Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Ssl filtering transparent and non-transparent

    Scheduled Pinned Locked Moved Bounties
    63 Posts 11 Posters 40.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • marcellocM
      marcelloc
      last edited by

      Yes, full content filtering. On squid3, full URL filtering with squidguard.  dansguardian will need more work as the source does not has a full working config.

      Treinamentos de Elite: http://sys-squad.com

      Help a community developer! ;D

      1 Reply Last reply Reply Quote 0
      • W
        wheelz
        last edited by

        So yes, then I'd put up $100.  How much are you looking for to get dansguardian set up with it?

        1 Reply Last reply Reply Quote 0
        • W
          wheelz
          last edited by

          Would this be easily adapted to IMspector as well?

          1 Reply Last reply Reply Quote 0
          • marcellocM
            marcelloc
            last edited by

            @wheelz:

            Would this be easily adapted to IMspector as well?

            Imspector has already his working mitm function for jabber/ssl.

            Treinamentos de Elite: http://sys-squad.com

            Help a community developer! ;D

            1 Reply Last reply Reply Quote 0
            • marcellocM
              marcelloc
              last edited by

              @wheelz:

              So yes, then I'd put up $100.  How much are you looking for to get dansguardian set up with it?

              First I need to get it working. The bounty could help me to speed up the process.

              Treinamentos de Elite: http://sys-squad.com

              Help a community developer! ;D

              1 Reply Last reply Reply Quote 0
              • W
                wheelz
                last edited by

                @marcelloc:

                @wheelz:

                So yes, then I'd put up $100.  How much are you looking for to get dansguardian set up with it?

                First I need to get it working. The bounty could help me to speed up the process.

                Oh, I haven't done a bounty before.  I wasn't sure if you needed more people to put some money up first or not.  Is the $100 enough to be worth it for you to do it?  If so I can send it to you tomorrow.  If not then would I send to the escrow to see if we get some other people to get it high enough?  I know you already put a lot of work into your packages for free which is great.  I wish I had more to offer but I'm trying to get this set up for home so no company backed funds. :(

                1 Reply Last reply Reply Quote 0
                • marcellocM
                  marcelloc
                  last edited by

                  @wheelz:

                  I wasn't sure if you needed more people to put some money up first or not.  Is the $100 enough to be worth it for you to do it?  If so I can send it to you tomorrow.

                  It will be great if more sysadmin that needs this feature donate a value.
                  I'm not asking for a specific value, but how nice a ssl filtering feature will be on pfsense gui?
                  BTW If you have in mind that this donation is to help on development instead of be sure it will be fixed, you can send it to me.

                  Thanks for your help on it.

                  Treinamentos de Elite: http://sys-squad.com

                  Help a community developer! ;D

                  1 Reply Last reply Reply Quote 0
                  • W
                    wheelz
                    last edited by

                    I asked about an escrow but I guess you have to have the full required amount before they will do an escrow.  However right now we don't have a goal for it.

                    1 Reply Last reply Reply Quote 0
                    • X
                      xbipin
                      last edited by

                      i need this for squid and squidguard, dont require it much but will support development - $25

                      bytheway the current squid in packages is 2.7.9 pkg v.4.3.3 so would this be also upgraded to 3?

                      1 Reply Last reply Reply Quote 0
                      • X
                        xbipin
                        last edited by

                        on behalf of a client add another $25

                        1 Reply Last reply Reply Quote 0
                        • O
                          Oliver_
                          last edited by

                          ssl filtering in a non-transparent network would be nice!
                          but with HAVP or eq. Virus Scanning it would be a awesome!  ;D

                          greetings Oli

                          1 Reply Last reply Reply Quote 0
                          • W
                            wheelz
                            last edited by

                            marcelloc, could you give us a goal amount for this that would prioritize this feature set for you?

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              @wheelz:

                              marcelloc, could you give us a goal amount for this that would prioritize this feature set for you?

                              The package is almost done, I'll ask for package compilation and publish.

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • X
                                xbipin
                                last edited by

                                bytheway, we would need to remove squid 2 and upgrade to squid 3 right?
                                would we still be able to use squid guard?

                                1 Reply Last reply Reply Quote 0
                                • N
                                  Nachtfalke
                                  last edited by

                                  @xbipin:

                                  bytheway, we would need to remove squid 2 and upgrade to squid 3 right?
                                  would we still be able to use squid guard?

                                  Yes!

