• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

RESOLVED: Warning: Possible bypass attempt. Found multiple slashes where only one is expected: http://dl.delivery.mp.microsoft.com/filestreamingservice//files/

Scheduled Pinned Locked Moved Cache/Proxy
12 Posts 1 Posters 1.7k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • J
    JonathanLee
    last edited by JonathanLee Jan 18, 2022, 5:47 PM Jan 18, 2022, 12:47 AM

    Help I keep getting this error for Windows updates with Squid guard running. Under the proxy live status it shows an attempt to connect to http and a url and will not pass traffic. Any ideas?

    windows updates.JPG

    (Image: Error for http updates)

    httpissues.JPG

    (Image: Squid Proxy showing abort)

    Make sure to upvote

    J 1 Reply Last reply Jan 18, 2022, 12:51 AM Reply Quote 0
    • J
      JonathanLee @JonathanLee
      last edited by JonathanLee Jan 18, 2022, 12:56 AM Jan 18, 2022, 12:51 AM

      @jonathanlee

      https://forum.netgate.com/topic/35377/squidguard-squid-getting-default-access/14?_=1642466193772&lang=en-US

      I adapted the config this did not resolve per the forum above

      /usr/local/pkg/squidGuard_configurator.inc

      adapted.JPG

      Same result. Normalized this change.

      This method change did not fix this issue.

      Make sure to upvote

      J 1 Reply Last reply Jan 18, 2022, 12:55 AM Reply Quote 0
      • J
        JonathanLee @JonathanLee
        last edited by Jan 18, 2022, 12:55 AM

        @jonathanlee

        No traffic will pass for http based update requests. If I go directly to this URL it will work and download however.

        httpissues2.JPG

        (Image: Traffic shows 0 and will timeout because of issues)

        Make sure to upvote

        J 1 Reply Last reply Jan 18, 2022, 9:04 AM Reply Quote 0
        • J JonathanLee referenced this topic on Jan 18, 2022, 12:58 AM
        • J
          JonathanLee @JonathanLee
          last edited by Jan 18, 2022, 9:04 AM

          @jonathanlee

          Tested GPO's for Windows 10

          Administrative Templates > Windows Components > Data Collection and Preview Builds > Configure Authenticated Proxy usage for the Connected User Experience and Telemetry Service.

          Administrative Templates > Windows Components > Data Collection and Preview Builds > Configure connected user experiences and telemetry:

          Administrative Templates > Windows Components > Microsoft Defender Antivirus > Define proxy server for connecting to the network.

          Ran netsh winhttp set proxy <proxy>:<port> "example 192.168.1.1:3128"

          Reference cited:

          Navigation. ConfigExamples/Caching/WindowsUpdates - Squid Web Proxy Wiki. (n.d.). Retrieved January 18, 2022, from https://wiki.squid-cache.org/ConfigExamples/Caching/WindowsUpdates

          Mjcaparas. (n.d.). Configure device proxy and internet connection settings. Configure device proxy and Internet connection settings | Microsoft Docs. Retrieved January 18, 2022, from https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/configure-proxy-internet?view=o365-worldwide

          Make sure to upvote

          J 1 Reply Last reply Jan 18, 2022, 9:05 AM Reply Quote 0
          • J
            JonathanLee @JonathanLee
            last edited by Jan 18, 2022, 9:05 AM

            @jonathanlee system started a download and stopped at 2 percent this time after Winhttp proxy changes.

            Make sure to upvote

            J 1 Reply Last reply Jan 18, 2022, 5:46 PM Reply Quote 0
            • J
              JonathanLee @JonathanLee
              last edited by Jan 18, 2022, 5:46 PM

              @jonathanlee

              RESOLVED!!

              Set GPOS to not configured per above. Reboot system Windows 10 and Netgate running pfSense. You must remove all Squidguard URL blocks for anything that is "azureedge. net", example fp-as-azureedge. net. Set Windows in two places one with "netsh http set proxy" to use with Http Updates.

              d104d4d5-f7cb-4a2a-b461-87a88d641db4-image.png

              Once this change was made the systems worked with http updates.

              cc7632b4-bd3f-4c77-89b2-beb992ce4c89-image.png
              The other set Windows Proxy settings in GUI.

              744dcb08-8b63-434b-8c69-006bdafcec24-image.png

              All update traffic now works.

              Make sure to upvote

              J 1 Reply Last reply Jan 20, 2022, 5:31 PM Reply Quote 0
              • J
                JonathanLee @JonathanLee
                last edited by Jan 20, 2022, 5:31 PM

                @jonathanlee

                Screen Shot 2022-01-20 at 9.28.45 AM.png

                (Image: HITS)

                Screen Shot 2022-01-20 at 9.30.42 AM.png

                (Image: Firewall wpad rules)

                Screen Shot 2022-01-20 at 9.30.56 AM.png

                (Image: NAT rules)

                Make sure to upvote

                J 1 Reply Last reply Jan 20, 2022, 5:34 PM Reply Quote 0
                • J
                  JonathanLee @JonathanLee
                  last edited by JonathanLee Jan 24, 2022, 10:29 PM Jan 20, 2022, 5:34 PM

                  @jonathanlee

                  Screen Shot 2022-01-24 at 2.29.08 PM.png

                  (Image: Refresh used)

                  Amazing thank you to all that have helped fix this.

                  Make sure to upvote

                  J 1 Reply Last reply Jan 20, 2022, 5:35 PM Reply Quote 0
                  • J
                    JonathanLee @JonathanLee
                    last edited by Jan 20, 2022, 5:35 PM

                    @jonathanlee

                    A main issue I found also while working this was this log did not show populated in squidguard until a reinstall.

                    Screen Shot 2022-01-20 at 9.34.48 AM.png

                    Make sure to upvote

                    J 1 Reply Last reply Jan 24, 2022, 10:28 PM Reply Quote 0
                    • J
                      JonathanLee @JonathanLee
                      last edited by Jan 24, 2022, 10:28 PM

                      @jonathanlee

                      I also added ports to the safe port list that are specific to the firewall itself port 3128, 3129, 1344. The others that are added are specific to my needs and not related to the firewall.

                      Screen Shot 2022-01-24 at 2.25.55 PM.png

                      Make sure to upvote

                      J 1 Reply Last reply Jan 24, 2022, 10:31 PM Reply Quote 0
                      • J
                        JonathanLee @JonathanLee
                        last edited by Jan 24, 2022, 10:31 PM

                        @jonathanlee Traffic now shows flowing with http requests as well as solid hits for updates.

                        Make sure to upvote

                        J 1 Reply Last reply Jan 26, 2022, 8:08 PM Reply Quote 0
                        • J
                          JonathanLee @JonathanLee
                          last edited by Jan 26, 2022, 8:08 PM

                          @jonathanlee

                          Playing with this setting also seemed to improve the refresh hits for windows updates.

                          4302a82a-f0b8-4c37-8b9a-6456a4d325e2-image.png

                          Squid's updates that are cached are considered a different pc over the standard windows url that provides updates

                          Make sure to upvote

                          1 Reply Last reply Reply Quote 0
                          1 out of 12
                          • First post
                            1/12
                            Last post
                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                            This community forum collects and processes your personal information.
                            consent.not_received