Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help on how to get a second pfsense box setup as main squid transparent proxy

    Scheduled Pinned Locked Moved pfSense Packages
    8 Posts 4 Posters 2.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      luke240778
      last edited by

      Ive had some help with this on the past from a few users, marcelloc being the main one who assisted alot, i unfortunately havent managed to get it working the way i want, so i am hoping i can get some kinda step by step assistance. What i have and what i want is the following:

      Main pfSense box has squid running in transparent mode.. i am trying to cache as much as possible to save bandwidth.. but the drive on this box is too small.

      Want to build a second pfSense box (virtual actually), with only WAN interface, and have all squid cache, logs and everything that goes along with it running and saving to this box.

      I have tried and gotten nowhere, from past assistence from marcelloc i created the second box and on the first box's squid settings i added this second box's IP into the Upstream proxy.. but from leaving it for a while i wasnt seeing any cache or Lightsquid logs being created on this second box.

      Would also like to transfer all cache and Lightsquid logs from the first box to the second, so i can continue on with the cache and logs even know is a new box.
      Thanks in advance..

      1 Reply Last reply Reply Quote 0
      • V
        vbentley
        last edited by

        This might not be the answer that you would like, for security appliances I think the installation should be kept simple. Just get a bigger hard drive or an additional drive mounted on /var/squid. An external USB hard drive could be used and if you don't want to buy one new you can find used drives cheap enough on eBay.

        Trademark Attribution and Credit
        pfSense® and pfSense Certified® are registered trademarks of Electric Sheep Fencing, LLC in the United States and other countries.

        1 Reply Last reply Reply Quote 0
        • L
          luke240778
          last edited by

          Correct, not the needed answer.  What you said to do i have also asked about in the past and was told that adding another hard drive to handle cache was not a good idea.

          What i mentioned needing help on in my original post, was something that was told to me was a good way to do it, so i am going with that.

          Anyone able to assist please?

          1 Reply Last reply Reply Quote 0
          • L
            luke240778
            last edited by

            no one knows how to do this?

            1 Reply Last reply Reply Quote 0
            • M
              Metu69salemi
              last edited by

              Maybe commercial support can do this

              1 Reply Last reply Reply Quote 0
              • jimpJ
                jimp Rebel Alliance Developer Netgate
                last edited by

                A few things you need:

                1. External squid proxy must be on a different interface than the users of the proxy
                2. Port forward rule on the LAN interface, set to match from the LAN subnet to any on port 80, redirecting to the squid proxy server

                … actually, that's it. If you have that, it should work.

                Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                Need help fast? Netgate Global Support!

                Do not Chat/PM for help!

                1 Reply Last reply Reply Quote 0
                • L
                  luke240778
                  last edited by

                  Hey Jimp, thanks for the reply.. as i have everything running on a ESXi server, i can do this just by adding a virtual interface quite easy, so with that, it should work fine then?

                  1 Reply Last reply Reply Quote 0
                  • jimpJ
                    jimp Rebel Alliance Developer Netgate
                    last edited by

                    it should, yes, make a new interface, a proxy vm, and a vswitch to connect them (on their own subnet) and then you should be able to make that work.

                    Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                    Need help fast? Netgate Global Support!

                    Do not Chat/PM for help!

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.