said in squid + squidguard + captive portal issue:

              To put it simply, a system can be created for this using pfsense + squid + squidguard + lightsquid + captive portal + freeradius.

              And yes its this type of system i'm trying to do

              thanks for your answers

              G 1 Reply Last reply Reply Quote 0
              • G
                greenlight @heras
                last edited by

                @heras Why are you Authentication through squid? You can use captive portal and freeradius for this.

                H 1 Reply Last reply Reply Quote 0
                • H
                  heras @greenlight
                  last edited by

                  @greenlight
                  When i put captive portal + squid (to log tafic)
                  They can just pass through portal without login

                  G 1 Reply Last reply Reply Quote 0
                  • G
                    greenlight @heras
                    last edited by

                    @heras Do you want users to access via a login screen?

                    H 1 Reply Last reply Reply Quote 0
                    • H
                      heras @greenlight
                      last edited by

                      @greenlight yes, a personalized one

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @heras
                        last edited by

                        @heras

                        Be aware : Deprecation of Squid Add-On Package For pfSense Software

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        H 1 Reply Last reply Reply Quote 0
                        • H
                          heras @Gertjan
                          last edited by

                          @Gertjan yes i just saw that.. Well i'll look for an alternative then

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.