                                  on pfsense 2.0.3 you need to install first squidguard and then squid3
                                  on pfsense 2.1 the package structure is new and you can first install squid3 and then squidguard

                                  1 Reply Last reply Reply Quote 0
                                  • X
                                    xbipin
                                    last edited by

                                    is squid3 and squidguard currently stable compared to squid2 on 2.1 as i only use squid2 with squiguard on it currently

                                    1 Reply Last reply Reply Quote 0
                                    • marcellocM
                                      marcelloc
                                      last edited by

                                      First squid3.3 devel release for pfsense is out.

                                      What I'm sure is not working is antivirus integration via i-cap.
                                      All other features should be working.

                                      on packages I'll describe main changes.

                                      att,
                                      Marcello Coutinho

                                      Treinamentos de Elite: http://sys-squad.com

                                      Help a community developer! ;D

                                      1 Reply Last reply Reply Quote 0
                                      • T
                                        tester_02
                                        last edited by

                                        marcelloc

                                        I am just a home user but I love pfsense and the development community.  I have not done any pfsense donations for a while.  Can I send you a small token for your efforts?

                                        Please PM me with details (paypal?).

                                        1 Reply Last reply Reply Quote 0
                                        • marcellocM
                                          marcelloc
                                          last edited by

                                          @tester_02:

                                          Please PM me with details (paypal?).

                                          Thanks for you interest in donating! ;D

                                          I've sent you a pm

                                          Treinamentos de Elite: http://sys-squad.com

                                          Help a community developer! ;D

                                          1 Reply Last reply Reply Quote 0
                                          • marcellocM
                                            marcelloc
                                            last edited by

                                            Since version 2.1.2 of squid3-dev ssl filtering is working fine on 2.1 without patches and on 2.0.x using squid 3.3.4_1 from my repo.  :)

                                            1368761856.278    210 192.168.0.3 TCP_MISS/200 978 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761856.699    442 192.168.0.3 TCP_MISS/200 19903 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/jso                                                                                 n
                                            1368761856.714    521 192.168.0.3 TCP_MISS/200 905 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761857.121    203 192.168.0.3 TCP_MISS/204 328 GET https://www.google.com.br/gen_204? - PINNED/189.86.41.119 text/html
                                            1368761857.136    219 192.168.0.3 TCP_MISS/200 680 GET https://www.google.com.br/xjs/_/js/k=-im9hrMhEvY.en_US./m=wta/am=wA/r                                                                                 t=j/d=0/sv=1/rs=AItRSTMxcUTKX7_k7F3jagv1ABf8swPrOg - PINNED/189.86.41.119 text/javascript
                                            1368761858.327    632 192.168.0.3 TCP_MISS/200 915 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761859.649   1548 192.168.0.3 TCP_MISS/200 14473 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/jso                                                                                 n
                                            1368761859.661    228 192.168.0.3 TCP_MISS/200 850 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761860.026    220 192.168.0.3 TCP_MISS/204 328 GET https://www.google.com.br/gen_204? - PINNED/189.86.41.119 text/html
                                            1368761860.970    397 192.168.0.3 TCP_MISS/200 851 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761861.121    388 192.168.0.3 TCP_MISS/200 856 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761861.223    311 192.168.0.3 TCP_MISS/200 855 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761861.410    397 192.168.0.3 TCP_MISS/200 860 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/json
                                            1368761862.720   1537 192.168.0.3 TCP_MISS/200 18542 GET https://www.google.com.br/s? - PINNED/189.86.41.119 application/jso                                                                                 n
                                            1368761863.104    222 192.168.0.3 TCP_MISS/204 328 GET https://www.google.com.br/gen_204? - PINNED/189.86.41.119 text/html
                                            1368761865.464    232 192.168.0.3 TCP_MISS/204 328 GET https://www.google.com.br/gen_204? - PINNED/189.86.41.119 text/html
                                            1368761866.209    507 192.168.0.3 TCP_MISS/200 982 POST http://ui.ff.avast.com/urlinfo - HIER_DIRECT/77.234.43.81 applicatio                                                                                 n/octet-stream
                                            1368761866.684    479 192.168.0.3 TCP_MISS/200 982 POST http://ui.ff.avast.com/urlinfo - HIER_DIRECT/77.234.43.81 applicatio   
                                            

                                            Treinamentos de Elite: http://sys-squad.com

                                            Help a community developer! ;D

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.