• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

PfSense HTTP/HTTPS firewall rules and Squid ...

Scheduled Pinned Locked Moved Firewalling
3 Posts 2 Posters 607 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • K
    kerlerom44
    last edited by Jan 28, 2020, 9:43 PM

    Hi,
    I am facing an issue regarding firewall of PfSense (http/s trafic).
    My FW gets 2 rules HTTP(80) and HTTPS(443) in order to prevent the LAN users accessing internet web sites.

    • when Squid Proxy service is disabled : both rules work (users cannot acces http/s )
    • when Squid Proxy service enabled (Transparent mode + SSL interception + SpiceAll) :
      users can access internet !
    • if I disable Squid, rules are taken into account again

    It seems like Squid Proxy service is "overriding" both firewall rules.
    Has anybody ever experienced this kind of issue ? would it be a configuration issue instead ?

    Thanks for your help

    1 Reply Last reply Reply Quote 0
    • I
      isolatedvirus
      last edited by Jan 29, 2020, 2:49 AM

      the issue youre experiencing is because of transparent mode on squid. the traffic is redirected to the pfsense squid service, intercepted, and then the traffic source is changed to be the firewall itself. your rule isnt blocking the firewall.

      if youre trying to intercept and force traffic through the proxy BEFORE going to the internet, this is working as intended then.

      1 Reply Last reply Reply Quote 1
      • K
        kerlerom44
        last edited by Jan 30, 2020, 3:28 PM

        Hi "isolatedvirus" and thx a lot !
        It makes sense. I configured [transparent mode] in order to avoid the configuration at every client side (Win or Linux) => no need to import PfSense selfsigned certificate and the SSL flow is not "broken" at the proxy level.
        If I understood, the solution would be to force the outbound web trafic going through Squid-proxy first and redirect it to the firewall after... both firewall and proxy applications should be "called" but I don't think that's possible...
        Regarding HTTP/S trafic flow, either I keep Squid in service (FW = useless) or I forgive Squid (and its proxy-cache for perf).
        On the other hand, a proxy is really usefull in a company IT network but at home...

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received