• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

The following error was encountered while trying to retrieve https://http/*

Scheduled Pinned Locked Moved Cache/Proxy
20 Posts 16 Posters 17.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    loboferoz
    last edited by Nov 27, 2017, 4:47 AM

    Nope, this does not work, tested several times on pfsense 2.4.2

    1 Reply Last reply Reply Quote 0
    • R
      rmr85
      last edited by Dec 6, 2017, 4:50 PM

      Im having same problem here on PfSense 2.4.2 (amd64)Transparent Proxy HTTP/HTTPS + Squidguard
      If i disable Squidguard all works well.

      Any help?

      1 Reply Last reply Reply Quote 0
      • I
        Impatient
        last edited by Dec 6, 2017, 5:30 PM

        It is not supposed to work with Default access [all] to deny.

        1 Reply Last reply Reply Quote 0
        • V
          Voxnod
          last edited by Nov 1, 2018, 4:10 AM

          It worked for me. PfSense 2.4.4 (amd64) Squid + Squidguard.

          K 1 Reply Last reply Feb 18, 2019, 7:33 AM Reply Quote 0
          • K
            kopraasbotha @Voxnod
            last edited by Feb 18, 2019, 7:33 AM

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • B
              bluegrass-168
              last edited by Jan 6, 2020, 9:48 AM

              I have the same error with Default access [all] to allow already.

              Anyone knows and helps the solution? Plz.

              1 Reply Last reply Reply Quote 0
              • C
                cavaco
                last edited by May 23, 2020, 10:20 PM

                this is happening to me ... squid with active squid guard , and the comon acl with the settings that are said in the first post ,but its not working ... did u guys get it working ???

                1 Reply Last reply Reply Quote 0
                • C
                  coffeelover
                  last edited by Jul 29, 2020, 1:11 PM

                  You have to append

                  url_rewrite_access deny CONNECT
                  url_rewrite_access allow all

                  to your squid custom options to make the redirect page work in SSL MITM mode.

                  S 1 Reply Last reply Jul 30, 2020, 8:31 AM Reply Quote 1
                  • S
                    sonerzin @coffeelover
                    last edited by Jul 30, 2020, 8:31 AM

                    @coffeelover said in The following error was encountered while trying to retrieve https://http/*:

                    You have to append

                    url_rewrite_access deny CONNECT
                    url_rewrite_access allow all

                    to your squid custom options to make the redirect page work in SSL MITM mode.

                    Where exactly do you put those options? Custom Options (Before Auth) / Custom Options (After Auth) / Custom Options (SSL/MITM)?

                    SSL/MITM Mode: Splice All, Splice Whitelist, bump otherwise or Custom?

                    Thanks!

                    1 Reply Last reply Reply Quote 1
                    • C
                      coffeelover
                      last edited by Jul 30, 2020, 2:15 PM

                      I put these in "Custom options (before auth)"

                      And for complete filtering (URLs instead of domains) of SSL-Traffic via squidguard you have to set the mode to "Splice whitelist, bump otherwise".

                      Splice: Do not break the SSL Connection
                      Bump: Break the SSL Connection (Proxy CA on Clients needed)

                      M 1 Reply Last reply Jul 22, 2021, 9:39 AM Reply Quote 2
                      • D
                        Dacosta
                        last edited by Dec 2, 2020, 1:48 AM

                        Hi Coffee Lover,

                        I got this error after I added as your suggest:

                        Fastly error: unknown domain: yahoo.com. Please check that this domain has been added to a service.

                        Details: cache-sin18030-SIN

                        Please help.

                        1 Reply Last reply Reply Quote 0
                        • M
                          Michele Trotta @coffeelover
                          last edited by Jul 22, 2021, 9:39 AM

                          @coffeelover Thanks I have solved it

                          1 Reply Last reply Reply Quote 0
                          • J
                            jpattard
                            last edited by Aug 26, 2021, 6:30 AM

                            I cannot make this work with the latest version of PF sense. Anything else i should check?

                            1 Reply Last reply Reply Quote 1
                            • R
                              robirf
                              last edited by Sep 4, 2021, 2:13 PM

                              I have the same problem, when I´m not using ssl interceptation the page showed is on picture bellow.
                              e16eb2c1-5485-478f-8bbd-2e9a85d24e2f-image.png

                              But when I actived ssl interception the page showed is bellow.
                              So I´ve tried to put these lines that you mentioned before , but for me not solved.

                              36df853f-5550-45a6-9508-c2254c9d519f-image.png

                              N 1 Reply Last reply Sep 24, 2021, 11:32 AM Reply Quote 1
                              • N
                                nilux17 @robirf
                                last edited by Sep 24, 2021, 11:32 AM

                                same issue

                                1 Reply Last reply Reply Quote 0
                                • A
                                  aGeekhere
                                  last edited by aGeekhere Sep 25, 2021, 2:11 AM Sep 25, 2021, 2:11 AM

                                  Try
                                  https://forum.netgate.com/topic/100342/guide-to-filtering-web-content-http-and-https-with-pfsense-2-3

                                  WPAD as your main setup
                                  and transparent proxy to catch the rest.

                                  Never Fear, A Geek is Here!

                                  N 1 Reply Last reply Sep 28, 2021, 8:13 AM Reply Quote 0
                                  • N
                                    nilux17 @aGeekhere
                                    last edited by nilux17 Sep 28, 2021, 8:16 AM Sep 28, 2021, 8:13 AM

                                    Thx,
                                    actually, i've already setup a wpad but i put a "return direct"
                                    changing for a "return proxy ..." seems to do the trick

                                    I don't investigate "more than that" but a windows 10 laptop, even with a proxy configuration try to connect on 443 for a lot of things.
                                    Android apps too...

                                    A 1 Reply Last reply Sep 28, 2021, 8:28 AM Reply Quote 0
                                    • A
                                      aGeekhere @nilux17
                                      last edited by Sep 28, 2021, 8:28 AM

                                      @nilux17 In Internet properties lan settings
                                      Is Automatically detect settings checked?

                                      Sounds like you are going through the transparent proxy rather than the WPAD

                                      Never Fear, A Geek is Here!

                                      N 1 Reply Last reply Sep 28, 2021, 10:22 AM Reply Quote 0
                                      • N
                                        nilux17 @aGeekhere
                                        last edited by Sep 28, 2021, 10:22 AM

                                        @ageekhere
                                        Yeap, of course !

                                        1 Reply Last reply Reply Quote 0
                                        • JonathanLeeJ JonathanLee referenced this topic on Aug 18, 2023, 7:07 PM
                                        • JonathanLeeJ JonathanLee referenced this topic on Aug 18, 2023, 9:42 PM
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                          This community forum collects and processes your personal information.
                                          consent.not_received