Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid SSL filtering cause Dropbox, Live Mail, etc. cant establish connection

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    2 Posts 2 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • H
      ha11oga11o
      last edited by

      hello all,

      finally i manage to configure everything work on 2.2-RELEASE (amd64). I installed squid3 3.4.10_2 pkg 0.2.6, squidGuard 1.4_7 pkg v.1.9.10 and all is working fine.

      Mine problem is, when i configure HTTPS/SSL interception it works fine. Eicar file on HTTPS in blocked and such. I imported certificate to my browser, all si fine…. but!

      Any other possible HTTPS which does not go via browser is blocked,.. like Dropbox, Live Mail, Google Drive, even some games launchers, Steam also,... probably everything.

      So now, as ima n00b, can someone answer questions;

      1. Is it possible to configure filtering but not to use certificate on every new freaking mobile, tablet, laptop, PC... etc, because of guests. I mean, is it even possible to make it work like that at all?

      2. Will squid now cache HTTPS traffic now? Will that TCP/HIT be more than tiny 4-8% now?

      3. Does anyone have any positive experience with Cache Dynamic Content? Is it even working? Is there anything to do/prepare prior just to enable it?

      Many thnx in advance!

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        1.  Yes!

        WPAD Autoconfigure for Squid

        2.  Squid will cache HTTP or HTTPS.  Your hit ratio depend entirely on the sites that you visit and the frequency at which you visit them.4-8% is around the same ratio I get.

        3.  I have had limited success with dynamic content.  Nobody seems to have a config that works well.  All the various wikis etc say the same thing: play with it, see what happens, YMMV, but nothing concrete.  That combined with the poor hit ratio has me thinking about deploying Squid just as a base for SquidGuard filtering.

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.