Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Load Balance and Squid does not work runnig in the same server

    Scheduled Pinned Locked Moved 2.0-RC Snapshot Feedback and Problems - RETIRED
    53 Posts 17 Posters 45.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rubic
      last edited by

      Hm… will think about... however, looking at pf packet flow diagram, I wonder if floating load-balance rule can fire twice
      by the way, in my case your solution works even without binding squid to loopback ???

      1 Reply Last reply Reply Quote 0
      • R
        rubic
        last edited by

        heper, you were right!
        when default WAN is down, an outgoing packet hits the rule twice (both on WAN fnd OPT-WAN interface)
        if you don't mind I would like to translate your how-to for russian pfSense community
        thanks!

        1 Reply Last reply Reply Quote 0
        • E
          eri--
          last edited by

          It hits it twice but really it does not execute the policy routing the second time.
          Only the nat rules are executed.

          1 Reply Last reply Reply Quote 0
          • R
            rubic
            last edited by

            @ermal:

            Only the nat rules are executed.

            There is one moment with NAT unclear to me. According to pf packet flow diagram (http://homepage.mac.com/quension/pf/flow.png) filtering happen after SNAT. That's why in the rule log we see: if:WAN src:WAN IP -> dst:remote host IP. But when packet rerouted by the policy routing rule reaches OPT-WAN outgoing chain (assuming WAN is down) it's source address appears magically restored to 127.0.0.1. Which block on the diagram do that?

            1 Reply Last reply Reply Quote 0
            • H
              heper
              last edited by

              my "how-to" can be translated in any language … it's only purpose was to return the info i got from ermal to the community ;)

              1 Reply Last reply Reply Quote 0
              • E
                eri--
                last edited by

                rubic, its pfSense customized pf(4), by me. :)

                This functionality can not be done with standard pf(4), at least the version that is used on FreeBSD, without too much tinkering.

                1 Reply Last reply Reply Quote 0
                • R
                  rubic
                  last edited by

                  @ermal:

                  rubic, its pfSense customized pf(4), by me. :)

                  This functionality can not be done with standard pf(4), at least the version that is used on FreeBSD, without too much tinkering.

                  Ok, now I see :) Thank you for your work!
                  translated: http://forum.pfsense.org/index.php/topic,34810.0.html

                  1 Reply Last reply Reply Quote 0
                  • L
                    lnaimi
                    last edited by

                    Ok the guide works with FailOver, but for LoadBalance???? Thanks

                    1 Reply Last reply Reply Quote 0
                    • J
                      juniorghr
                      last edited by

                      Please, where I am testing the sense pf 2.0 is required to enter some sites that require https and when I configure squid with loadbalance the gateway connection changes every time, how can I fix this?

                      Please help.

                      1 Reply Last reply Reply Quote 0
                      • F
                        Frozen_Fire
                        last edited by

                        Please help…Load balancing is ok...but squid is not functioning...please do some ups in the floating rule..
                        Thank you...

                        1 Reply Last reply Reply Quote 0
                        • H
                          heper
                          last edited by

                          @juniorghr

                          well you could create a dedicated gateway group with failover (different tiers) and add a seperate rule  for https traffic to use that gateway group …..

                          or you could enable 'sticky connections' in system  .... but i don't know if that would solve all issues

                          1 Reply Last reply Reply Quote 0
                          • O
                            onkeldave83
                            last edited by

                            Yes, BUT WITH THIS SOLUTION YOU CANT HAVP as parent for SQUID ;)

                            1 Reply Last reply Reply Quote 0
                            • F
                              farrukhndm
                              last edited by

                              I Follow the same above procedure but no success,My browser just working working and working without showing any results.
                              my configurations are.

                              My browser dosn't open any page after given settings ?????..Where I have take mistake. please guide me .

                              ![2011-04-29, 11_55_27.jpg](/public/imported_attachments/1/2011-04-29, 11_55_27.jpg)
                              ![2011-04-29, 11_55_27.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_55_27.jpg_thumb)
                              ![2011-04-29, 11_55_32.jpg](/public/imported_attachments/1/2011-04-29, 11_55_32.jpg)
                              ![2011-04-29, 11_55_32.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_55_32.jpg_thumb)
                              ![2011-04-29, 11_55_42.jpg](/public/imported_attachments/1/2011-04-29, 11_55_42.jpg)
                              ![2011-04-29, 11_55_42.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_55_42.jpg_thumb)
                              ![2011-04-29, 11_55_47.jpg](/public/imported_attachments/1/2011-04-29, 11_55_47.jpg)
                              ![2011-04-29, 11_55_47.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_55_47.jpg_thumb)
                              ![2011-04-29, 11_56_02.jpg](/public/imported_attachments/1/2011-04-29, 11_56_02.jpg)
                              ![2011-04-29, 11_56_02.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_56_02.jpg_thumb)
                              ![2011-04-29, 11_56_10.jpg](/public/imported_attachments/1/2011-04-29, 11_56_10.jpg)
                              ![2011-04-29, 11_56_10.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_56_10.jpg_thumb)
                              ![2011-04-29, 11_56_33.jpg](/public/imported_attachments/1/2011-04-29, 11_56_33.jpg)
                              ![2011-04-29, 11_56_33.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_56_33.jpg_thumb)
                              ![2011-04-29, 11_57_39.jpg](/public/imported_attachments/1/2011-04-29, 11_57_39.jpg)
                              ![2011-04-29, 11_57_39.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_57_39.jpg_thumb)
                              ![2011-04-29, 11_57_49.jpg](/public/imported_attachments/1/2011-04-29, 11_57_49.jpg)
                              ![2011-04-29, 11_57_49.jpg_thumb](/public/imported_attachments/1/2011-04-29, 11_57_49.jpg_thumb)

                              1 Reply Last reply Reply Quote 0
                              • F
                                Frozen_Fire
                                last edited by

                                @ far … your Nat ountbound should be set to "manual"

                                1 Reply Last reply Reply Quote 0
                                • E
                                  eri--
                                  last edited by

                                  You need only loopback interface on squid selected.
                                  Also on LAN the rule with a GatewayPool should not match the port 80/443 tcp which get handled by squid.

                                  1 Reply Last reply Reply Quote 0
                                  • M
                                    mjtbrady
                                    last edited by

                                    Has anyone got failover working on 2.0RC3?  I have been trying to get this working for several days now and and have not been successful.

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.