Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid and OpenVPN - remote internet traffic proxying

    Scheduled Pinned Locked Moved Cache/Proxy
    4 Posts 3 Posters 5.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Z
      zeureo1
      last edited by

      Hi PFsense users,
      I have a pfsense 2.2.2-amd64 guest on ESXI 5.5, with LAN,DMZ and WAN interfaces. Squid transparently proxies on LAN and DMZ.
      I have OpenVPN running too, and would like to force all remote VPN traffic through my system for security/monitoring.
      However, while I can force all traffic thru the VPN (OpenVPN settings), Squid doesn't see it (I can check this in syslogs/Splunk).

      I tried adding a new (OPT1) interface and binding to OpenVPN, however that broken all VPN access (even after allowing ALL on new OPT1 interface FW rules). So enabling OPT1 in Squid didn't work with no VPN access.

      Can someone help show the error of my ways? I'm assuming there's a simple routing bit I'm missing to enable traffic from OpenVPN on the newly-bound OPT1 interface, and then allow SQUID to transparently proxy it… But I can't work it out.
      Thanks for any help provided.
      Zeureo

      1 Reply Last reply Reply Quote 0
      • Z
        zeureo1
        last edited by

        RESOLVED!!

        To resolve this

        • Port-Forward (NAT) TCP/80 from VPN subnet to localhost 127.0.0.1 to dport 3128 (squid port)
        • add a FW rule on the OpenVPN iface to allow TCP/3128 from OpenVPN subnet to localhost.

        Now I can monitor, secure and proxy internet requests from VPN interface too!

        T 1 Reply Last reply Reply Quote 0
        • Z
          z71prix
          last edited by

          I'm having a similar issue like yours.  Are you available to help?

          I'm using open VPN on LAN1

          LAN2 is normal WAN IP

          When I enable Squid, I loose VPN address on LAN1, it becomes my WAN IP address?

          I tried to port forward in NAT, then tried to set a rule.  I need more details?  I'm still new to pfsense.

          thank you

          1 Reply Last reply Reply Quote 0
          • T
            Techneau @zeureo1
            last edited by Techneau

            @zeureo1 said in Squid and OpenVPN - remote internet traffic proxying:

            add a FW rule on the OpenVPN iface to allow TCP/3128 from OpenVPN subnet to localhost.

            Can you please be clear on "adding a FW rule on the OpenVPN iface to allow TCP/3128 from OpenVPN subnet to localhost".
            I've been using pfsense for years and I don't believe I've heard of adding FW rule on OpenVPN

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.