Pfsense 2.3.1 problem squid + load balance

    We have a pfsense v2.3.1 Firewall in our office doing Load Balancing between 2 WAN connections, it also has enabled squid v0.4.21 and squidGuard v1.14_3 for Proxy.

    The problem is, when one of the WAN connections goes offline because of problems with the ISP, the traffic passing by the other WAN gets VERY slowly. The problems seems happening when the squid is enabled, because if we stop the squid/squidGuard the traffic goes fast again.

  • As described in documentation (even on-line doc), load-balancing doesn't work for proxy deployed on pfSense itself.

    Reason is that fail-over and load-balancing rely on "GW group" that is configured as "policy routing" for FW rules, meaning then "per interface".

    If you define, e.g. one "HAGW" group and use it for FW rules defined for LAN, this will not be used by HTTP proxy running locally thus not using LAN.

