• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Squid - proxy test don't detect proxy

Scheduled Pinned Locked Moved Cache/Proxy
13 Posts 3 Posters 2.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C
    chudak
    last edited by Nov 20, 2017, 11:06 PM Nov 20, 2017, 10:27 PM

    I have a standard Squid proxy setup and it used to pass proxy tests (like http://www.all-nettools.com/toolbox/proxy-test.php)

    And now tests show - no proxy detected !

    I don't know even know where to start troubleshooting this.
    Any help is appreciated !

    Thx

    1 Reply Last reply Reply Quote 0
    • K
      KOM
      last edited by Nov 21, 2017, 1:07 AM

      And now tests show - no proxy detected !

      That should be a good thing.  You don't want external sources knowing you're going through a proxy server.

      1 Reply Last reply Reply Quote 0
      • C
        chudak
        last edited by Nov 21, 2017, 1:17 AM

        @KOM:

        And now tests show - no proxy detected !

        That should be a good thing.  You don't want external sources knowing you're going through a proxy server.

        @KOM how do i test it then?

        1 Reply Last reply Reply Quote 0
        • K
          KOM
          last edited by Nov 21, 2017, 2:10 PM

          Services - Squid proxy server - Realtime.

          If everything is working then you should see URLs scrolling by in realtime as your users access pages.

          Back to what I was saying about masking your proxy, make sure you have the following set:

          X-Forwarded Header Mode: delete
          Disable Via header: checked
          Suppress squid version: checked

          1 Reply Last reply Reply Quote 0
          • C
            chudak
            last edited by Nov 21, 2017, 4:06 PM

            Thanks! Your statement that proxy should not be detected contradicts all videos I've see on this topic tho … odd...

            1 Reply Last reply Reply Quote 0
            • K
              kejianshi
              last edited by Nov 21, 2017, 4:38 PM

              The videos are all wrong.  Kom is right.

              Frequently, advertising that your traffic goes through a proxy will get you blocked and end up with some form of captcha way more often than necessary.

              1 Reply Last reply Reply Quote 0
              • C
                chudak
                last edited by Nov 21, 2017, 4:49 PM

                @kejianshi:

                The videos are all wrong.  Kom is right.

                Frequently, advertising that your traffic goes through a proxy will get you blocked and end up with some form of captcha way more often than necessary.

                It's unfortunate as many people are using videos on youtube to learn things and pfsense in particular.
                The reason I was wondering about the squid proxy as I use also antivirus and it stopped detecting  test files from http://www.eicar.org/85-0-Download.html

                Not sure WTH is going on ? …

                1 Reply Last reply Reply Quote 0
                • K
                  kejianshi
                  last edited by Nov 21, 2017, 4:52 PM

                  You likely have a broken squid cache.  I'd delete and rebuild the cache.  Start there.

                  This problem of yours is a regular subject here, so the answer is already in the threads.

                  1 Reply Last reply Reply Quote 0
                  • C
                    chudak
                    last edited by Nov 21, 2017, 4:55 PM

                    Tried that already with no luck :(

                    I guess I have to live with the idea it was not doing much anyway…

                    1 Reply Last reply Reply Quote 0
                    • K
                      kejianshi
                      last edited by Nov 21, 2017, 5:05 PM

                      Sounds very broken. 
                      Sorry.

                      1 Reply Last reply Reply Quote 0
                      • K
                        KOM
                        last edited by Nov 21, 2017, 5:34 PM

                        AV is best done on the client.  I don't know how effective the Clam AV signatures are, or how effective it is at stopping anything other than the obvious stuff.  And it's one more thing to give you problems with your Squid config.

                        1 Reply Last reply Reply Quote 0
                        • C
                          chudak
                          last edited by Nov 21, 2017, 5:41 PM

                          @KOM:

                          AV is best done on the client.  I don't know how effective the Clam AV signatures are, or how effective it is at stopping anything other than the obvious stuff.  And it's one more thing to give you problems with your Squid config.

                          Well AV does not worry me much.  It's more about oveall health of my pfSense router and it used to do all of this before 2.4.1 uograde and now no.
                          I spent some time on this https://github.com/darold/squidclamav/issues/42 with no result.  BTW I see no errors on squid site.  So just keep trying :)

                          1 Reply Last reply Reply Quote 0
                          • K
                            kejianshi
                            last edited by Nov 21, 2017, 5:58 PM

                            I remember when I built my first pfsense.  I just started adding every feature that looked cool and later realized that most of it I didn't need at home.  Squid and clam av were among those that I found not very useful for my home scenarios.  My clients were either windows which had far superior AV or linux systems which need no AV.  So, I don't use those now.

                            There are scenarios where it is useful though.  For me, I used it to control what my kids could see on the net.

                            Later when they reached their teen years I turned it off…

                            1 Reply Last reply Reply Quote 0
                            13 out of 13
                            • First post
                              13/13
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              This community forum collects and processes your personal information.
                              consent.not_received