Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Web proxy question. Iam a proxy noob.

    Scheduled Pinned Locked Moved pfSense Packages
    17 Posts 6 Posters 5.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      If you want a content analyzer, then you can try dansguardian together with squid.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • K
        kira
        last edited by

        From: marcelloc

        _"Just note that transparent proxy does not filter https.

        This way if you block for example www.facebook.com a simple https://www.facebook.com will do the job."_

        @marcelloc

        will Dansguardian be able to block https ? for example https://www.facebook.com

        is there any link on how to configure Dansguardian?

        thanks in advance :)

        1 Reply Last reply Reply Quote 0
        • marcellocM
          marcelloc
          last edited by

          Https url can be blocked using squid,squidguard or dansguardian.

          The first step is to configure proxy on client's browser or WPAD on network.

          Dansguardian default config is applied on package install. You need to configure daemon tab and access lists to get it working. There is also a link to a dansguardian wiki that can you understanding how it works.

          Treinamentos de Elite: http://sys-squad.com

          Help a community developer! ;D

          1 Reply Last reply Reply Quote 0
          • K
            kira
            last edited by

            @Marcelloc

            I have successfully blocked https://facebook and other unwanted sites. only defined url are permitted. But by using proxy settings in browser, it also blocked FTP protocol. how do i configure that to allow my LAN users be able to access local FTP?

            Thanks alot !  ;D

            1 Reply Last reply Reply Quote 0
            • marcellocM
              marcelloc
              last edited by

              You can include exclude range in proxy settings.

              On firefox default option is no proxy for: localhost,127.0.0.1,192.168.0.0/24

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • K
                kira
                last edited by

                Well that worked marcelloc thanks alot. :)

                Now Is there anyway to set the users browser( Guest internet user) that there will be no internet connection at all if they will not use the defined proxy settings? although i have already setup the WPAD, for my guest users they can still alter the settings not to use proxy.

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  Yes you can do it via group policy on Windows or denying access on firewall to internet on dhcp ip range.

                  The second way will enable access only for users using proxy.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • S
                    sully
                    last edited by

                    While I am no linux nor proxy guru, I have set my network up pretty well, and actually for the very same reasons as the OP, to protect my kids from "accidentily" being exposed to the more adult side of the net.

                    The first thing I did was to define a set of IP addresses that would be dedicated to machines that would have no filtering effects. I used the dhcp server service to do this. I declared a set of static dhcp mappings, matched via MAC address. So in my case, the first 20 were reserved. I then gave a 10 address buffer for actual dhcp "guests", from 21 to 30. And finally, I set up my kids addresses above that. I did map those as well.

                    Next, I installed squid. I enabled transparent proxy. I set the proxy to exclude addresses 1-20.

                    Next I installed squidguard. I create one ACL, which encompasses the entire subnet, addresses 1-254. So, all computers fall within this ACL except those excluded from squid itself. I set the default rule to deny.

                    Then, I created my target categories, or whitelists. I segregated them out, creating a disney and starwars category individually, etc. I have one for java and other such stuff needed for some of the kids games.

                    In order to find what was being blocked by the rules, I enabled logging on the ACL rule. I would load a page, see what displayed, and examine what the logs said. It took a bit, but was well worth it. Now I have a pretty good list of websites they can visit, and I really don't have to worry about much. I haven't played with HTTPS yet, but would imagine, since my kids don't need it, I could create a deny category for global HTTPS or change thier PC, although some of my goal is also to keep the guests IPODs from accessing everything as well without me approving it.

                    I was also using captive portal, with MAC pass-throughs so that any guest client would have to ask for password, but figured the restricted nature of squidguard would work just as well.

                    I did install lightsquid, which is very neat. I was using shallas blacklist at one time, but really found that I don't need it, since I know what sites I want them to visit. If they need to do homework or soemthing of the sort, then they do it on a computer that is visible to everyone (they each have thier own computer). It works really well. I can't say that my pfsense box is really any faster than my normal dlink router, but it sure gives a lot more flexibility and control!

                    1 Reply Last reply Reply Quote 0
                    • K
                      kira
                      last edited by

                      Hey Marcelloc,

                      URL Filtering works smoothly on HTTP/HTTPS. but as things go on, i cant seem to work out on how to enable captive portal, although it is enabled in the services. Is it possible to use this or not anymore? It only works out for me if im not using the proxy settings (transparent mode)

                      Thank you so much in advance! :)

                      1 Reply Last reply Reply Quote 0
                      • marcellocM
                        marcelloc
                        last edited by

                        kira,

                        Take a look on this thread.

                        http://forum.pfsense.org/index.php/topic,46817.msg245830.html#msg245830

                        Treinamentos de Elite: http://sys-squad.com

                        Help a community developer! ;D

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.