• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Transparent Squid via Splice = Intermittent SSL Connectivity Failures

Scheduled Pinned Locked Moved Cache/Proxy
3 Posts 2 Posters 827 Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • T
    The_Boss
    last edited by The_Boss Feb 11, 2023, 11:44 PM Feb 11, 2023, 11:40 PM

    I set up Squid as below, with no caching. The environment is two heavy users and about 50 IOT devices. 2.6.0-RELEASE (amd64) FreeBSD 12.3-STABLE

    Intermittently I get errors like:

    This site can’t provide a secure connection
    www.aliexpress.com sent an invalid response.
    Try running Windows Network Diagnostics.
    ERR_SSL_PROTOCOL_ERROR

    Access log simply shows:

    1676158285.661 0 192.168.0.101 NONE/409 4034 CONNECT www.aliexpress.us:443 - HIER_NONE/- text/html
    1676158285.661 0 192.168.0.101 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
    1676158285.662 0 192.168.0.101 NONE/200 0 CONNECT 104.69.113.196:443 - HIER_NONE/- -
    1676158285.663 0 192.168.0.101 NONE/409 4034 CONNECT www.aliexpress.us:443 - HIER_NONE/- text/html
    1676158285.663 0 192.168.0.101 NONE/000 0 NONE error:transaction-end-before-headers - HIER_NONE/- -
    1676158285.664 0 192.168.0.101 NONE/200 0 CONNECT 104.69.113.196:443 - HIER_NONE/- -

    If I wait and check later, it usually works. I progressively increased SSL Certificate Deamon Children to 200, but only moderate improvement it seems. I also tried Modern and Intermediate, key size, etc. I tried a few other tips and searched posts, but nothing has resolved it.

    There are many posts and tutorials to support that the certificate does not need to be added to the user store.

    Any tips?

    611b35f1-2aa7-43c2-9f09-c748e628d33c-image.png

    M 1 Reply Last reply Feb 11, 2023, 11:51 PM Reply Quote 0
    • M
      michmoor LAYER 8 Rebel Alliance @The_Boss
      last edited by Feb 11, 2023, 11:51 PM

      @the_boss you will need to whitelist the domain. It’s possible there is certificate pinning going on.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      T 1 Reply Last reply Feb 12, 2023, 12:30 AM Reply Quote 0
      • T
        The_Boss @michmoor
        last edited by Feb 12, 2023, 12:30 AM

        @michmoor said in Transparent Squid via Splice = Intermittent SSL Connectivity Failures:

        @the_boss you will need to whitelist the domain. It’s possible there is certificate pinning going on.

        I see, thanks. It is my understanding that Peek/Splice has no issue with pinning, and only Bump does, no?

        The quantity of things getting blocked randomly would make any whitelisting insurmountable. Others seem to report no challenges with Splice.

        1 Reply Last reply Reply Quote 0
        3 out of 3
        • First post
          3/3
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
          This community forum collects and processes your personal information.
          consent.not_received