• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Squid bypassing firewall rules?

Scheduled Pinned Locked Moved Cache/Proxy
8 Posts 6 Posters 2.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    Kai_null
    last edited by Oct 22, 2017, 4:25 AM

    Squid seems to be bypassing the firewall rules with transparent proxy?

    Is there a way around this?

    I tried searching online without much luck.

    1 Reply Last reply Reply Quote 0
    • Z
      Zamboni111
      last edited by Oct 29, 2017, 7:32 PM

      @Kai_null:

      Squid seems to be bypassing the firewall rules with transparent proxy?

      Is there a way around this?

      I tried searching online without much luck.

      It seems to bypass the firewall rules even without transparent proxy for me -  I would also like to know if this is intentional.  Any rule i create on WAN /LAN/ Floating is entirely ignored as far as i can tell

      1 Reply Last reply Reply Quote 0
      • S
        sichent Banned
        last edited by Oct 30, 2017, 12:59 PM

        May be this will help - https://docs.diladele.com/tutorials/filtering_https_traffic_squid_pfsense/updates.html#enable-transparent-proxy
        See a note about QUIC

        1 Reply Last reply Reply Quote 0
        • K
          Kai_null
          last edited by Nov 17, 2017, 9:04 AM

          This issue is still affecting me.

          This completely unrelated to the QUIC protocol.

          The sites in question are being blocked by pfblockerng ip address lists.  Which blocks everything to said sites except for port 80, which is routing through squid past the firewall and firewall rules.

          Testing was done by putting the ip address of said site into the browser ex: http://1.2.3.4 and watching it return a response.

          1 Reply Last reply Reply Quote 0
          • K
            Kai_null
            last edited by Apr 8, 2018, 8:20 AM

            follow up:

            In the end, the only way around this problem for me was to disable squid :(.

            1 Reply Last reply Reply Quote 0
            • C
              corvey
              last edited by Apr 8, 2018, 5:45 PM

              @Kai_null:

              the only way around this problem for me was to disable squid :(.

              Agreed.  Anything that supersedes my set in stone authority gets two thumbs down from me, too.

              pfSensationalâ„¢

              1 Reply Last reply Reply Quote 0
              • B
                brrugg
                last edited by May 21, 2018, 8:04 PM

                In my case I noticed that if the firewall rules were ignored only if Enable SSL filtering / Splice All was activated. I still haven't found a solution to have both.

                1 Reply Last reply Reply Quote 0
                • K
                  kpa
                  last edited by May 21, 2018, 8:38 PM

                  Normal LAN firewall rules are ignored for traffic that is passed to the proxy and for good reason.Tthe NAT redirect that is in place for the transparent proxy forces the traffic to the proxy by rewriting the destination address:port pair in the packets to 127.0.0.1:3128 (the usual set up) before they hit the LAN filter rules. This is why the modified traffic won't match your LAN filter rules.

                  Make sure you're not proxying too much with a too "wide" NAT rule, NAT only the traffic you want to be controlled by the proxy.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    [[user:consent.lead]]
                    [[user:consent.not_received]]