Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SquidGuard ACL Order

    Scheduled Pinned Locked Moved pfSense Packages
    7 Posts 2 Posters 7.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      freebee
      last edited by

      Hi for all.
      Is about the SquidGuard. If i understand, in ACL in SquidGuard, the acls have action when in order. So, the problem is. The first acl have some sites like orkut and youtube. The third have just bloqued categories. In first ACL, default access is allow, but in that, the second and third list is ignored. But, if i change to deny in first ACL, no pages are browserable, just get browsing in pages inside registered. Attach is the print screen.
      squidguard1.jpg
      squidguard1.jpg_thumb
      squidguard2.jpg
      squidguard2.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • D
        dvserg
        last edited by

        Each ACL contains self full ruleset. Each ACL defined only for his 'Sources'. Client processed first-mach ACL from list, or with Default ACL, if not found suitable ACL. Not one of the clients can not be processed by several ACL, only one suitable.
        ACL order need for define VIP-ACL for Source from common list
        fo example
        0 - source 10.0.0.200 - director
        1 - source 10.0.0.0/30 - IT department
        3 - source 10.0.0.0/24 - all my subnet
        DEFAULT…....................................

        SquidGuardDoc EN  RU Tutorial
        Localization ru_PFSense

        1 Reply Last reply Reply Quote 0
        • F
          freebee
          last edited by

          i think i made a bad expression. In the truth, i want change the Destination order to my custom list come before others destinations in the acl.

          1 Reply Last reply Reply Quote 0
          • D
            dvserg
            last edited by

            @freebee:

            i think i made a bad expression. In the truth, i want change the Destination order to my custom list come before others destinations in the acl.

            It's possible. Use 'white'(whitelist) for hi-level proirity for rule.
            Rules order ->-[deny]->-[allow]->-[last default=allo/deny]
            If you want exclude some sites from blacklist need define self Destination rule and select 'white' for him in ACL.

            SquidGuardDoc EN  RU Tutorial
            Localization ru_PFSense

            1 Reply Last reply Reply Quote 0
            • F
              freebee
              last edited by

              how i can do that trought squidguard gui in pfsense?

              1 Reply Last reply Reply Quote 0
              • D
                dvserg
                last edited by

                @freebee:

                how i can do that trought squidguard gui in pfsense?

                In ACL select 'white' for you destination rule.

                SquidGuardDoc EN  RU Tutorial
                Localization ru_PFSense

                1 Reply Last reply Reply Quote 0
                • F
                  freebee
                  last edited by

                  i got it… thanks a lot.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.