Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Bypass ssl-bump on squid3-dev

    Scheduled Pinned Locked Moved pfSense Packages
    37 Posts 8 Posters 18.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      webstor
      last edited by

      Microsoft Windows Update is using only one ip? Cannot believe that.

      1 Reply Last reply Reply Quote 0
      • W
        webstor
        last edited by

        For the moment it is the best solution. Of course it would be better, but the acl dstdomain isn't working as it should.

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          What solution? Cannot see any solution here - acl ssl_bypass dst with a single IP is nonsense and not a solution.

          1 Reply Last reply Reply Quote 0
          • W
            webstor
            last edited by

            Then brinng up a solution depending in that Problem. ACL dstdomain wont work with SSL bump with hosts with multiple IP adresses.

            1 Reply Last reply Reply Quote 0
            • D
              doktornotor Banned
              last edited by

              Already brought up a solution. Traffic to these domains should not hit a proxy at all. No other input until this gets answered.

              1 Reply Last reply Reply Quote 0
              • W
                webstor
                last edited by

                Thats not a solution.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  @webstor:

                  Thats not a solution.

                  What's not a solution? You do not MITM OS updates. Period.

                  1 Reply Last reply Reply Quote 0
                  • W
                    webstor
                    last edited by

                    Try it yourself. Maybe you should understand SSL bumping first.

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      Why on earth should I try something known to NOT work by design? Stop directing your Windows Update traffic to the transparent SSL proxy. If you want to serve updates locally, use WSUS server or some of the other enterprise solutions intended for that purpose.

                      1 Reply Last reply Reply Quote 0
                      • W
                        webstor
                        last edited by

                        As mentioned before, not a solution.  ;D

                        1 Reply Last reply Reply Quote 0
                        • S
                          siceff
                          last edited by

                          Hello again !
                          You're right, it's not possible to exclude the Windows update by IP, that's too big… by the way, I've quite the same problem with teamviewer, which is working, but the event viewer is full of schannel error due to this inspection too. Maybe I could place a WSUS server, but as it's not a main site, it's a lot of trouble for a few PCs.

                          As I understand, the other way is to have a proxy for some sites and no proxy for others based on wpad files. But can I do that when pfsense is my single Gateway/router/NAT of the whole network ? I cannot understand how. Or I have to turn to a non-transparent proxy, so I could proxify some site and exclude others based on proxy port...

                          Could you explain me what do you think exactly ?

                          1 Reply Last reply Reply Quote 0
                          • D
                            doktornotor Banned
                            last edited by

                            @siceff:

                            As I understand, the other way is to have a proxy for some sites and no proxy for others based on wpad files. But can I do that when pfsense is my single Gateway/router/NAT of the whole network ? I cannot understand how.

                            I don't understand how's this a problem? See this, e.g.: http://findproxyforurl.com/example-pac-file/

                            1 Reply Last reply Reply Quote 0
                            • marcellocM
                              marcelloc
                              last edited by

                              @webstor:

                              He has to generate a certificate for the required domain when bumping server-side first, it is a wildcard generated for the correct domain and not the ip.

                              I know it is for the site.

                              the question is, in transparent mode, how could squid know without intercepting that connection from 192.168.1.1 to 64.54.10.10 is a request to microsoft windows update?

                              Squid will only know the domain after interception, so acl will take no effect.

                              Also there are some notes about fast and slow acls that not work on this or that squid option.

                              Treinamentos de Elite: http://sys-squad.com

                              Help a community developer! ;D

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.