Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SVL 3 Problem

    Scheduled Pinned Locked Moved General pfSense Questions
    5 Posts 2 Posters 725 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • P
      PatrizioIB
      last edited by

      Hi everybody,

      i've got this problem with my new installation of PfSense.
      When i navigate on some websites i receive a block and Pfsense displays the message below.

      Before i write this message, i check in the forum, and i change the "compatibility mode" of proxy server
      to INTERMEDIATE but it still doesn't work, and i put the Ip in the Bypass proxy.

      Can someone help me, please?


      The following error was encountered while trying to retrieve the URL: https://access.mef.gov.it/*

      Failed to establish a secure connection to 5.152.246.63

      The system returned:

      (92) Protocol error (TLS code: SQUID_ERR_SSL_HANDSHAKE)

      Handshake with SSL server failed: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure

      This proxy and the remote host failed to negotiate a mutually acceptable security settings for handling your request. It is possible that the remote host does not support secure connections, or the proxy is not satisfied with the host security credentials.

      Your cache administrator is administrator@domain.it.


      1 Reply Last reply Reply Quote 0
      • johnpozJ
        johnpoz LAYER 8 Global Moderator
        last edited by

        Who would still be using slv3 ??  Been dead for years ;)

        That site only gets a C btw..
        https://www.ssllabs.com/ssltest/analyze.html?d=access.mef.gov.it

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.8, 24.11

        1 Reply Last reply Reply Quote 0
        • P
          PatrizioIB
          last edited by

          Any solution to get program ready to work?
          Can you suggest any setting to let all employees navigate on the webiste to avoid blocking?

          Thank you.

          1 Reply Last reply Reply Quote 0
          • johnpozJ
            johnpoz LAYER 8 Global Moderator
            last edited by

            what version of pfsense did you install.. I don't see how proxy would be even attempting to use ssl3

            And you shouldn't even be doing proxy of https anyway..  You can filter it for the connect but the client should be end to end for https - mitm middle opens up a whole can of worms from privacy and security points of view.

            An intelligent man is sometimes forced to be drunk to spend time with his fools
            If you get confused: Listen to the Music Play
            Please don't Chat/PM me for help, unless mod related
            SG-4860 24.11 | Lab VMs 2.8, 24.11

            1 Reply Last reply Reply Quote 0
            • P
              PatrizioIB
              last edited by

              Ok, i understand the problem. I thought there was a possibility
              to bypass it.

              Thank you anyway.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.