Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PfSense+Squid Proxy=Error 111 (net::ERR_TUNNEL_CONNECTION_FAILED) - https ONLY

    Scheduled Pinned Locked Moved Firewalling
    8 Posts 7 Posters 17.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dpessanha
      last edited by

      Hi all!

      I'm new to the pfSense world, so I'll assume that the problem can be my n00bness.
      I have a machine with pfSense and Squid Proxy and my network machines are pointing to this machine as the GW. The proxy is working as a charm to all http pages, but the https pages show this error in Google Chrome (the IE doesn't show anything…):  Error 111 (net::ERR_TUNNEL_CONNECTION_FAILED). Ok. I give a F5 and the page loads as if nothing has ever happened. This problem doesn't occour every time I try to load a https page, but its enough to be a headache.

      I know this is my fault in some rule, but I could not guess how to solve this problem. Can anyone help me?

      Thanks in advance!

      PS.: Sorry if I'm in the wrong place in the forum,  but I'm new and n00b here too!
      erro_tunnel_pfSense.jpg
      erro_tunnel_pfSense.jpg_thumb

      1 Reply Last reply Reply Quote 0
      • N
        Nachtfalke
        last edited by

        When googeling for this error it seems that not squid is the problem but the destination web server.
        Which version of squid are you using ? If you use squid 2.7 try with newer squid3 version.

        and if you are using squid3 then set the option "IPv4 first".

        1 Reply Last reply Reply Quote 0
        • D
          dpessanha
          last edited by

          Hi, Nachtfalke!

          Thanks a ton, man! It worked! The option in the pfSense GUI is in Services > Proxy Server > General > Resolv dns v4 first.

          Thanks, man, thanks! =)

          1 Reply Last reply Reply Quote 0
          • V
            volkans80
            last edited by

            @Nachtfalke:

            When googeling for this error it seems that not squid is the problem but the destination web server.
            Which version of squid are you using ? If you use squid 2.7 try with newer squid3 version.

            and if you are using squid3 then set the option "IPv4 first".

            Thank you "Resolve dns v4 first" works!

            1 Reply Last reply Reply Quote 0
            • E
              echowings
              last edited by

              The one is worked! Thanks so much.

              1 Reply Last reply Reply Quote 0
              • E
                EagleDM
                last edited by

                I would also like to confirm this WORKS.

                In fact, if I didn't put this option, all kinds of weirds things starts to happen on gmail and facebook.

                Thanks you!

                1 Reply Last reply Reply Quote 0
                • R
                  respinoza
                  last edited by

                  Where is that option? I have the same problem and i can't find it.

                  IMAGEN 1: https://www.dropbox.com/s/z8ombf8snrjtlbi/1.PNG

                  IMAGEN 2: https://www.dropbox.com/s/rbnfnkpnzlqigh9/2.PNG

                  1 Reply Last reply Reply Quote 0
                  • P
                    Patanours
                    last edited by

                    hi everyone,

                    I enabled "Resolv dns v4 first" but it's always the same error : ERR_TUNNEL_CONNECTION_FAILED

                    I restarted Squid and Squidguard

                    Flush all web caches and flushdns on my PC

                    I'm blocked, any idea gentlemen ? :)

                    1 Reply Last reply Reply Quote 0
                    • First post
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.