• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

(SOLVED) pfSense + SQUID + SquidGuard (SquidGuard not bloking all)

Scheduled Pinned Locked Moved Cache/Proxy
8 Posts 4 Posters 1.5k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rec
    last edited by rec Jul 10, 2019, 3:43 PM Jul 5, 2019, 6:54 PM

    Hi there.

    I have a new pfSense installation (version 2.4.4-RELEASE-p3 (amd64)).

    I configured the SQUID with LDAP (Windows Server 2016), it works.

    I configured the SquidGuard in "Common ACL" to DENY default access.

    If the Windows use the Proxy = Block, it's OK
    If the Windows dont use the Proxy = Free Access.

    I need to block all the client who don't use the Proxy.

    What I doing What I doing errored?

    alt text

    alt text

    Best regards,

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Jul 7, 2019, 1:44 PM

      We can't read that first screenshot. Can you include that at higher resolution?

      Steve

      1 Reply Last reply Reply Quote 1
      • R
        rec
        last edited by rec Jul 9, 2019, 1:28 PM Jul 9, 2019, 1:25 PM

        Hello, my problem continuous.

        In bellow more images.

        alt text
        alt text
        alt text
        alt text

        Regards,

        1 Reply Last reply Reply Quote 0
        • K
          kiokoman LAYER 8
          last edited by Jul 9, 2019, 1:36 PM

          if you want to enforce the use of the proxy you need to activate 'Trasparent HTTP Proxy'

          ̿' ̿'\̵͇̿̿\з=(◕_◕)=ε/̵͇̿̿/'̿'̿ ̿
          Please do not use chat/PM to ask for help
          we must focus on silencing this @guest character. we must make up lies and alter the copyrights !
          Don't forget to Upvote with the 👍 button for any post you find to be helpful.

          1 Reply Last reply Reply Quote 0
          • S
            stephenw10 Netgate Administrator
            last edited by Jul 9, 2019, 3:09 PM

            Or if you just need to block clients who are not using the proxy just add deny rules on LAN for destination ports 80 and 443.

            The anti-lockout rule will still allow access the webgui. Clients will only be able to use http/s whilst going via the proxy.

            Steve

            R 1 Reply Last reply Jul 10, 2019, 3:42 PM Reply Quote 0
            • R
              rec @stephenw10
              last edited by Jul 10, 2019, 3:42 PM

              @stephenw10, thanks.

              My problem has been solved.

              Best regards,

              S 1 Reply Last reply Nov 21, 2019, 4:31 PM Reply Quote 0
              • S
                spyshagg @rec
                last edited by stephenw10 Nov 22, 2019, 4:56 PM Nov 21, 2019, 4:31 PM

                @rec-br9 said in (SOLVED) pfSense + SQUID + SquidGuard (SquidGuard not bloking all):

                @stephenw10, thanks.

                My problem has been solved.

                Best regards,

                How?

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by Nov 22, 2019, 4:57 PM

                  Presumably by blocking ports 80 and 443 directly since they were not using a transparent proxy.

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                    [[user:consent.lead]]
                    [[user:consent.not_received]]