<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Portforward windows squid]]></title><description><![CDATA[<p dir="auto">Hello,<br />
I’m using Pfsense 1.2.2  to lets you provide restricted internet access to guests via captive portal.<br />
I need manage access (acl, blacklist etc) from my SquidNT under Windows (I can’t use a linux squid).<br />
I have tried looking the answer with google and here, but …<br />
I need some help</p>
<p dir="auto" style="text-align:right">|–-------------</p>
<table class="table table-bordered table-striped">
<thead>
<tr>
<th>Implementation</th>
</tr>
</thead>
</table>
<p dir="auto">Addresses used<br />
172.16.10.92/16 SquidNT (Windows Server)<br />
172.16.10.162/16 RAS (Microsoft IAS)<br />
172.16.10.15/16 DC (Domain Controller-Active Directory))<br />
192.168.10.254/24 AP (Wireless Access Point)<br />
192.168.10.X/24 Guests<br />
172.16.10.110/16 (WAN) &amp; 192.168.10.1/24 (LAN) Pfsense (Captive Portal)</p>
<p dir="auto" style="text-align:center">-------------</p>
<table class="table table-bordered table-striped">
<thead>
<tr>
<th>Network diagram</th>
</tr>
</thead>
</table>
<p dir="auto">Internet<br />
|<br />
|<br />
SquidNT        RAS            DC<br />
|              |              |<br />
-------------SWITCH------------<br />
                |<br />
              PFSENSE<br />
                |     <br />
              AP<br />
              |<br />
              Guests</p>
<p dir="auto">I try to implement a policy based routing rule that redirect all trafic from Lan  (80 ) to my squidNT (3128) by create a portforward at interface Lan</p>
<p dir="auto">But SquidNT (isn’t running in transparent mode) return an error : Invalid request.</p>
<p dir="auto"><em>Invalid request<br />
some aspect of the HTTP request is invalid. Possible Problems:<br />
-Missing or unknown request method<br />
-missing url<br />
-missing http identifier (http/1.0)<br />
-content-length missing for POST or PUT request<br />
-illegal character in hostname; underscores are not allowed</em></p>
<p dir="auto">Entry in access.log :</p>
<p dir="auto">1202027164.370 2 192.168.0.1 TCP_DENIED/400 2028 GET error:invalid-request - NONE/- text/html</p>
<p dir="auto">It’s a problem with my policy or squid must run in transparent mode?</p>
<p dir="auto">So, I have tried using transparent proxy from pfsense and cache_peer parent to my squidNT (it can’t run transparent mode)<br />
I add in  squid.conf (pfsense) :</p>
<p dir="auto">Cache_peer IP_fromMySquidNT parent 3128 7 no-query proxy-only login=loginuser:passworduser<br />
Never_direct allow all</p>
<p dir="auto">But I’ve a different error from access to my squidNT ( ntlm auth or LDAP) : access cache denied.</p>
<p dir="auto">ERROR<br />
The requested URL could not be retrieved</p>
<p dir="auto">–------------------------------------------------------------------------------</p>
<p dir="auto">While trying to retrieve the URL: http://2007.fr.msn.com/ArticleView.aspx?</p>
<p dir="auto">The following error was encountered:</p>
<p dir="auto">Access Denied.<br />
Access control configuration prevents your request from being allowed at this time. Please contact your service provider if you feel this is incorrect.<br />
Your cache administrator is root.</p>
<p dir="auto">I can’t login at this state (not ntlm box etc)</p>
<p dir="auto">Is this possible, and if so how do I accomplish it?</p>
<p dir="auto">Thanks</p>
<p dir="auto">PS: I don't think that pfsense problem.<br />
I'm not an expert with policy rule</p>
]]></description><link>https://forum.netgate.com/topic/19098/portforward-windows-squid</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Jul 2026 15:12:12 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/19098.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 06 Nov 2009 11:46:25 GMT</pubDate><ttl>60</ttl></channel></rss>