Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Facebook problem with squid

    Scheduled Pinned Locked Moved Cache/Proxy
    16 Posts 5 Posters 4.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chiar
      last edited by

      hello, i've just installed pfsense with squid + squidguard, and all it's ok. I've a problem with facebook, i can't load the site if i use the proxy. the domain is in white list, i can ping facebook.com, i can do a traceroute (both from pc or from pfsense), but via web, squid return me: error (65) no route to host with the ipv6 of facebook, or some times (60) operation time out.

      the browser stay in waiting for www.facebook.com mode.

      Can anyone help me?

      Thanks.

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        Go to Services - Squid Proxy Server - General.  Find Resolve DNS IPv4 First and check it, then Save.

        1 Reply Last reply Reply Quote 0
        • C
          chiar
          last edited by

          it's already checked

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Are you actually running IPv6 on your network?

            1 Reply Last reply Reply Quote 0
            • R
              rfzh1996
              last edited by

              System -> Advanced -> Networking

              You have checked Allow IPv6?

              1 Reply Last reply Reply Quote 0
              • C
                chiar
                last edited by

                @KOM:

                Are you actually running IPv6 on your network?

                no, all lan is ipv4, also the internet connection is ipv4

                @rfzh1996:

                System -> Advanced -> Networking

                You have checked Allow IPv6?

                yes and no, i've try with both option, not works.

                the dnslookup return me ipv4 and ipv6 address, for google and facebook sites for exemple, but google works without problem, facebook no.

                1 Reply Last reply Reply Quote 0
                • D
                  doktornotor Banned
                  last edited by

                  Well broken DNS has nothing to do with Squid.

                  1 Reply Last reply Reply Quote 0
                  • C
                    chiar
                    last edited by

                    @doktornotor:

                    Well broken DNS has nothing to do with Squid.

                    the dns is not broken. we have 3 internal dns AD server, and works without problem. without squid facebook is open without problem, with squid no. So i think it's a squid / pfsense problem

                    1 Reply Last reply Reply Quote 0
                    • D
                      doktornotor Banned
                      last edited by

                      If your get AAAA resolved when no IPv6 is available then yes, it is very broken.

                      1 Reply Last reply Reply Quote 0
                      • C
                        chiar
                        last edited by

                        @doktornotor:

                        If your get AAAA resolved when no IPv6 is available then yes, it is very broken.

                        mmmm, if you try to use google dns also return ipv4 and ipv6 address. also if use other dns.

                        BUT, why only with facebook? all sites works, but not facebook.

                        i've just try to do a nslookup from ssh of pfsense, it's return only ipv4! i've try also telnet facebook.com 443, and return me that is connected. it's seems that works all ok, but not via web

                        1 Reply Last reply Reply Quote 0
                        • P
                          papartsharingan
                          last edited by

                          Hi Chiar,

                          We have same problem, but in me i can block all the sites when i use proxy at the client side..

                          but my question here if the client side will change to autodetect setting they can access all. I thought if they change the LAN settings to autodetect they will have no connection?

                          papartsharingan

                          1 Reply Last reply Reply Quote 0
                          • C
                            chiar
                            last edited by

                            @papartsharingan:

                            Hi Chiar,

                            We have same problem, but in me i can block all the sites when i use proxy at the client side..

                            but my question here if the client side will change to autodetect setting they can access all. I thought if they change the LAN settings to autodetect they will have no connection?

                            papartsharingan

                            i can also block websites too. is not a client problem. after some test, i think is a network problem. I've deploy a new vm on my laptop with ad server and all works perfectly. So i need to understand why squid is acting like this.

                            my squid has 1 wan interface, i've disabled all firewall features (with the flag, and adding a rule all open)

                            1 Reply Last reply Reply Quote 0
                            • D
                              doktornotor Banned
                              last edited by

                              Considering we have ZERO information about your network or broken client, we cannot debug any network issues (which are off-topic in this forum section anyway.)

                              @chiar:

                              i've disabled all firewall features (with the flag, and adding a rule all open)

                              Congrats on ruining your firewall. WTF dude!!!  :o ::)

                              1 Reply Last reply Reply Quote 0
                              • C
                                chiar
                                last edited by

                                @doktornotor:

                                Considering we have ZERO information about your network or broken client, we cannot debug any network issues (which are off-topic in this forum section anyway.)

                                @chiar:

                                i've disabled all firewall features (with the flag, and adding a rule all open)

                                Congrats on ruining your firewall. WTF dude!!!  :o ::)

                                pfsense is NOT my firewall, i use it only for squid and squidguard, i've a cisco asa as firewall. pfsense MUST NOT act like a firewall  :)

                                this morning i will try some changes in pfsense network.

                                1 Reply Last reply Reply Quote 0
                                • D
                                  doktornotor Banned
                                  last edited by

                                  pfSense is not a proxy appliance. Note that "disabling" IPv6 on pfSense will do nothing for the clients that get IPv6 RAs etc. from your real router and so will resolve IPv6 first.

                                  This is not a pfSense issue or Squid issue, at all.

                                  1 Reply Last reply Reply Quote 0
                                  • C
                                    chiar
                                    last edited by

                                    @doktornotor:

                                    pfSense is not a proxy appliance. Note that "disabling" IPv6 on pfSense will do nothing for the clients that get IPv6 RAs etc. from your real router and so will resolve IPv6 first.

                                    This is not a pfSense issue or Squid issue, at all.

                                    of course. i've resolve the problem adding a second network interface. So the lan is in my lan segment, and the was is in external network.

                                    now works everything (a bit slow, i'm working on it).

                                    it was a network problem definitely.

                                    Thanks to all!

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.