Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Exceptions in locked categories load without images SOLVED

    Scheduled Pinned Locked Moved Cache/Proxy
    17 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      firewire
      last edited by

      Hello,

      I installed pfsense 2.2 with Squid 3 and Squidguard to make content filtering.
      The proxy is configured in transparent mode, with MITM mode for https sites.
      I added a Target Categories "AllowedSites" containing twitter.com domain.
      I created an ACL Group called "BlockedClients" that blocks all SocialNet; in this group "AllowedSites" category is set to "whitelist" (basically all the social are blocked except Twitter).
      If I try to navigate from "BlockedClients"  group all seems to work, and i open twitter, but the site is like a text site without images (as you can see in the attached image).
      I tried googling the problem but no luck.
      Is there anyone who can help me to understand the type of problem and how to solve it?

      Thanks in advance.
      Selezione_046.png
      Selezione_046.png_thumb

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        This question would be better in the Cache/Proxy forum.

        What you're seeing is cached content from the last time that site was successfully loaded by squid.  You can fix it by going to squid's settings and clicking the Clear Disk Cache NOW button.

        1 Reply Last reply Reply Quote 0
        • F
          firewire
          last edited by

          Unfortunately your tip dont works.
          I've cleared and rebooted pfsense but problems remains.

          I move question in cache/proxy section.

          ThankU

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Try clearing your browser's cache as well.

            1 Reply Last reply Reply Quote 0
            • F
              firewire
              last edited by

              ThankU again

              so  i've performed these tasks:

              1. clear disk cache now
              2. rebooted pfsense
              3. clear cache of Chrome and Firefox
              4. install new browser (opera)

              Result on all browser: problems remains

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                OK, I misunderstood your problem.  Please post some screenshots of your squidGuard ACLs & Target Categories so we can see what you have configured.

                1 Reply Last reply Reply Quote 0
                • F
                  firewire
                  last edited by

                  attached group acl and categories

                  Selezione_048.png
                  Selezione_048.png_thumb
                  Selezione_049.png
                  Selezione_049.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • F
                    firewire
                    last edited by

                    ah
                    common ACL have alla catecories untouched except
                    Dummy = deny
                    Default access [all] = allow

                    (see screenshots)

                    Selezione_050.png
                    Selezione_050.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • KOMK
                      KOM
                      last edited by

                      I do something similar so that our salespeople can get to LinkedIn but not other social media sites.  I set my Target Category to Allow instead of Whitelist.  Try that and maybe it will work better for you.

                      1 Reply Last reply Reply Quote 0
                      • F
                        firewire
                        last edited by

                        modify from "whitelist" to "allow" gives me FORBIDDEN

                        Selezione_052.png_thumb
                        Selezione_052.png

                        1 Reply Last reply Reply Quote 0
                        • KOMK
                          KOM
                          last edited by

                          For ACL 'Gruppo1', can you click the green arrow beside Target Rules List (click here) and look at the list of categories.  Where is your SitiAbilitati Target Category in the list?  It should be at the top.  See my image for an example.  To be clear, I named my target category Whitelist.  I also notice that you are using a schedule.  Make sure that you don't have it backwards, where it blocks things that you expect to be open based on time of day.

                          sg.png
                          sg.png_thumb

                          1 Reply Last reply Reply Quote 0
                          • F
                            firewire
                            last edited by

                            I have disabled time restictions with no success

                            attached order of categories

                            Selezione_054.png
                            Selezione_054.png_thumb

                            1 Reply Last reply Reply Quote 0
                            • KOMK
                              KOM
                              last edited by

                              Look in the squidguard log and see if that shows anything of interest.

                              1 Reply Last reply Reply Quote 0
                              • F
                                firewire
                                last edited by

                                SOLVED

                                twitter use pbs.twimg.com wherer it put images and so on (cfr https://twittercommunity.com/t/what-is-this-pbs-twimg-etc/10119)
                                whitelisting only twitter.com it is not sufficient
                                i've added also twimg.com and load is correct.

                                ThankU for your support

                                PS
                                I've another problem,  I have to open a new topic?

                                thankU again

                                1 Reply Last reply Reply Quote 0
                                • KOMK
                                  KOM
                                  last edited by

                                  I've another problem,  I have to open a new topic?

                                  Glad to hear you figured it out.  How did you do it?

                                  Yes, please start a new topic if it isn't directly related to this specific problem.

                                  1 Reply Last reply Reply Quote 0
                                  • F
                                    firewire
                                    last edited by

                                    surfing with chrome at bottom you can see url surfed
                                    i've noted this url, googled and understand what was
                                    in squidguard log pbs.twimg.com was blocked
                                    et voilà:)

                                    1 Reply Last reply Reply Quote 0
                                    • KOMK
                                      KOM
                                      last edited by

                                      Yeah, I should have mentioned checking squidguard's log much sooner than I did.

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.