Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    (SOLVED) pfSense + SQUID + SquidGuard (SquidGuard not bloking all)

    Scheduled Pinned Locked Moved Cache/Proxy
    8 Posts 4 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      rec
      last edited by rec

      Hi there.

      I have a new pfSense installation (version 2.4.4-RELEASE-p3 (amd64)).

      I configured the SQUID with LDAP (Windows Server 2016), it works.

      I configured the SquidGuard in "Common ACL" to DENY default access.

      If the Windows use the Proxy = Block, it's OK
      If the Windows dont use the Proxy = Free Access.

      I need to block all the client who don't use the Proxy.

      What I doing What I doing errored?

      alt text

      alt text

      Best regards,

      1 Reply Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator
        last edited by

        We can't read that first screenshot. Can you include that at higher resolution?

        Steve

        1 Reply Last reply Reply Quote 1
        • R
          rec
          last edited by rec

          Hello, my problem continuous.

          In bellow more images.

          alt text
          alt text
          alt text
          alt text

          Regards,

          1 Reply Last reply Reply Quote 0
          • kiokomanK
            kiokoman LAYER 8
            last edited by

            if you want to enforce the use of the proxy you need to activate 'Trasparent HTTP Proxy'

            ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
            Please do not use chat/PM to ask for help
            we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
            Don't forget to Upvote with the 👍 button for any post you find to be helpful.

            1 Reply Last reply Reply Quote 0
            • stephenw10S
              stephenw10 Netgate Administrator
              last edited by

              Or if you just need to block clients who are not using the proxy just add deny rules on LAN for destination ports 80 and 443.

              The anti-lockout rule will still allow access the webgui. Clients will only be able to use http/s whilst going via the proxy.

              Steve

              R 1 Reply Last reply Reply Quote 0
              • R
                rec @stephenw10
                last edited by

                @stephenw10, thanks.

                My problem has been solved.

                Best regards,

                S 1 Reply Last reply Reply Quote 0
                • S
                  spyshagg @rec
                  last edited by stephenw10

                  @rec-br9 said in (SOLVED) pfSense + SQUID + SquidGuard (SquidGuard not bloking all):

                  @stephenw10, thanks.

                  My problem has been solved.

                  Best regards,

                  How?

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Presumably by blocking ports 80 and 443 directly since they were not using a transparent proxy.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.