Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Need help with squid proxy + firewall Rules

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 2 Posters 648 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • L
      leao.adilson
      last edited by

      So, I'm new to pfSense and I'm having some trouble settig up squid(not transparent proxy) + squidguard + webfiltering.

      The proxy is working as intended, filtering web sites based on Users groups in AD. That is, only if the default rule of the firewall to alllow IPv4 traffic trhough LAN is enabled, if I disable this, than nothing works.

      I created a new rule to allow LAN machines to access the firewall on port 3128 (where squid is running) and it works, but still cant access the Internet.

      The problem really is: I can't figure how to create a rule to allow squid to access the internet.

      M 2 Replies Last reply Reply Quote 0
      • M
        mcury @leao.adilson
        last edited by

        @leao-adilson Probably missing the DNS rule?

        dead on arrival, nowhere to be found.

        L 1 Reply Last reply Reply Quote 0
        • L
          leao.adilson @mcury
          last edited by

          @mcury My Samba 4 is setup ad my DNS server, forwarding to googles DNS, and event so, I tried ping requests to 8.8.8.8 and got timeout.

          1 Reply Last reply Reply Quote 0
          • L
            leao.adilson
            last edited by

            This is my current firewall rule set.
            dfbad7e9-6a4e-4a21-85f4-75c8d5953b77-image.png

            M 1 Reply Last reply Reply Quote 0
            • M
              mcury @leao.adilson
              last edited by

              @leao-adilson said in Need help with squid proxy + firewall Rules:

              only if the default rule of the firewall to alllow IPv4 traffic trhough LAN is enabled, if I disable this, than nothing works.

              You need a firewall rule in LAN, allowing users to access the DNS server.
              TCP/UDP 53.

              I tried ping requests to 8.8.8.8 and got timeout.

              Ping is not TCP/UDP, you would need to allow ICMP.

              dead on arrival, nowhere to be found.

              1 Reply Last reply Reply Quote 0
              • M
                mcury @leao.adilson
                last edited by

                @leao-adilson said in Need help with squid proxy + firewall Rules:

                This is my current firewall rule set.
                dfbad7e9-6a4e-4a21-85f4-75c8d5953b77-image.png

                It's missing the DNS rule...

                dead on arrival, nowhere to be found.

                1 Reply Last reply Reply Quote 0
                • L
                  leao.adilson
                  last edited by

                  After insertinf the DNS rule and a reboot the internet access through the proxy is finally working. Thanks for the help.

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    mcury @leao.adilson
                    last edited by

                    @leao-adilson you are welcome

                    dead on arrival, nowhere to be found.

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.