• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Dansguardian package for 2.0

Scheduled Pinned Locked Moved pfSense Packages
492 Posts 51 Posters 478.3k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dig1234
    last edited by May 10, 2012, 4:43 PM

    Is there any way I could get "captive portal" style authentication with dansguardian either through the built-in pfsense captive portal or something else? Basically I'm looking for forms based authentication.

    1 Reply Last reply Reply Quote 0
    • F
      FiscoKid
      last edited by May 10, 2012, 6:57 PM May 10, 2012, 6:12 PM

      The content scanner timeout should read 60 seconds on the DansGuardian config page. Instead the field changes to the icapserver settings. The error I received was that Dans Guardian could not understand the config file.

      1 Reply Last reply Reply Quote 0
      • A
        abnz
        last edited by May 16, 2012, 7:44 AM

        The startup problem is solved for me. Dans Guardian now starts on reboot. Thanks.

        1 Reply Last reply Reply Quote 0
        • A
          asterix
          last edited by May 24, 2012, 1:51 AM May 24, 2012, 1:45 AM

          Is there a doc that explains step by step how to configure Dansguardian? I am looking to replace SquidGuard (which works fine) with Dansguardian.
          I have Snort, HAVP, Squid (null config) and SquidGuard installed.

          1 Reply Last reply Reply Quote 0
          • R
            rjcrowder
            last edited by May 24, 2012, 2:00 AM

            @asterix:

            Is there a doc that explains step by step how to configure Dansguardian? I am looking to replace SquidGuard (which works fine) with Dansguardian.
            I have Snort, HAVP, Squid (null config) and SquidGuard installed.

            Check out this thread http://forum.pfsense.org/index.php/topic,47856.0.html

            1 Reply Last reply Reply Quote 0
            • A
              asterix
              last edited by May 25, 2012, 12:24 AM

              Thank you !!!!!!

              1 Reply Last reply Reply Quote 0
              • F
                fiftyheight
                last edited by Jul 9, 2012, 9:59 AM

                hi all
                I have a bug here:

                in access list, when I am in URL tab, and then I click on Content tab, it goes to Extension tab

                Can someone reproduced this ?

                bye
                Julien

                1 Reply Last reply Reply Quote 0
                • M
                  marcelloc
                  last edited by Jul 9, 2012, 1:35 PM

                  @fiftyheight:

                  in access list, when I am in URL tab, and then I click on Content tab, it goes to Extension tab

                  Thank's for the feedback Julien

                  It's fixed now.
                  To apply this patch, just reinstall the package or apply the changes to dansguardian_url_acl.xml

                  https://github.com/bsdperimeter/pfsense-packages/commit/5e02cb482cd5bc25eaac17e7af33c4039390ed33

                  att,
                  Marcello Coutinho

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • F
                    fiftyheight
                    last edited by Jul 9, 2012, 1:47 PM

                    thank's Marcello for you're quick response, it's fixed after reinstalling the package

                    1 Reply Last reply Reply Quote 0
                    • M
                      marcelloc
                      last edited by Jul 9, 2012, 3:29 PM

                      version 0.1.5.4 of dansguardian package is out

                      Changes:

                      • fix content xml call in dansguardian_url_acl.xml file

                      • Includes exceptioniplist missing field on ip tab.

                      att,
                      Marcello Coutinho

                      Treinamentos de Elite: http://sys-squad.com

                      Help a community developer! ;D

                      1 Reply Last reply Reply Quote 0
                      • P
                        pman860507
                        last edited by Jul 10, 2012, 1:25 PM Jul 10, 2012, 4:19 AM

                        Maybe i missed out on all of this, but how do you access the logs created by Dansguardian.  Also the funny thing is clicking reply showed up as pornographic.  :o

                        Thanks.

                        Again i surprise myself. Figured it all out.

                        1 Reply Last reply Reply Quote 0
                        • M
                          marcelloc
                          last edited by Jul 10, 2012, 3:43 PM

                          @pman860507:

                          Maybe i missed out on all of this, but how do you access the logs created by Dansguardian.

