Reverse Squid no longer working on latest development branch
-
@kiokoman 2.5.
-
And you do actually see that line in squid.conf?
That site is something you have configured?
Steve
-
@stephenw10 yes that line is in squid.conf. been running this for over a year. The latest dev branch seems to have broken something.
-
So the actual line in the file is?:
http_port Array:80 accel defaultsite=mysite.com vhost
Is it only the reverse proxy failing?
That line looks like it's from a much older Squid version. The only recent thing I'm seeing is this:
https://github.com/pfsense/FreeBSD-ports/pull/776What snapshot were you running previously when it was working?
Steve
-
Yes, mysite.com is obliviously my outside DNS not mysite.com. And i am running the latest package I can get from the available packages. About 3 snaphots ago, i don't remember which on. Omg i forgot to mention I have Pfsense firewall on what it is running on.
-
'Array' there looks like it might be incorrect. It should be the listening listening interface
Try editing the file to correct that and starting the service. It will be overwritten if you make changes but will prove the issue.
Steve
-
What should I change it to?
-
I think Steve is saying to remove the
Array:
part of the line, so it should be justhttp_port 80 accel...
Stop the service, edit the file, and restart the service. Just remember that making any changes to Squid settings via the GUI will likely reintroduce the
Array:
bit back into the file, at least until the issue is fixed. -
Hello!
For reference:
http://www.squid-cache.org/Versions/v3/3.5/cfgman/http_port.html
John
-
@serbus That worked. Thanks. But why is it doing that? Who can inform the devs to fix that for PFSENSE?
-
@nafeasonto said in Squid no longer working on latest development branch:
/usr/local/etc/squid/squid.conf
i'm unable to reproduce this, everything seems to work fine on my side
the generation of the squid.conf is ok idk maybe some glich on your pfsense -
It looks like it should be producing a line like: http_port ipaddress:80 accel defaultsite=mysite.com vhost
It should be choosing the IP address from an array of the ip addresses on the interfaces by the interface it's listening on.
I would guess that last change that went in to add IPv6 missed something for the reverse proxy case.
I also note 'vhost' is a deprecated option. Reverse Squid could use some love.
Steve
-
@kiokoman said in Squid no longer working on latest development branch:
i'm unable to reproduce this
In reverse mode?
-
i put some random stuff inside and it was working, i will try again
-
May be something else required to 'tickle' it. Like something in the array contents... or a lack of contents etc.
-
ah ok found it.. yeah it put Array in the config
bug https://redmine.pfsense.org/issues/10367foreach (explode(",", $ifaces) as $i => $iface) { $real_ifaces[] = squid_get_real_interface_address($iface); if ($real_ifaces[$i][0]) {
$real_ifaces[] contain only "Array"
-
Good job finding it. I love when people listen to me. Thanks for taking the time to read the post.
-
Fix:
https://github.com/pfsense/FreeBSD-ports/pull/805 -
Rapido!
-
nice work as always viktor