• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense behind a proxy server is not connecting to the internet

Scheduled Pinned Locked Moved General pfSense Questions
14 Posts 3 Posters 1.4k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • A
    arsalan
    last edited by Oct 27, 2022, 8:19 AM

    Hi,
    I have a Pfsense machine behind a proxy. The proxy server is connected to the internet.
    All of the LAN clients are supposed to connect to the Internet through Pfsense.
    How should I configure Pfsense in this scenario?

    I tried this configuration unsuccessfully:
    System-->Advanced-->Miscellaneous-->Proxy URL: 192.168.55.100
    System-->Advanced-->Miscellaneous-->Proxy Port:8080 (no username, no password)

    Thank you

    1 Reply Last reply Reply Quote 0
    • S
      stephenw10 Netgate Administrator
      last edited by Oct 27, 2022, 5:57 PM

      That field configured pfSense itself to use the proxy for connections it creates itself, for updates for example.
      https://docs.netgate.com/pfsense/en/latest/config/advanced-misc.html#proxy-support

      If clients are not set to use the proxy directly and the proxy is not redirecting that traffic itself you could add a port forward to redirect client web traffic to it in pfSense. That's what Squid does if you're running that in pfSense.

      Steve

      Z 1 Reply Last reply May 29, 2024, 3:48 PM Reply Quote 0
      • Z
        zaibi12345 @stephenw10
        last edited by May 29, 2024, 3:48 PM

        @stephenw10
        Sir i am stuck please help me below

        I am working in an organization already having proxy configured, and managed by other department
        Now I install pfsense and set wan as dhcp and lan with static and enable dhcp I am able to ping my company network resouces from that dhcp (used win 10 as vm ) also set company's proxy in system-->advanced --> misc tab alongwith port.
        I would like to pass traffic through pfsense I also installed squid package and set proxy address of my pfsense LAN interface alongwith 3128 port but unable to browse internet (err connection time out) but ping works fine
        when I put company's proxy then internet works fine but i need to pass traffic through my pfsense
        please help me I am new to pfsense need your kind support
        thankyou

        WAN IP static 10.101.4.38 DNS 10.10.0.10 and 11---> LAN IP 192.168.1.100 (dhcp enabled) dns for client 10.101.4.1 and 8.8.8.8

        1 Reply Last reply Reply Quote 0
        • S
          stephenw10 Netgate Administrator
          last edited by May 29, 2024, 5:44 PM

          If you are using Squid you need to set the upstream proxy in Squid directly in the Remote Cache settings.

          Z 1 Reply Last reply May 30, 2024, 12:13 PM Reply Quote 0
          • Z
            zaibi12345 @stephenw10
            last edited by May 30, 2024, 12:13 PM

            @stephenw10
            Sir I already set remote cache , screen shot is below attached
            d03789a9-9c9c-401d-a131-7a3d5b071b2b-image.png

            0fee46c6-9b2c-4f8d-809c-910abd894ada-image.png

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by May 30, 2024, 12:33 PM

              Do you see connections to it in the state table? (Diag > States)

              Z 1 Reply Last reply May 30, 2024, 1:02 PM Reply Quote 0
              • Z
                zaibi12345 @stephenw10
                last edited by May 30, 2024, 1:02 PM

                @stephenw10
                Sir connection from wan ip to my actual production proxy is established as stated below
                bcd1e646-6515-43a3-a445-b2e7fbe77c8e-image.png

                complete states are below

                99646920-880a-427c-baa8-925ef5e0b0fe-image.png

                1 Reply Last reply Reply Quote 0
                • S
                  stephenw10 Netgate Administrator
                  last edited by May 30, 2024, 1:08 PM

                  So what is not working here? Does the upstream proxy show it failing?

                  Z 1 Reply Last reply May 30, 2024, 1:14 PM Reply Quote 0
                  • Z
                    zaibi12345 @stephenw10
                    last edited by May 30, 2024, 1:14 PM

                    @stephenw10
                    sir actually ping to upstream works fine but browsing is not err connectin timed out is showing if i give proxy to browser but it i pass traffic from prod proxy then internet works fine but i want to pass traffic through my pfsense,
                    Is there any network restriction may from production side ? actually wan ip 10.101.4.38 is of my lab and this network is fine for browsing this ip should be enough to communicate with the world.
                    any suggestions is highly appreciated sir

                    1 Reply Last reply Reply Quote 0
                    • S
                      stephenw10 Netgate Administrator
                      last edited by May 30, 2024, 1:24 PM

                      Does it show blocked on the upstream proxy?

                      Is it authenticated? Do you have a username/password entered there?

                      Z 1 Reply Last reply May 30, 2024, 1:30 PM Reply Quote 0
                      • Z
                        zaibi12345 @stephenw10
                        last edited by May 30, 2024, 1:30 PM

                        @stephenw10
                        there is no username password
                        just ip and port no

                        1 Reply Last reply Reply Quote 0
                        • S
                          stephenw10 Netgate Administrator
                          last edited by May 30, 2024, 1:38 PM

                          Probably need to check the logs then. Both in Squid and the upstream proxy.

                          1 Reply Last reply Reply Quote 0
                          • S
                            stephenw10 Netgate Administrator
                            last edited by May 30, 2024, 1:42 PM

                            Oh you might need this in the advanced options:
                            Screenshot from 2024-05-30 14-42-00.png

                            Z 1 Reply Last reply May 30, 2024, 1:49 PM Reply Quote 1
                            • Z
                              zaibi12345 @stephenw10
                              last edited by May 30, 2024, 1:49 PM

                              @stephenw10
                              superb sir you are awesome it works fine thankyou so much sir

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                [[user:consent.lead]]
                                [[user:consent.not_received]]