Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid 3 - Reverse Proxy

    Scheduled Pinned Locked Moved pfSense Packages
    15 Posts 3 Posters 10.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      "The connection is reseted" is the squid3 message for no rule match.

      The default fqdn is the full dns name instead of domain name.

      Take a screenshot with a sample config. Maybe it will be easier to help.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • Q
        qwaven
        last edited by

        Thanks for your help.

        I've added some photo's (4 of them) with sample entries.

        Where domain.com is my primary domain, and mysite.domain.com would be the address I am trying to use and point to a specific internal server.

        I do have another NAT rule on a different external port which works fine when by-passing the proxy.

        Thanks for your help!

        Cheers.

        reserse_proxy_general.JPG
        reserse_proxy_general.JPG_thumb
        reserse_proxy_mappings.JPG
        reserse_proxy_mappings.JPG_thumb
        reserse_proxy_web_servers.JPG
        reserse_proxy_web_servers.JPG_thumb
        reverse_proxy_firewall_rule.JPG
        reverse_proxy_firewall_rule.JPG_thumb

        1 Reply Last reply Reply Quote 0
        • Q
          qwaven
          last edited by

          So after looking at my own screenshots I tried one more thing.

          I unchecked "reset unauthorized connections" and I now see more info. I believe it is something with Squid blocking the connection?

          
          The following error was encountered while trying to retrieve the URL: http://mysite.domain.com/
          
              Access Denied.
          
          Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect.
          
          Your cache administrator is admin@domain.com.
          
          

          Would you happen to know what option would effect "access"?

          Thanks!

          1 Reply Last reply Reply Quote 0
          • marcellocM
            marcelloc
            last edited by

            Change external fqdn to mysite.domain.com and check squid realtime tab / error logs.

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • Q
              qwaven
              last edited by

              Thanks for your response.

              I had already tried setting FQDM to mysite.domain.com ; tried it again and its still not working.

              I'm not sure where to see the live logs, under SARG I see this:

              2012-07-04 13:57 xxx.xxx.xxx.xxx - GET mysite.domain.com

              I'm wondering if I use mysite.domain.com does that mean I cannot have more than one domain (website) behind the proxy?

              Thanks!

              1 Reply Last reply Reply Quote 0
              • Q
                qwaven
                last edited by

                Hi again,

                Thanks for your help.

                I've stumbled upon Mod Security package which I think will better meet my needs. It seems to be working with my setup.

                Thanks again. If you have any comments (should I not use this?) or something please let me know.

                Cheers

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  @qwaven:

                  I've stumbled upon Mod Security package which I think will better meet my needs. It seems to be working with my setup.

                  I'm doind new package gui for modsecurity  :D

                  It's almost done, maybe this week.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • Q
                    qwaven
                    last edited by

                    Cool I'd be happy to try the new one out.

                    Thanks for your help.

                    Cheers. :)

                    1 Reply Last reply Reply Quote 0
                    • Y
                      yon
                      last edited by

                      Hi, I am new use the Squid 3. I want to do like www.facebook.com.sixxs.org Reverse Proxy service. How I do it? Could you help me?!

                      If you are interested in free peering for clearnet and dn42,contact me !

                      1 Reply Last reply Reply Quote 0
                      • Q
                        qwaven
                        last edited by

                        Hey marcelloc,

                        Been using your mod_security package and its still working great! Curious about the functionality. My understanding is that Mod_Security is supposed to be an "application firewall/IPS" for web servers… is this still the case or is this solely running in proxy only mode?

                        If its able to do the firewall bit, will the new package you're working on including customizations for this? (or how does one customize rules)

                        Thoughts or input?

                        Thanks for all your hard work! Very much appreciated. :)

                        Update: Figure I'm supposed to edit / add code to the bottom "custom mod security rules" and when I put one from the mod security site to change what my web server is reported as it does not seem to apply or nmap is able to still figure it out 100% correctly?

                        Thanks

                        1 Reply Last reply Reply Quote 0
                        • marcellocM
                          marcelloc
                          last edited by

                          @qwaven:

                          Been using your mod_security package and its still working great!

                          This is not my package, I'm just improving an existing package  :)

                          @qwaven:

                          Curious about the functionality. My understanding is that Mod_Security is supposed to be an "application firewall/IPS" for web servers… is this still the case or is this solely running in proxy only mode?

                          If I'm not wrong modsecurity rules on current package are too old, so just some features are working

                          @qwaven:

                          If its able to do the firewall bit, will the new package you're working on including customizations for this? (or how does one customize rules)

                          New version will have a lot of new modsecurity_options, updated rules and rules customization

                          Treinamentos de Elite: http://sys-squad.com

                          Help a community developer! ;D

                          1 Reply Last reply Reply Quote 0
                          • Q
                            qwaven
                            last edited by

                            haha whoops… well thanks to the creator then! ;)

                            I'll hold off playing with this older package and eagerly wait for your new one. Sounds like it will be quite nice! :)

                            Will it be seen as an update or a totally new package?

                            Thanks again.

                            Cheers!

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              @qwaven:

                              Will it be seen as an update or a totally new package?

                              Maybe as an update, but config will change a lot, save your config on a txt and/or backup file

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • Q
                                qwaven
                                last edited by

                                awesome thanks I'll look forward to it.

                                Cheers!

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.