Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Haproxy and acme setup for TLS inspection

    Scheduled Pinned Locked Moved General pfSense Questions
    3 Posts 2 Posters 194 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      chopster123
      last edited by

      I have lets encrypt cert installed on pfsense firewall and client pc. I cant find any information on how to setup MITM TLS inspection. After certs I don't know what to do next. Also how can i see unencrypted traffic after adding certs. Am I supposed to setup a reverse proxy with HaProxy, or use a virtual ip and mirror traffic. Also I want to keep my Wan closed when following steps. I want to set this up so i can use suricata on Lan traffic. Can you guys give me some leads on what to do next hardware or software needed and steps, or any websites or terms that will lead me on the right track?

      NollipfSenseN 1 Reply Last reply Reply Quote 0
      • NollipfSenseN
        NollipfSense @chopster123
        last edited by

        @chopster123 Did you saw this: https://docs.netgate.com/pfsense/en/latest/packages/haproxy.html and https://docs.netgate.com/pfsense/en/latest/troubleshooting/haproxy.html you can watch this video: https://www.youtube.com/watch?v=gVOEdt-BHDY

        Get busy...

        pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
        pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

        C 1 Reply Last reply Reply Quote 0
        • C
          chopster123 @NollipfSense
          last edited by

          @NollipfSense Thanks

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.