Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid with LigthSqiud reporting

    Scheduled Pinned Locked Moved Traffic Monitoring
    ligthsquid atatstatic ip
    13 Posts 2 Posters 2.2k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      Modesty @KOM
      last edited by

      @kom said in Squid with LigthSqiud reporting:

      pass Proxy for These Source IP

      Nothing there

      0_1544803314270_1488c3e6-d2af-4604-8243-1ff83cd3ca74-image.png

      Everything can be rebuilt!

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by KOM

        Well, once you answer my question about which mode your proxy is running in and confirmation that the missing users are definitely using the proxy or not, I might be able to come up with other ideas.

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          Modesty @KOM
          last edited by Modesty

          @kom
          Thanks for helping me.

          Transparent HTTP Proxy is enebled

          SSL filtering disabled

          0_1544808798874_6eda7ee3-d2a0-4cf5-853c-5f1b945e33fe-image.png

          0_1544808903555_0353fe58-8ab5-4bab-8e14-02c9fc036ec0-image.png

          I also experience that log dont change:

          0_1544808976231_8d399c2a-8eb4-4379-829f-c3eb63ce8650-image.png

          The Sum Bytes are the same now as for 5 h ago

          Everything can be rebuilt!

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            If you look at the squid access.log yourself, do you see any entries from IP addresses that are supposed to be in the report but aren't?

            M 1 Reply Last reply Reply Quote 1
            • M Offline
              Modesty @KOM
              last edited by

              @kom
              I have a static ip on 192.168.0.50 that is not showing in log (a online smart house controller).

              DHCP range is from 192.168.0.100 -.200

              I only find log entries from DHCP range, no ip's under .100

              So i guess that range outide DHCP is not catched.

              Everything can be rebuilt!

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                Which means they aren't using the proxy. Is it possible that those devices are using a different gateway? pfSense can only transparently capture traffic that passes through it.

                M 1 Reply Last reply Reply Quote 1
                • M Offline
                  Modesty @KOM
                  last edited by

                  Thanks for answer KOM.

                  Static IP use the same gateway, and I have only one defined in System->Routing

                  My conclusion so far is that IP's outside DHCP range are not captured (and static IP must be outside DHCP range).

                  I think this is something that is not the intension for makers of Squid, so there must be an answer someware. The idea to monitor traffic and not messure static IP is not best practise :

                  Anybody who have a indea for next step in this riddle?

                  Everything can be rebuilt!

                  1 Reply Last reply Reply Quote 0
                  • M Offline
                    Modesty
                    last edited by

                    And now its fun
                    I switched on a pc with static IP and guess....:

                    0_1544870306406_0e0ad24c-2c44-4e81-8c4e-82a97e62df99-image.png

                    .16 ip is in log. and .16 is static

                    I have many static, this is the only one in 3 days...

                    Any new ideas?

                    Everything can be rebuilt!

                    1 Reply Last reply Reply Quote 0
                    • KOMK Offline
                      KOM
                      last edited by

                      Nope. Borked configuration maybe? I stopped using transparent years ago and switched to explicit + WPAD.

                      1 Reply Last reply Reply Quote 0
                      • M Offline
                        Modesty
                        last edited by

                        Hi

                        In my LigthSquid logs I only get http:// entries:

                        0_1545989957321_5b857bec-b09c-4a8d-ad49-a8b80cabd33d-image.png

                        Is this an expected behaviour, not logging all types of access, like https?

                        Everything can be rebuilt!

                        1 Reply Last reply Reply Quote 0
                        • KOMK Offline
                          KOM
                          last edited by

                          You won't get ANY https traffic in transparent mode unless you install a trusted cert on every single last client that will use your proxy.

                          1 Reply Last reply Reply Quote 0
                          • First post
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.