Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squidguard ACL help [Solved]

    Scheduled Pinned Locked Moved Cache/Proxy
    1 Posts 1 Posters 293 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance
      last edited by michmoor

      Some background.
      I have pfsense runnign with HA proxy. My internal sites are behind it and everything is working as it should.
      I am also running Squid Proxy (Transparent) for mostly all VLANs and that is working without issue.
      Right now if you are on my IoT VLAN, you have access to go to any of my internal sites. The squid proxy is doing what it should do.
      I have SG enabled and i have 2x ACLs.
      Permit vault.example.com
      Deny example.com
      My thinking goes is that i do want my password manager (vault) accessible through the proxy and everything else should be dropped.
      My group ACL target list shows the following
      0f897bf2-ec97-4859-8309-9a30e7501e70-image.png

      The problem is that this doesnt work. All internal sites are still accessible.

      Whats Odd is that in the Blocked log file you see the request hitting the block ACL but its still permitted through
      19cf0610-798b-458c-95c3-7e0ee2d68d64-image.png

      I do realize i could rely on firewall rules instead by having all RFC1918 address bypass the proxy but i dont want to do that.
      What am I missing?

      Those long nights of tshooting the issue and it was a crazy misconfiguration on my part. I did have Bypass Proxy for RFC1918 enabled but i thought i had it disabled.
      While typing out my post here i double checked all my settings.
      Problem solved. sheesh....

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      1 Reply Last reply Reply Quote 0
      • First post
        Last post
      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.