Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    SquidGuard package TEST

    Scheduled Pinned Locked Moved Russian
    175 Posts 14 Posters 145.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dhipo
      last edited by

      is this ….

      The order of "ACL" is important ...
      look this note:

      Note: The client groups are matched in the order they are defined.

      we need an control to ordering "ACL"s

      Dhix Networks
      Everything Secure

      http://www.dhix.com.br

      1 Reply Last reply Reply Quote 0
      • D
        dvserg
        last edited by

        @dhipo:

        is this ….
        The order of "ACL" is important ...
        look this note:
        Note: The client groups are matched in the order they are defined.
        we need an control to ordering "ACL"s

        Client group this is Sources blocks
        Do you have possible test config with swithching sources blocks? (manually swap and restart squid). I will be able to test tomorrow :-\

        SquidGuardDoc EN  RU Tutorial
        Localization ru_PFSense

        1 Reply Last reply Reply Quote 0
        • D
          dhipo
          last edited by

          no …. source or destinations order is NOT important ....

          important is the ACL order ....  blocking is made based on order of ACL...

          Dhix Networks
          Everything Secure

          http://www.dhix.com.br

          1 Reply Last reply Reply Quote 0
          • D
            dhipo
            last edited by

            i did test order of acl and this is real …. .ACL order is important...

            Dhix Networks
            Everything Secure

            http://www.dhix.com.br

            1 Reply Last reply Reply Quote 0
            • D
              dvserg
              last edited by

              @dhipo:

              i did test order of acl and this is real …. .ACL order is important...

              I now have test via remote access on my work next simple config

              
              src_myip_on = myip
              src_myip_off = myip
              
              acl {
                default .... none // all block
                src_myip_on ... all // all pass
                src_myip_off ... none //all block
              }
              

              –- A --- beginner
              sources  (1)src_myip_on (2)src_myip_off
              ACLS (1)default (2)src_myip_on (3)src_myip_off
              result MyIP Access = pass

              --- B --- swapping acls
              sources  (1)src_myip_on (2)src_myip_off
              ACLS (1)default (2)src_myip_off (3)src_myip_on
              result MyIP Access = pass (!!)

              -- C -- swapping sources
              sources  (1)src_myip_off (2)src_myip_on
              ACLS (1)default (2)src_myip_on (3)src_myip_off
              result MyIP Access = blocked (!!)

              SquidGuardDoc EN  RU Tutorial
              Localization ru_PFSense

              1 Reply Last reply Reply Quote 0
              • D
                dhipo
                last edited by

                you are right ….. the sources order change the result of policy ....  i hate this.... only about lucky .... but my order of sources was right and when i changed policies stop to work.....

                great work ..... SOURCES MUST BE ORDERED TO WORK ....

                Dhix Networks
                Everything Secure

                http://www.dhix.com.br

                1 Reply Last reply Reply Quote 0
                • D
                  dvserg
                  last edited by

                  In sources table no way to mooving table line up/down
                  I have idea add one checkbox field with 3 positions (–/move up/move down)

                  Any other idea?

                  SquidGuardDoc EN  RU Tutorial
                  Localization ru_PFSense

                  1 Reply Last reply Reply Quote 0
                  • P
                    Perry
                    last edited by

                    In sources table no way to mooving table line up/down

                    Maybe you could get around it by first saving it to a temp file first, adding a number 1 2 3 and then add it to conf by number…

                    /Perry
                    doc.pfsense.org

                    1 Reply Last reply Reply Quote 0
                    • D
                      dvserg
                      last edited by

                      For example this

                      src_project.jpg
                      src_project.jpg_thumb

                      SquidGuardDoc EN  RU Tutorial
                      Localization ru_PFSense

                      1 Reply Last reply Reply Quote 0
                      • D
                        dhipo
                        last edited by

                        looks good ….

                        but correct english in some words ...

                        change
                        Sources order have very impotant importance
                        to
                        Sources order have very higy importance.

                        word "chose" the correct is "choose"

                        Dhix Networks
                        Everything Secure

                        http://www.dhix.com.br

                        1 Reply Last reply Reply Quote 0
                        • D
                          dhipo
                          last edited by

                          new thing ….

                          on the Destinations tab i cannot add an redirect url all tries give me the following message.

