Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Manual Outbound NAT for CARP IPs and Squid

    Scheduled Pinned Locked Moved NAT
    3 Posts 2 Posters 1.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      wheelz
      last edited by

      I tried to follow this guide on pfsense 2.1 release:  http://forum.pfsense.org/index.php?topic=60977.0 to get my Squid proxy to not drop connections during a CARP failover.  The biggest difference in my config is that I don't have a second ISP yet.  I also found this thread which is pretty much what I am experiencing (still only one ISP though):  http://forum.pfsense.org/index.php/topic,57999.msg310203.html#msg310203.

      I have all the default NAT rules including the loopback rule and I added the web rule in the first link.  However every time I enable manual outbound NAT I can no longer get out to the internet.  I'm guessing there is something basic I am missing.  Is there anyone that can fill me in?

      1 Reply Last reply Reply Quote 0
      • W Offline
        wheelz
        last edited by

        Sill no luck… Anyone have any ideas?

        1 Reply Last reply Reply Quote 0
        • jimpJ Offline
          jimp Rebel Alliance Developer Netgate
          last edited by

          What you're after won't work. The connections go through squid, not NAT, so no amount of NAT will help that.

          The proxy process on the two nodes are separate. AFAIK squid doesn't have any kind of a multi-node sync for the connection/cache, only settings.

          Unless somehow the squid proxy processes could share data about ongoing connections in a clustered fashion, that isn't going to work no matter what you have set in pfSense.

          Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

          Need help fast? Netgate Global Support!

          Do not Chat/PM for help!

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.