Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Https block sgerror only in transparent mode

    Scheduled Pinned Locked Moved Cache/Proxy
    20 Posts 11 Posters 9.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      misant
      last edited by

      @Hanswerner:

      https://example.com blocked but NO REDIRECT:

      Can you open block page with https itself? just type https://YUORIP/sgerror.php

      Check if you disallow numeric URLs, if yes - add your pfSense to exclusion.

      1 Reply Last reply Reply Quote 0
      • H
        Hanswerner
        last edited by

        Opening blockpage itself depends on webconfigurator http or https setting. Both works.
        it doesnt matter if i chose internal or external page.
        The only problem here is the default redirect of the blacklist advertisement filter that redirects to the ip  with a domain cert error instead of fqdn without error ;)
        (this could be managed with the webconfigurator setting)

        the very interesting thing is, that everything is working nice in transparent mode (witch ssl-bump) and gateway setting via dhcp. Everything except some strange cert errors because there is a lack of options for squid to correctly mimik the server cert…
        (for example if www.example.com loads js from www.cd.example.com -> squid is too dump to generate different cert for different connection and so you get cert domain errors)

        1 Reply Last reply Reply Quote 0
        • H
          Hanswerner
          last edited by

          "Do not allow IP-Addresses in URL" doesnt matter… :(

          1 Reply Last reply Reply Quote 0
          • H
            Hanswerner
            last edited by

            End Workaround: I changed squid error page to sgerror.php

            Better the users get blocked message than proxy errors.. but … crap

            1 Reply Last reply Reply Quote 0
            • R
              RoFz
              last edited by

              According to Amos Jeffries, a squid developer/maintainer, it's a browser problem:

              http://www.squid-cache.org/mail-archive/squid-users/201202/0216.html

              1 Reply Last reply Reply Quote 0
              • O
                olivier.dumonexodata.fr
                last edited by

                Hi all.
                Is there any update on this case ?
                I have exactly the same problem with a pfsense version 2.3.2.

                Thanks.
                Regards.
                Olivier.

                1 Reply Last reply Reply Quote 0
                • C
                  chicago_cs
                  last edited by

                  Hi, Me too.

                  Any advice?

                  1 Reply Last reply Reply Quote 0
                  • H
                    heliop100
                    last edited by

                    @Hanswerner:

                    End Workaround: I changed squid error page to sgerror.php

                    Better the users get blocked message than proxy errors.. but … crap

                    Hi,

                    How to change squid error page to sgerror.php?

                    Thanks.

                    1 Reply Last reply Reply Quote 0
                    • B
                      beto0914
                      last edited by

                      I reported this issue as a bug in https://redmine.pfsense.org/issues/6777

                      I hope that the programmers can help us, in my situation, this issue is present in pfsense 2.3.2

                      1 Reply Last reply Reply Quote 0
                      • L
                        LFCavalcanti
                        last edited by

                        Ressurecting this thread…

                        I'm having similar issues, more... even when the external error page is loaded, no CSS on that page is applied.

                        –

                        Luiz Fernando Cavalcanti
                        IT Manager
                        Arriviera Technology Group

                        1 Reply Last reply Reply Quote 0
                        • L
                          LFCavalcanti
                          last edited by

                          After some search, It's a behavior standard in Browsers.

                          See this: https://bugzilla.mozilla.org/show_bug.cgi?id=479880

                          So any page blocked by Squid(+SquidGuard) that is HTTPS will not display the error page, just the generic error message from the browser on Tunnel connection error.

                          –

                          Luiz Fernando Cavalcanti
                          IT Manager
                          Arriviera Technology Group

                          1 Reply Last reply Reply Quote 0
                          • S
                            shyaminayesh
                            last edited by

                            any updates on this ?

                            1 Reply Last reply Reply Quote 0
                            • jimpJ
                              jimp Rebel Alliance Developer Netgate
                              last edited by

                              @shyaminayesh:

                              any updates on this ?

                              No because it is not a bug, it's working in the only way that it can with SSL/TLS.

                              Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

                              Need help fast? Netgate Global Support!

                              Do not Chat/PM for help!

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.