• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Configuration for Squid + RADIUS in CARP environment?

Scheduled Pinned Locked Moved Cache/Proxy
1 Posts 1 Posters 1.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P
    piwwo
    last edited by Aug 24, 2016, 3:46 PM

    When using Squid in a CARP failsafe environment, I'd have Squid listening to the CARP VIP, yes? Since the package's GUI only allows setting listen to the IP numbers of the interfaces, I added advanced configuration

    http_port 192.168.10.1:3128; http_port 192.168.30.1:3128; http_port 192.168.40.1:3128
    

    Where .10.0/24, .30.0/24, .40.0/24 stand for my VLAN networks. .10.1, 30.1, .40.1 are my CARP VIPs and .10.2, 30.2, .40.2 are my interface's real IPs on the master.

    [2.3.2-RELEASE][root@pfSense.office.curesec.com]/root: sockstat -l4 | grep squid
    squid    squid      36870 8  udp4 6 *:52425               *:*
    squid    squid      36870 9  udp4   *:15299               *:*
    squid    squid      36870 12 tcp4   192.168.10.2:3128     *:*
    squid    squid      36870 15 tcp4   192.168.30.2:3128     *:*
    squid    squid      36870 17 tcp4   192.168.40.2:3128     *:*
    squid    squid      36870 19 tcp4   192.168.10.1:3128     *:*
    squid    squid      36870 20 tcp4   192.168.30.1:3128     *:*
    squid    squid      36870 21 tcp4   192.168.40.1:3128     *:*
    
    

    I want Squid accessible from all VLANs

    The question I have now is, what exactly Squid has to listen to, and what Squid's client-IP might be so that I can set that IP as a NAS client in the FreeRADIUS configuration. For some reasons, RADIUS refuses to answer to requests from Squid, when I set the NAS Client IP to the CARP VIP .10.1 - but when I set .10.2 as the NAS client IP and the RADIUS config is synced, that IP number won't exist on the backup system since their real interface IP is .3 instead of .2

    Can you tell me how I'd have to setup RADIUS and Squid so that this works in a CARP environment?

    1 Reply Last reply Reply Quote 0
    1 out of 1
    • First post
      1/1
      Last post
    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
      This community forum collects and processes your personal information.
      consent.not_received