Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    OpenSense on SG-2100

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    23 Posts 8 Posters 2.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      michmoor LAYER 8 Rebel Alliance @jimp
      last edited by

      @jimp
      This was suggested on Reddit and i think its a good idea if one has the resources.
      Squid with the unresolved CVEs is probably best sitting behind a firewall . I dunno. Just a thought.

      Firewall: NetGate,Palo Alto-VM,Juniper SRX
      Routing: Juniper, Arista, Cisco
      Switching: Juniper, Arista, Cisco
      Wireless: Unifi, Aruba IAP
      JNCIP,CCNP Enterprise

      1 Reply Last reply Reply Quote 1
      • S
        SteveITS Galactic Empire @JonathanLee
        last edited by

        @JonathanLee said in OpenSense on SG-2100:

        I want the web cache support for Squid is what I am after. I am going to be stuck in 23.05.01 land until the end of time.

        23.09 includes Squid per the blog post.

        re: cache, SSD is recommended for the disk writes on eMMC...
        https://www.netgate.com/supported-pfsense-plus-packages
        https://docs.netgate.com/pfsense/en/latest/troubleshooting/disk-lifetime.html

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote πŸ‘ helpful posts!

        S 1 Reply Last reply Reply Quote 2
        • S
          SteveITS Galactic Empire @SteveITS
          last edited by

          SSD

          @JonathanLee I see from one of your other posts you have a Max so never mind this comment. I like to post it when it comes up since many don't know about the recommendation list (which would help if it was in the docs, or linked from the docs; AFAIK it isn't).

          Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
          When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
          Upvote πŸ‘ helpful posts!

          1 Reply Last reply Reply Quote 1
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Indeed Squid is in 23.09. I agree though, running a separate internal proxy is probably a better option.

            M 1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @stephenw10
              last edited by michmoor

              @stephenw10
              To be fair, commercial solutions like Cisco Umbrella or Zorus do a really better job at this whole proxy thing.
              I know there isn’t a home lab or SMB pricing that makes sense which is really the pain point here for mostly everyone.
              Also I’m not aware of any commercial proxy to be used internally. Is BlueCoat still a thing?

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              JonathanLeeJ 1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee @michmoor
                last edited by

                @michmoor what is bluecoat? I have Squid 6.6 running great in 24 minor issue the status page changed to non squidclient based. But other than that it has a lot of the CVEs fixed I am told it’s the latest and greatest.

                Make sure to upvote

                1 Reply Last reply Reply Quote 0
                • stephenw10S
                  stephenw10 Netgate Administrator
                  last edited by

                  If you want to proxy and filter all the traffic from/to a small country you call Bluecoat. πŸ˜‰

                  M 1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @stephenw10
                    last edited by michmoor

                    @stephenw10
                    SWG are the future. Its been the future? Its here now :)

                    https://www.cloudflare.com/learning/access-management/what-is-a-secure-web-gateway/

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    1 Reply Last reply Reply Quote 1
                    • stephenw10S
                      stephenw10 Netgate Administrator
                      last edited by

                      'SWG' seems like another acronym for what has been around for years. Maybe with a shinier front end glued onto it. πŸ˜‰

                      M 1 Reply Last reply Reply Quote 0
                      • M
                        michmoor LAYER 8 Rebel Alliance @stephenw10
                        last edited by

                        @stephenw10
                        lol oh for sure !

                        Firewall: NetGate,Palo Alto-VM,Juniper SRX
                        Routing: Juniper, Arista, Cisco
                        Switching: Juniper, Arista, Cisco
                        Wireless: Unifi, Aruba IAP
                        JNCIP,CCNP Enterprise

                        1 Reply Last reply Reply Quote 1
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.