Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    HOWTO: pfSense 1.2.x Traffic Shaping with Squid Transparent Proxy

    Scheduled Pinned Locked Moved Traffic Shaping
    31 Posts 26 Posters 77.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      splippity
      last edited by

      Is this still relevant with 2.0RC1? I assume it is so after every update I make the changes that it tells you to. Thanks

      1 Reply Last reply Reply Quote 0
      • K
        kirlox_kitoy
        last edited by

        so what should be the order? install squid package first then traffic shaper or the other way around mess first with traffic shaper and install squid last

        1 Reply Last reply Reply Quote 0
        • K
          kirlox_kitoy
          last edited by

          which will be the sequence of installation? do i need to configure first the traffic shaper or install the squid first?

          1 Reply Last reply Reply Quote 0
          • A
            anagh
            last edited by

            Is it the same method for pfsense2.0 rc3. there are several instance of 127.0.0.1 in squid.inc among those which i required to change please explain in details alomg with the traffic shaping way

            1 Reply Last reply Reply Quote 0
            • A
              anagh
              last edited by

              Waiting for the reply in pfsense2.0 rc3 I have installed squid with lusca with squid guard and in squid.inc there are 10 instances of 127.0.0.1 among those whic i required to change

              1 Reply Last reply Reply Quote 0
              • T
                tacfit
                last edited by

                Any comments on whether this works in Pfsense 2.0? It would be great to be shaping and caching on the same box.

                1 Reply Last reply Reply Quote 0
                • H
                  hyrol
                  last edited by

                  The easy way Traffic Shaping with Squid Transparent Proxy
                  Add under Firewall Rules

                  Action = Pass
                  Interface= LAN
                  Source= LAN subnet
                  Protocol = TCP
                  Source = LAN
                  Destination = any
                  Destination port range = (Squid Proxy port) eg. 3128

                  Reason http port 80 has moved to the squid proxy port 3128

                  1 Reply Last reply Reply Quote 0
                  • J
                    jigpe
                    last edited by

                    @hyrol - Thanks it works on 1.2.3. Ill test it on 2.1

                    1 Reply Last reply Reply Quote 0
                    • A
                      argyx
                      last edited by

                      @hyrol:

                      The easy way Traffic Shaping with Squid Transparent Proxy
                      Add under Firewall Rules

                      Action = Pass
                      Interface= LAN
                      Source= LAN subnet
                      Protocol = TCP
                      Source = LAN
                      Destination = any
                      Destination port range = (Squid Proxy port) eg. 3128

                      Reason http port 80 has moved to the squid proxy port 3128

                      This works for me on 2.0.1 (tested with various speed settings). Also, you will already have this rule in place if you are have a Deny All rule and are using transparent proxy. So, it's a good idea to take advantage of the rule.

                      1 Reply Last reply Reply Quote 0
                      • S
                        ScottNJ
                        last edited by

                        @argyx - This doesn't work, all HTTP traffic is still getting dumped into qlandef, which by default receives 1% bandwidth from the wizard.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.