Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Transparent Squid-squidquard and https

    pfSense Packages
    3
    7
    2.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      apant
      last edited by

      Hi!

      I use transparent squid with squidguard and I wonder if there is a way to catch https requests also. For example I block the facebook.com domain but if users write https://www.facebook.com they pass the rule. Is there any way to block https too transparently?

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by

        It could not easy be done as I read in some other forum posts. You have to copy certificates on the squid and this breaks some RFCs.

        Perhaps you should search the forum for better explaination in other threads or find a way to deploay the proxy server address to your clients browsers (GPO, WPAD)

        1 Reply Last reply Reply Quote 0
        • A
          AS
          last edited by

          I cant even get transparent squid working with HTTP web traffic could you help?

          1 Reply Last reply Reply Quote 0
          • N
            Nachtfalke
            last edited by

            post screenshots of your squid config, please.

            1 Reply Last reply Reply Quote 0
            • A
              AS
              last edited by

              I have attached my squid configuration, but ignore the 'Wireless' interface as it does not work in my VM

              proxy1.png
              proxy1.png_thumb

              1 Reply Last reply Reply Quote 0
              • N
                Nachtfalke
                last edited by

                The configuration is ok.
                So every traffic which passes LAN to somewhere else and using port 80 (http) is using the proxy.

                You can verify this when you look ath the logs (access.log) in

                /var/squid/log

                Connect to the pfsense cosole and use:

                tail -F /var/squd/log/access.log
                

                and then browse a webpage like google.com. Then you will see that squid is working.

                1 Reply Last reply Reply Quote 0
                • A
                  AS
                  last edited by

                  Thanks for you help its working again now,

                  Is there anything I can help you with ?
                  AS.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.