Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Pfsense 2.4.4 squid, squid guard, Outlook and office 365 disconnects

    Cache/Proxy
    3
    5
    763
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      ahmed 0 last edited by ahmed 0

      Hello everyone.
      I'm using pfsense 2.4.4 , with squid, as a transparent proxy.I installed squidguard and configured it to block access to specific pages and yes, that works. The issue is that when enable SSL interception to filter HTTPS sites the filtration works well, but the problem happens with Outlook it connect then after 5 minutes it disconnects.and this happens continually without stopping, and I makes lots of trouble shooting and get nothing

      Greetings and thank you very much.!!_20190727_055650.JPG

      1 Reply Last reply Reply Quote 0
      • KOM
        KOM last edited by

        I am not sure what is to be gained by proxying webmail, but perhaps you could add an exclusion for the Outlook mail host via Services - Squid Proxy Server - Transparent Proxy Settings - Bypass Proxy for These Destination IPs?

        A 1 Reply Last reply Reply Quote 0
        • A
          ahmed 0 @KOM last edited by

          @KOM Hi, could you please tell me what is the ip's to be added
          Thanks

          1 Reply Last reply Reply Quote 0
          • KOM
            KOM last edited by

            How would I know? Use the tools at your disposal. Look at your squid access.log to see the hosts its talking to. That field I told you about accepts hostnames, not just IP addresses, but I don't know how it handles multiple replies to a DNS query. It may ony resolve to a single address every 5 minutes or so. You might have to track all the addresses the webmail host uses and then create an alias to hold them, and use that alias for the bypass.

            1 Reply Last reply Reply Quote 0
            • A
              aGeekhere last edited by

              Try this

              1. setup a WPAD (make web browser use it )
              2. Manual configure any device that cannot use a WPAD
              3. Use transparent proxy with MITM splice all to catch the rest
                https://forum.netgate.com/topic/100342/guide-to-filtering-web-content-http-and-https-with-pfsense-2-3/178

              Never Fear, A Geek is Here!

              1 Reply Last reply Reply Quote 0
              • First post
                Last post