Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Help!!! SquidGuard barring Installs

    Scheduled Pinned Locked Moved Cache/Proxy
    14 Posts 3 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      Marco Noronha
      last edited by

      Guys, I have a simple question, but I have to solve it:

      I use squid + squid guard with authenticated proxy. In my Squidguard I have a group where the users are directors of the company, and they have full access to any site when they authenticate, perfect, I just added them to the acl user groups and I checked allow in default access. The problem is that when these users will install some program like firefox, chrome, or some other that download and install at the same time, squid blocks because in the installation process the user is not recognized by the application, I think.

      These users access all sites right away, but the installs are barred. Does anyone know how to solve this?

      sry about my english, im a br lover guy

      1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan
        last edited by

        @Marco:

        ….. squid blocks because in the installation process the user is not recognized by the application, I think.

        The installation program runs on their PC, right ?
        So how can "squid + squid guard" (running on pfSEnse) interfere with a process not running on the same device ?

        If you use a proxy setup on each PC and the installer process (you can't control what it does) doesn't use proxy settings on that device (PC), well … I can imagine it will get blocked.

        Or, more basic : users haven't the "Administrator" rights to install whatever on their PC - and thus the problem isn't even pfSense related.

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • M
          Marco Noronha
          last edited by

          @Gertjan:

          @Marco:

          ….. squid blocks because in the installation process the user is not recognized by the application, I think.

          The installation program runs on their PC, right ?
          So how can "squid + squid guard" (running on pfSEnse) interfere with a process not running on the same device ?

          If you use a proxy setup on each PC and the installer process (you can't control what it does) doesn't use proxy settings on that device (PC), well … I can imagine it will get blocked.

          Or, more basic : users haven't the "Administrator" rights to install whatever on their PC - and thus the problem isn't even pfSense related.

          but if I monitor the real time of squid, the address is seen blocked. Remember that these are programs that use an internet for installation.

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            Do you also have these users in other ACLs that are blocked?

            1 Reply Last reply Reply Quote 0
            • M
              Marco Noronha
              last edited by

              @KOM:

              Do you also have these users in other ACLs that are blocked?

              No, my users are all in a single group that has default allow

              1 Reply Last reply Reply Quote 0
              • KOMK
                KOM
                last edited by

                What is the exact error they're getting?

                1 Reply Last reply Reply Quote 0
                • M
                  Marco Noronha
                  last edited by

                  @KOM:

                  What is the exact error they're getting?

                  When I try to install, the application is loading, or depending on the program a connection error. And when I look in the real time log appears: DENIED for the user "-"

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    And the reason for the denial?

                    1 Reply Last reply Reply Quote 0
                    • M
                      Marco Noronha
                      last edited by

                      @KOM:

                      And the reason for the denial?

                      When i try install google chrome…

                      realtime.ong.PNG
                      realtime.ong.PNG_thumb

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        That's an authentication problem, TCP_DENIED 407.  I've read some other people lately with squid problems related to the ssl handshake.

                        1 Reply Last reply Reply Quote 0
                        • M
                          Marco Noronha
                          last edited by

                          @KOM:

                          That's an authentication problem, TCP_DENIED 407.  I've read some other people lately with squid problems related to the ssl handshake.

                          but how squid will identify in which user is a skype.exe installing? It is possible?

                          1 Reply Last reply Reply Quote 0
                          • KOMK
                            KOM
                            last edited by

                            Squid either knows the IP address, or IP address and user/pass depending on whether or not you have any user auth.

                            1 Reply Last reply Reply Quote 0
                            • M
                              Marco Noronha
                              last edited by

                              @KOM:

                              Squid either knows the IP address, or IP address and user/pass depending on whether or not you have any user auth.

                              Interesting. The total permission I gave to users was not by ip, but by users. But if squid can make this association, can you tell me how to solve it?

                              ps: I would not like to have to allow ip

                              1 Reply Last reply Reply Quote 0
                              • KOMK
                                KOM
                                last edited by

                                What version of pfSense are you running?  This might be helpful:

                                http://squid-web-proxy-cache.1019090.n4.nabble.com/TCP-DENIED-407-with-SSL-Sites-but-the-site-is-accessible-td2340748.html

                                I can't be more specific since I don't have user auth for my squid and I've never seen this problem before.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.