                          The following input errors were detected:

                          * Redirect must contains valid url. Example: 'http://www.my.com', 'https://my.com', 'ftp://my.com'

                          i try put in the field redirect

                          http://www.mydom.com.br/
                          http://www.mydom.com.br/test.htm
                          403:http://www.mydom.com.br/
                          403:http://www.mydom.com.br/test.htm

                          all with errors

                          Dhix Networks
                          Everything Secure

                          http://www.dhix.com.br

                          1 Reply Last reply Reply Quote 0
                          • D
                            dvserg
                            last edited by

                            Yes .. may be validator problem
                            Temporary - assign only '404'
                            User will view 404 error page

                            SquidGuardDoc EN  RU Tutorial
                            Localization ru_PFSense

                            1 Reply Last reply Reply Quote 0
                            • P
                              Perry
                              last edited by

                              Source order is of high importance. Sources are evaluated on a first-match basis
                              Wrong order:
                              First source entry is the range 10.0.0.0/24 and second entry is 10.0.0.15 (or 10.0.0.15/32 )
                              Right order:
                              First source entry is the single ip 10.0.0.15 (or 10.0.0.15/32 ) then the overlaying range 10.0.0.0/24

                              My none native language suggestion :)

                              /Perry
                              doc.pfsense.org

                              1 Reply Last reply Reply Quote 0
                              • D
                                dvserg
                                last edited by

                                I shall is thanked for good english text

                                SquidGuardDoc EN  RU Tutorial
                                Localization ru_PFSense

                                1 Reply Last reply Reply Quote 0
                                • D
                                  dvserg
                                  last edited by

                                  Uhhm
                                  Ready for test
                                  Need update from site files
                                  'squidguard.inc'
                                  'squidguard_configurator.inc'
                                  'squidguard_src.xml'
                                  OR reinstall

                                  SquidGuardDoc EN  RU Tutorial
                                  Localization ru_PFSense

                                  1 Reply Last reply Reply Quote 0
                                  • D
                                    dhipo
                                    last edited by

                                    not necessary squidgaurd.xml ????

                                    Dhix Networks
                                    Everything Secure

                                    http://www.dhix.com.br

                                    1 Reply Last reply Reply Quote 0
                                    • D
                                      dhipo
                                      last edited by

                                      i did an test
                                      if an source is deleted (eg … source # 0) to other sources become indexed is necessary open the source #1 and move it to #0

                                      but moving orders is good .... and working ,..

                                      Dhix Networks
                                      Everything Secure

                                      http://www.dhix.com.br

                                      1 Reply Last reply Reply Quote 0
                                      • D
                                        dvserg
                                        last edited by

                                        @dhipo:

                                        not necessary squidgaurd.xml ????

                                        I modified only this 3 files

                                        i did an test
                                        if an source is deleted (eg … source # 0) to other sources become indexed is necessary open the source #1 and move it to #0

                                        or i stupid, or my translator.. what processed if deleted all sources??? Please looking what's happening with 'squidguard.conf' in this moment? Broken or no?

                                        but moving orders is good …. and working ,..

                                        Sources order in gui das is correspond order in squidguard.cfg

                                        PS i test all bugs too, but i need more 'test statistic' for diagnose BUG
                                        PS2 Thanks for you job  :)

                                        SquidGuardDoc EN  RU Tutorial
                                        Localization ru_PFSense

                                        1 Reply Last reply Reply Quote 0
                                        • D
                                          dhipo
                                          last edited by

                                          ok … english is not my language too... but i ll try again ....

                                          remove an source, example source number 0... the others sources are not modified....
                                          to modify , you need open next source, move it to number 0 and save ...

                                          yes ... the squidguard.conf is ok ....

                                          Dhix Networks
                                          Everything Secure

                                          http://www.dhix.com.br

                                          1 Reply Last reply Reply Quote 0
                                          • D
                                            dhipo
                                            last edited by

                                            @dhipo:

                                            remove an source, example source number 0… the others sources are not modified....
                                            to modify , you need open next source, move it to number 0 and save ...

                                            this only for cosmetic …. squidguard.conf is ok

                                            Dhix Networks
                                            Everything Secure

                                            http://www.dhix.com.br

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.