                          using console/ssh, exec tail -f /var/log/dansguardian/access.log

                          @pman860507:

                          Also the funny thing is clicking reply showed up as pornographic.  :o

                          Just whitelist it  ;)

                          Treinamentos de Elite: http://sys-squad.com

                          Help a community developer! ;D

                          1 Reply Last reply Reply Quote 0
                          • B
                            broncoBrad
                            last edited by Jul 10, 2012, 10:34 PM

                            I'm very new to proxies and running content filtering via servers, but I want to try. Can someone please tell me step-by-step (sorry for needing the newbie run down) how to set up squid + squidguard + dansguardian? (32-bit system)

                            From what I've read, squidguard is more customizable/configurable as far as ACLs (with respect to users, subnets, etc), but I really want content filtering instead of just URL filtering.

                            Thanks in advance!

                            1 Reply Last reply Reply Quote 0
                            • M
                              marcelloc
                              last edited by Jul 10, 2012, 10:57 PM

                              test dansguardian + squid packages first.

                              Dansguardian default install creates almost 90% of default configuration, you will get a running filter with few steps:

                              • Install squid2, enable service on loopback port 3128)

                              • Install dansguardian package, enable service on port 8080

                              • Create a firewall rule on lan to enable access to lan address port 8080

                              • configure client proxy to use dansguardian ip/port

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • B
                                broncoBrad
                                last edited by Jul 11, 2012, 2:51 AM

                                Thanks for the quick response. If I have two NICs (subnets) one for the adults and one for the kids, I read with the squidguard that it's very easy to make different blacklists per subnet or user. How easy is that to do with dansguardian? Also, would I need to make a firewall rule on each NIC allowing access to LAN port 8080?

                                Now the really dumb questions… where do I get the dansguardian package? When you say configure client proxy is that the browser on all users computers?? I don't want to have to manually adjust settings on all computers.

                                Thanks again!

                                1 Reply Last reply Reply Quote 0
                                • M
                                  marcelloc
                                  last edited by Jul 11, 2012, 6:14 AM

                                  @broncoBrad:

                                  How easy is that to do with dansguardian?

                                  Just create groups based on ip addresses/subnets and select ip based auth

                                  @broncoBrad:

                                  Also, would I need to make a firewall rule on each NIC allowing access to LAN port 8080?

                                  Yes.

                                  @broncoBrad:

                                  where do I get the dansguardian package?

                                  just go on system -> packages and install it.

                                  @broncoBrad:

                                  When you say configure client proxy is that the browser on all users computers?? I don't want to have to manually adjust settings on all computers.

                                  Transparent proxy can only filter http but not https.

                                  You can configure it using proxy wpad/pac settings on dns/dhcp

                                  Treinamentos de Elite: http://sys-squad.com

                                  Help a community developer! ;D

                                  1 Reply Last reply Reply Quote 0
                                  • E
                                    elemay
                                    last edited by Jul 12, 2012, 11:22 AM

                                    @marcelloc:

                                    Transparent proxy can only filter http but not https.

                                    is the ssl stuff already working?

                                    thanks

                                    1 Reply Last reply Reply Quote 0
                                    • M
                                      marcelloc
                                      last edited by Jul 12, 2012, 2:15 PM

                                      @elemay:

                                      is the ssl stuff already working?

                                      No, we are still on the same point. Dansguardian tries to intercept but client rejects it's certificate.

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • J
                                        jai23155
                                        last edited by Aug 1, 2012, 1:33 PM

                                        i have installed Dansguardian but its not showing up in services or anywhere else apart from installed packages. i am using latest pfsense. any idea? thanks

                                        1 Reply Last reply Reply Quote 0
                                        • M
                                          marcelloc
                                          last edited by Aug 1, 2012, 2:12 PM

                                          @jai23155:

                                          any idea?

                                          If its not on services-> dansguardian, try to reinstall it.

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received