Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Https block sgerror only in transparent mode

    Scheduled Pinned Locked Moved Cache/Proxy
    20 Posts 11 Posters 9.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      misant
      last edited by

      @Hanswerner:

      http://facebook.com -> blocked with sgerror.php

      Is your block page shown with http or https? I mean sgerror.php

      1 Reply Last reply Reply Quote 0
      • H
        Hanswerner
        last edited by

        after i solved that ssl error i get following message from squid:
        could not retrieve hostname from: https://http/*
        so i thing the page is delivered with http and the browser wants to open https://http://sgerror.php….

        I think you can setup this with the webconfigurator setting (System -> Advanced)
        if i cahnge to https webconfigurator i get the same error with https://https/*

        I think the problem is located somwhere how squid reads the request(from squid.log):
        transparent setting: only ip as gateway and nothing else: https://www.facebook.com
        configured as non transparent and setup with wpad or manual: www.facebook.com:443

        my next try will be a setup from scratch to prevent configuration problems because of massive testing

        1 Reply Last reply Reply Quote 0
        • M
          moley2016
          last edited by

          Let me know if you get this sorted.  Sounds like a similar issue to what i'm having.

          https://forum.pfsense.org/index.php?topic=109208.0

          1 Reply Last reply Reply Quote 0
          • H
            Hanswerner
            last edited by

            Ok…
            configured new pfsense in VM.
            everything stays the same. It is impossible to tell squid to redirect correctly.

            NON - Transparent with or without ssl - man in the middle
            http://eample.com blocked and redirect to sgerror.php
            https://example.com blocked but NO REDIRECT:

            same setup only enabling the transparent setting:
            everything works

            i believe its a bug. during my configurations there were so many bugs in reloading config or something like squidgard stops working after setting something complete different...

            1 Reply Last reply Reply Quote 0
            • M
              misant
              last edited by

              @Hanswerner:

              https://example.com blocked but NO REDIRECT:

              Can you open block page with https itself? just type https://YUORIP/sgerror.php

              Check if you disallow numeric URLs, if yes - add your pfSense to exclusion.

              1 Reply Last reply Reply Quote 0
              • H
                Hanswerner
                last edited by

                Opening blockpage itself depends on webconfigurator http or https setting. Both works.
                it doesnt matter if i chose internal or external page.
                The only problem here is the default redirect of the blacklist advertisement filter that redirects to the ip  with a domain cert error instead of fqdn without error ;)
                (this could be managed with the webconfigurator setting)

                the very interesting thing is, that everything is working nice in transparent mode (witch ssl-bump) and gateway setting via dhcp. Everything except some strange cert errors because there is a lack of options for squid to correctly mimik the server cert…
                (for example if www.example.com loads js from www.cd.example.com -> squid is too dump to generate different cert for different connection and so you get cert domain errors)

                1 Reply Last reply Reply Quote 0
                • H
                  Hanswerner
                  last edited by

                  "Do not allow IP-Addresses in URL" doesnt matter… :(

                  1 Reply Last reply Reply Quote 0
                  • H
                    Hanswerner
                    last edited by

                    End Workaround: I changed squid error page to sgerror.php

                    Better the users get blocked message than proxy errors.. but … crap

                    1 Reply Last reply Reply Quote 0
                    • R
                      RoFz
                      last edited by

                      According to Amos Jeffries, a squid developer/maintainer, it's a browser problem:

                      http://www.squid-cache.org/mail-archive/squid-users/201202/0216.html

                      1 Reply Last reply Reply Quote 0
                      • O
                        olivier.dumonexodata.fr
                        last edited by

                        Hi all.
                        Is there any update on this case ?
                        I have exactly the same problem with a pfsense version 2.3.2.

                        Thanks.
                        Regards.
                        Olivier.

                        1 Reply Last reply Reply Quote 0
                        • C
                          chicago_cs
                          last edited by

                          Hi, Me too.

                          Any advice?

                          1 Reply Last reply Reply Quote 0
                          • H
                            heliop100
                            last edited by

                            @Hanswerner:

                            End Workaround: I changed squid error page to sgerror.php

                            Better the users get blocked message than proxy errors.. but … crap

                            Hi,

                            How to change squid error page to sgerror.php?

                            Thanks.

                            1 Reply Last reply Reply Quote 0
                            • B
                              beto0914
                              last edited by

                              I reported this issue as a bug in https://redmine.pfsense.org/issues/6777

                              I hope that the programmers can help us, in my situation, this issue is present in pfsense 2.3.2

                              1 Reply Last reply Reply Quote 0
                              • L
                                LFCavalcanti
                                last edited by

                                Ressurecting this thread…

                                I'm having similar issues, more... even when the external error page is loaded, no CSS on that page is applied.

                                –

                                Luiz Fernando Cavalcanti
                                IT Manager
                                Arriviera Technology Group

                                1 Reply Last reply Reply Quote 0
                                • L
                                  LFCavalcanti
                                  last edited by

                                  After some search, It's a behavior standard in Browsers.

                                  See this: https://bugzilla.mozilla.org/show_bug.cgi?id=479880

                                  So any page blocked by Squid(+SquidGuard) that is HTTPS will not display the error page, just the generic error message from the browser on Tunnel connection error.

                                  –

                                  Luiz Fernando Cavalcanti
                                  IT Manager
                                  Arriviera Technology Group

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    shyaminayesh
                                    last edited by

                                    any updates on this ?

                                    1 Reply Last reply Reply Quote 0
                                    • jimpJ
                                      jimp Rebel Alliance Developer Netgate
                                      last edited by

                                      @shyaminayesh:

                                      any updates on this ?

                                      No because it is not a bug, it's working in the only way that it can with SSL/TLS.

                                      Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                                      Need help fast? Netgate Global Support!

                                      Do not Chat/PM for help!

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.