Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multi-Lan Squid 2.7 Transparent Firewalling

    Scheduled Pinned Locked Moved pfSense Packages
    6 Posts 2 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jitguy
      last edited by

      Sorry if this is obvious…  I have multi-vlan setup.  Firewall rules seem to work fine for keeping guest vlan from HTTP accessing secure lan.  This via allowing !LAN as port 80 destination.

      I'd like to proxy-cache for all VLANs , however when I turn on transparent proxy, guest now has HTTP access to other vlans, apparently bypassing firewall.  Blacklisting the 'secure' vlans doesn't help.

      Not using any special filetering packages.  I'd just like to use squid to cache, and obey firewall rules...

      Any ideas?

      Thanks!

      1 Reply Last reply Reply Quote 0
      • J
        jitguy
        last edited by

        Guess it was kind of obvious.  Had rules to allow certain traffic, and was relying on default deny rule to stop everything else.  This worked fine till Squid opened a port to listen.  Then I needed to explicitly reject traffic I didn't want to allow.

        1 Reply Last reply Reply Quote 0
        • A
          ajuser
          last edited by

          where you deny access squid or firewall rules?
          I'm in the same case, and now deny in squidGuard

          1 Reply Last reply Reply Quote 0
          • J
            jitguy
            last edited by

            Firewall Rule.  Added a reject rule to my PUBLIC tab, source PUBLIC net, destination LAN net, any port.  Seems to work for me.

            1 Reply Last reply Reply Quote 0
            • A
              ajuser
              last edited by

              I have this rule, but still, you can enter webconfigurator.

              1 Reply Last reply Reply Quote 0
              • J
                jitguy
                last edited by

                I replied on your thread.

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.