Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid port 3128 and Firewall Rules

    Scheduled Pinned Locked Moved Firewalling
    squidfirewall rulesdefault denyacllan
    27 Posts 2 Posters 8.4k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M Offline
      mcury Rebel Alliance @JonathanLee
      last edited by

      @JonathanLee said in Squid port 3128 and Firewall Rules:

      @mcury Yes I do have both, my XBOX uses the transparent side

      Have you bypassed all other hosts that don't need transparent proxy in the Squid settings ?

      Disable transparent proxy for one sec and test.

      If it works, enable it again and try to bypass clients that are pointing to the proxy (explicit) in the transparent settings.

      dead on arrival, nowhere to be found.

      JonathanLeeJ 2 Replies Last reply Reply Quote 1
      • JonathanLeeJ Offline
        JonathanLee @mcury
        last edited by

        @mcury How do you bypass for example one host like 192.168.1.17 from the SSL intercept but still make it use the the transparent proxy?

        Make sure to upvote

        M 1 Reply Last reply Reply Quote 0
        • M Offline
          mcury Rebel Alliance @JonathanLee
          last edited by mcury

          @JonathanLee said in Squid port 3128 and Firewall Rules:

          How do you bypass for example one host like 192.168.1.17 from the SSL intercept but still make it use the the transparent proxy?

          1- Disable transparent proxy
          2- You would have to create the transparent NAT manually, using a ! in the source, with that IP address.
          3- That NAT would have to redirect outbound TCP 443 connections to 127.0.0.1 3128.

          Test like that, if doesn't work, try to change the port in the 3rd step to 3129.

          I think that will do it.
          95214dee-5a00-4b21-af44-733c5d20aa41-image.png

          Note that you would also need to create one for port 80.

          dead on arrival, nowhere to be found.

          1 Reply Last reply Reply Quote 1
          • JonathanLeeJ Offline
            JonathanLee @mcury
            last edited by

            @mcury Thanks!!!! that helps a lot I no longer see double requests for everything and it all still works!!! The XBOX uses transparent and UpNp and all the devices that know about the proxy don't need the transparent!!! YES!!!

            Make sure to upvote

            M 1 Reply Last reply Reply Quote 1
            • M Offline
              mcury Rebel Alliance @JonathanLee
              last edited by

              @JonathanLee said in Squid port 3128 and Firewall Rules:

              @mcury Thanks!!!! that helps a lot I no longer see double requests for everything and it all still works!!! The XBOX uses transparent and UpNp and all the devices that know about the proxy don't need the transparent!!! YES!!!

              Oh, good to hear that :)

              dead on arrival, nowhere to be found.

              JonathanLeeJ 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ Offline
                JonathanLee @mcury
                last edited by

                @mcury

                Thanks all I see is WAN blocks now !! YES!!! THANK YOU

                Screenshot 2023-10-21 at 1.07.06 PM.png

                Make sure to upvote

                1 Reply Last reply Reply Quote 1
                • JonathanLeeJ Offline
                  JonathanLee
                  last edited by

                  Could it be set flags SYN ACK ? and or state type keep or sloppy ?

                  Make sure to upvote

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.