• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Issue with bypass proxy for these source IPs

Scheduled Pinned Locked Moved Cache/Proxy
5 Posts 4 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    JLSheldrake
    last edited by Feb 15, 2017, 11:46 AM

    Hi,

    We currently have 2 Pfsense firewall routers setup both running squidguard. I have configured these to block a number of websites which works perfectly. I have also added 2 IP address entry’s into bypass proxy for these source IPs.

    These were working for a few days without issue but now has began blocking websites although they are still listed under bypass proxy for these source IP addresses on both routers.

    removing and reading them fixes the problem but I shouldn't have to do this on a weekly basis.

    Any suggestions on how to fix this issue would be greatly appreciated.

    Cheers

    J

    1 Reply Last reply Reply Quote 0
    • D
      dlawley
      last edited by Feb 18, 2017, 5:21 PM

      I have found a problem here as well, it seems that if I enter a domain hostname the whole squid process fails to load (or maybe just squidguard and lightsquid).  IP address works fine.

      I' get something about not being able to find ipaddress for xyz.domain

      1 Reply Last reply Reply Quote 0
      • D
        doktornotor Banned
        last edited by Feb 18, 2017, 6:34 PM

        @dlawley:

        I have found a problem here as well, it seems that if I enter a domain hostname the whole squid process fails to load (or maybe just squidguard and lightsquid).  IP address works fine.

        Why on earth would you put a domain there? Yeah it won't work when it doesn't resolve. And what does this have to do with this thread's topic?

        1 Reply Last reply Reply Quote 0
        • D
          dlawley
          last edited by Feb 23, 2017, 1:25 AM

          feel better now?

          Do not proxy traffic going to these destination IPs, CIDR nets, hostnames, or aliases, but let it pass directly through the firewall.

          because it says I can, if it fails lookup it should not crash the whole process

          1 Reply Last reply Reply Quote 0
          • J
            jimp Rebel Alliance Developer Netgate
            last edited by Feb 27, 2017, 5:06 PM

            Just because you can, doesn't mean you should.

            Put the hostname in an alias, put the alias name in the squid settings.

            That will (a) stop a bad hostname from tanking squid and (b) allow pfSense to update the alias if the results of the hostname resolution changes.

            Remember: Upvote with the 👍 button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received