Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squidguard - doesn't work Ldap search by groups

    Scheduled Pinned Locked Moved Cache/Proxy
    4 Posts 3 Posters 3.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R
      Rarog
      last edited by

      There are Pfsense 2.3.5, squid, squidguard configured according to the instructions from the site pf2ad.mundounix.com.br

      Problem: the group filter ldapusersearch ldap doesn't work: ldapusersearch ldap://192.168.0.100/DC=domain,DC=com?SAMAccountName?Sub?(&(SAMAccountName=%s)(memberOf=CN=FullAccess%2cOU=Internet%2cDC= domain%2cDC=com))

      The user is authorized, but squidguard considers that it is in the target default. He does not allow you to go to sites.
      Log squidGuard: ldap_simple_bind_s failed: Invalid credentials

      1. What needs to be corrected for the user to be in group acl? (group acl is created with the rule of access to the Internet)
      2. Why doesn't  ldap authorization work in squid?

      1 Reply Last reply Reply Quote 0
      • perikoP
        periko
        last edited by

        Hi Rarog, I'm working in the integration pfsense-2.4.1 SG vs win server 2012 r2 AD, are u?

        or is a Linux LDAP?

        If is AD, what is your status?

        I'm interest in.

        Thanks.

        Necesitan Soporte de Pfsense en México?/Need Pfsense Support in Mexico?
        www.bajaopensolutions.com
        https://www.facebook.com/BajaOpenSolutions
        Quieres aprender PfSense, visita mi canal de youtube:
        https://www.youtube.com/c/PedroMorenoBOS

        1 Reply Last reply Reply Quote 0
        • R
          Rarog
          last edited by

          @periko:

          Hi Rarog, I'm working in the integration pfsense-2.4.1 SG vs win server 2012 r2 AD, are u?

          or is a Linux LDAP?

          If is AD, what is your status?

          I'm interest in.

          Thanks.

          I solved this problem today. In pFsense, Squid Authentication Method LDAP works on port 3268, not 389 on Windows Server 2012 R2 AD. So, pf2ad not needed.

          Squidguard works with simple password without symbols.

          1 Reply Last reply Reply Quote 1
          • B
            bessem
            last edited by

            @Rarog I have the same problem my friend!!
            so how did u solve it??
            where did u chage the port setting to 3268 ??
            and about the AD password I use "pa$$w0rd' so you suggest me to change it?

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.