Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Filtering confusion

    Scheduled Pinned Locked Moved Firewalling
    13 Posts 2 Posters 2.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G Offline
      gerry613
      last edited by

      Hello there.
      It is now couple days I am playing with the packages and settings and I cannot see to find the best option for my situation.
      I am running pfsense 2.2 32 bits
      I would like to block outgoing traffic based on keyword or URL (mostly keyword though, facebook, hidemyass, amazon etc…)

      I check the firewall rules and as it is based on IP addresses, that doesnt do the job
      I tried Dansguardian, and for whatever reason, everything go through
      I tried squid + squidguard, it seems to be blocking absolutely everything as soon as I turn the proxy filter on and squidguard service never starts.

      My question is : does anyone managed to successfully filter outgoing traffic
      if yes , what did you use?

      Thank you for any info.

      Gerry

      1 Reply Last reply Reply Quote 0
      • KOMK Offline
        KOM
        last edited by

        Squid and SquidGuard will do what you want.  You just need to get them working first.

        1 Reply Last reply Reply Quote 0
        • G Offline
          gerry613
          last edited by

          i  checked quite a decent amount of tutos and never can get SquidGuard running  and I do not see any log where i can see what is going on :'(
          edit: I also tried squid3

          1 Reply Last reply Reply Quote 0
          • KOMK Offline
            KOM
            last edited by

            Is there any way you can run x64 instead of i386?  I haven't played much with the 32-bit stuff as it's going EOL soon enough.

            1 Reply Last reply Reply Quote 0
            • G Offline
              gerry613
              last edited by

              unfortunately no i cannot  :( hardware limitation

              1 Reply Last reply Reply Quote 0
              • KOMK Offline
                KOM
                last edited by

                Well, I would install Squid3 and get that working first.  Then move to SquidGuard.

                1 Reply Last reply Reply Quote 0
                • G Offline
                  gerry613
                  last edited by

                  @KOM:

                  Well, I would install Squid3 and get that working first.  Then move to SquidGuard.

                  I get squid 3 running no problem but the SquidGuqrd never starts
                  Is there any screenshot or log I can show you to help you pinpoint the issue ?

                  here is an example of logs:
                  21.02.2015 21:49:23 squidGuard stopped (1424573363.735)
                  21.02.2015 21:49:23 db update done
                  21.02.2015 21:49:23 squidGuard 1.4 started (1424573301.973)
                  21.02.2015 21:47:32 squidGuard stopped (1424573252.961)
                  21.02.2015 21:47:32 db update done
                  21.02.2015 21:47:32 squidGuard 1.4 started (1424573252.960)
                  21.02.2015 21:46:41 squidGuard stopped (1424573201.525)
                  21.02.2015 21:46:41 db update done
                  21.02.2015 21:46:41 squidGuard 1.4 started (1424573201.523)
                  21.02.2015 21:45:53 squidGuard stopped (1424573153.959)

                  Squid is running, I can see entries populating in the proxy monitor section

                  1 Reply Last reply Reply Quote 0
                  • KOMK Offline
                    KOM
                    last edited by

                    From what I understand, with the new SquidGuard it can appear to be in a stopped state when there is nothing for it to do.  Have you tested the blocking functionality?

                    1 Reply Last reply Reply Quote 0
                    • G Offline
                      gerry613
                      last edited by

                      @KOM:

                      From what I understand, with the new SquidGuard it can appear to be in a stopped state when there is nothing for it to do.  Have you tested the blocking functionality?

                      I loaded the blacklist from shallalist.tar.gz  and created one custom target category with the facebook and amazon keyword
                      also Denied the Social ACL

                      Still I am able to fully able browse those sites :(

                      1 Reply Last reply Reply Quote 0
                      • KOMK Offline
                        KOM
                        last edited by

                        Are you running Squid in standard or transparent mode?  If standard, do you have ports 80 and 443 blocked on LAN?  What is your browser set to for proxy config?  Your browser may be going straight out the firewall instead of via Squid.

                        1 Reply Last reply Reply Quote 0
                        • G Offline
                          gerry613
                          last edited by

                          I am using the transparent mode.
                          My understanding was i do not need to set up the proxy on my browser with that mode.( i would like to avoid to ahve to configure a prxy on each devices)

                          1 Reply Last reply Reply Quote 0
                          • KOMK Offline
                            KOM
                            last edited by

                            The problem with transparent mode is that you can't effectively filter HTTPS sites without installing a trusted cert on every client.  Better to use WPAD to allow your clients to dynamically locate and use the proxy.  You can filter HTTPS without triggering Man in the Middle warnings.  Details here:

                            WPAD Autoconfigure for Squid

                            You can even use pfSense to host the wpad.dat file as long as you have WebGUI running in HTTP mode and not HTTPS.

                            1 Reply Last reply Reply Quote 0
                            • G Offline
                              gerry613
                              last edited by

                              thx i ll give it a try

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.