Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squidgard no bloquea trafico HTTP(80)

    Scheduled Pinned Locked Moved Cache/Proxy
    13 Posts 3 Posters 1.2k Views 3 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mikeMTY
      last edited by

      Hola, tengo un SG-3100 version 2.4.4-RELEASE-p2 configurado con squid + squidgard con SSL Splice ALL, la config de squid esta por default, al igual que la del squidgard, los bloqueos configurados en el squidgard funcionan correctamente para el trafico HTTPS, pero al accesar a sitios que funcionan con HTTP, no los bloquea, en el log del squidgard me muestra que los esta bloqueando pero en realidad los browsers si despliega la pagina, las reglas firewal solo tiene abierto el acceso de la lan al puerto 53 DNS de la ip del pfsense...

      alguna idea??

      saludos

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        What?

        1 Reply Last reply Reply Quote 1
        • M Offline
          mikeMTY
          last edited by

          Sorry,

          Hello, I have an SG-3100 version 2.4.4-RELEASE-p2 configured with squid + squidgard with SSL Splice ALL, the squid config is by default, like the squidgard, the blocks configured in the squidgard work correctly for the HTTPS traffic, but when accessing sites that work with HTTP, it does not block them, in the squidgard log it shows me that they are blocking but in reality the browsers if the page is deployed, the rules firewal only has open the access of the lan to the port 53 DNS of the ip of the pfsense ...

          any ideas??

          greeting

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            Are you sure the browser isn't getting its data from it's cache or squid itself? Are these phones or PCs?

            1 Reply Last reply Reply Quote 0
            • M Offline
              mikeMTY
              last edited by

              @kom said in Squidgard no bloquea trafico HTTP(80):

              Are you sure the browser isn't getting its data from it's cache or squid itself? Are these phones or PCs

              I'm sure, it's been tried with different browsers, chrome, firefox, ie and the result is the same all the port 80 traffic is not blocked

              the squidgard log shows that the traffic is blocked, but it is false

              09.01.2019 22:40:35 192.168.1.200/192.168.1.200 http://www.elchat.net/favicon.ico Request(BLACK_LIST/bloqueados/-) - GET REDIRECT

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                Are these phones or PCs?

                1 Reply Last reply Reply Quote 0
                • M Offline
                  mikeMTY
                  last edited by

                  both devices

                  1 Reply Last reply Reply Quote 0
                  • KOMK Offline
                    KOM
                    last edited by

                    Some phones will switch to data if they detect they're blocked on wifi. Squidguard log will show the block but then the device just switches to data and connects.

                    1 Reply Last reply Reply Quote 0
                    • M Offline
                      mikeMTY
                      last edited by

                      yes but this happens with pcs too ... what do you suggest

                      1 Reply Last reply Reply Quote 0
                      • KOMK Offline
                        KOM
                        last edited by

                        I don't have any suggestions as I've never seen this happen before. It could be that squidguard is somehow broken. Usually when people have problems with squid, it's to do with https sites. I don't know enough about your network or squid/squidguard config to even guess.

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ Offline
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          That is just a favicon.ico -- it has nothing to do with serving up anything..

                          Why don't you just sniff the traffic an see what is happening since you say its just http you should easy see the traffic.. More then likely its not using what you think its using to access the site your trying to block, etc.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 25.07.1 | Lab VMs 2.8.1, 25.07.1

                          1 Reply Last reply Reply Quote 0
                          • KOMK Offline
                            KOM
                            last edited by

                            How is sniffing the traffic going to help him figure out why it's not being blocked??

                            Mike, post screenshots of your network config details and squid/squidguard config. Maybe something will jump out at us.

                            1 Reply Last reply Reply Quote 0
                            • M Offline
                              mikeMTY
                              last edited by

                              thanks for your help, I had to reset the equipment to factory values, reconfigure and function correctly, maybe, as KOM says, squidgard was broken

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.