Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid Proxy with private pfSense issued certs showing weird https traffic when SSL intercept enabled

    Scheduled Pinned Locked Moved Cache/Proxy
    3 Posts 1 Posters 743 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • JonathanLeeJ
      JonathanLee
      last edited by

      Hello fellow Netgate community, Can you please help?

      I wanted to take Netgates pfSense with Squid Proxy loaded for a test drive today. Everything is working. I generated and loaded the root certificate and intermediate on my Windows 10 system.

      In the Squid Proxy real time I see this same highlighted address over and over is there a issue here? (See image below)
      signalr-relayhub.JPG
      (Image: What is relay hub?)

      certificatesworking.JPG
      (Image: internal-ca is my loaded pfSense generated certificate)

      noninternal.JPG

      (Image: Google has some weird ones now they show it is not using my certificate it started using something else)

      SSLproxy.JPG

      (Image: The hit rates with https proxy options enabled sky rockets)

      I made a Access control list for everything on the lan can access tcp/udp 3128-3129 to the firewalls IP address also

      Make sure to upvote

      1 Reply Last reply Reply Quote 0
      • JonathanLeeJ
        JonathanLee
        last edited by

        Part 2:

        Here is without SSL proxy running accessing ABC news

        Disabled Rotues to Amazon for AWS.JPG

        (Image: Certificate issued from Amazon)

        enabled.JPG

        (Image: pfSense running Squid with SSL enabled showing pfSense custom generated certificates)

        Make sure to upvote

        JonathanLeeJ 1 Reply Last reply Reply Quote 0
        • JonathanLeeJ
          JonathanLee @JonathanLee
          last edited by

          @jonathanlee

          Firewalls and AntiVirus is a thing of beauty when it works correctly. It is art.

          This can decode and inspect every single https, http URL not only that the URLs that are cookie related. This inspects for spyware viruses check for issues. Amazing. What a work of art. Google started working Facebook does not like this running for some reason last website issue for me. Bing, Google, News sites, all work just not Facebook.

          squid.JPG

          Make sure to upvote

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.