Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid - allowed subnets

    pfSense Packages
    3
    7
    7.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B
      bmaster
      last edited by

      I am trying to setup pfsense with squid, but I want to grant access to the proxy to specific ip addresses. So I uncheck "allow users on interface" and under "access control" I enter for example "10.1.2.56/32" in the "allowed subnets"-box. This doesn't work: the client receives an access denied message. I then looked at the squid.conf file (/usr/local/etc/squid/squid.conf) and noticed that the required acl line is created (acl allowed_subnets src 10.1.2.56/32) but there's no matching http_access line. When I add the line manually and restart the squid service, it seems to work…. is this a known problem?

      1 Reply Last reply Reply Quote 0
      • M
        mhab12
        last edited by

        Try toggling the allow users on interface, hit save, turn it off, hit save again.  There have been some issues with the squid.conf interaction with that option in the past.

        1 Reply Last reply Reply Quote 0
        • M
          mhab12
          last edited by

          Also, keep in mind that squid.conf is generated by /usr/local/pkg/squid.inc at boot.  If you want to manually edit your squid.conf - do it here.

          1 Reply Last reply Reply Quote 0
          • B
            bmaster
            last edited by

            That's a quick reply - thanks!

            But it didn't help… I've been trying to get it to work for a few hours now, toggling and saving exactly as you say, but the http_access line just isn't there. I googled the problem and indeed found some old things, but thought it would be solved after so many years... :(

            I also know about the file being overwritten at reboot. It was just a way to try if that was the problem...

            1 Reply Last reply Reply Quote 0
            • B
              bmaster
              last edited by

              Any other ideas?

              1 Reply Last reply Reply Quote 0
              • D
                dvserg
                last edited by

                Use 'Unrestricted IPs' field for allow single ip addresses.

                SquidGuardDoc EN  RU Tutorial
                Localization ru_PFSense

                1 Reply Last reply Reply Quote 0
                • B
                  bmaster
                  last edited by

                  That seems to do the trick, thanks! (don't know why I didn't see that myself, duh)

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.