Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Limiter blocks internet access (Squid transparent proxy)

    Scheduled Pinned Locked Moved Traffic Shaping
    73 Posts 34 Posters 33.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      Abhishek
      last edited by

      @doktornotor:

      Well then stick with 2.1.5 until fixed.

      Can any1 share 2.1.5 v pfsense usb image ?

      2.3-RC (amd64)
      built on Mon Apr 04 17:09:32 CDT 2016
      FreeBSD 10.3-RELEASE
      Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz

      darkstat 3.1.2_1
      Lightsquid 3.0.3_1
      mailreport 3.0_1
      pfBlockerNG 2.0.9_1  
      RRD_Summary 1.3.1_2
      snort 3.2.9.1_9  
      squid 0.4.16_1  
      squidGuard 1.14_1
      syslog-ng 1.1.2_2

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        That's a pretty good question.

        I just clicked around and couldn't find a 2.1.5 download.

        You might want to start thinking about other products/distros if you can't wait months for the functionality you need.

        I <3 pfSense but this limiter shit is getting old.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • D
          doktornotor Banned
          last edited by

          @Derelict:

          That's a pretty good question.

          I just clicked around and couldn't find a 2.1.5 download.

          You clicking skills suck.  ;D :P

          Just click on the "Just show me the mirrors" on the download page. Select one, and go to "old" dir.

          1 Reply Last reply Reply Quote 0
          • DerelictD
            Derelict LAYER 8 Netgate
            last edited by

            Didn't see the old dir.  Knew it was there somewhere.  Thanks.

            Chattanooga, Tennessee, USA
            A comprehensive network diagram is worth 10,000 words and 15 conference calls.
            DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
            Do Not Chat For Help! NO_WAN_EGRESS(TM)

            1 Reply Last reply Reply Quote 0
            • A
              Alfanetindo
              last edited by

              SOLVED*

              I managed to find a simple fix. All I needed to do was create a pass all firewall rule on the (LAN) interface for port 3128 (my proxy port).

              IPv4 TCP * * * 3128 * none   Rule to allow transparent proxy to work

              It worked and the speed limiter still works also.

              1 Reply Last reply Reply Quote 0
              • A
                Abhishek
                last edited by

                @Alfanetindo:

                SOLVED*

                I managed to find a simple fix. All I needed to do was create a pass all firewall rule on the (LAN) interface for port 3128 (my proxy port).

                IPv4 TCP * * * 3128 * none   Rule to allow transparent proxy to work

                It worked and the speed limiter still works also.

                anyone else tested this ?

                2.3-RC (amd64)
                built on Mon Apr 04 17:09:32 CDT 2016
                FreeBSD 10.3-RELEASE
                Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz

                darkstat 3.1.2_1
                Lightsquid 3.0.3_1
                mailreport 3.0_1
                pfBlockerNG 2.0.9_1  
                RRD_Summary 1.3.1_2
                snort 3.2.9.1_9  
                squid 0.4.16_1  
                squidGuard 1.14_1
                syslog-ng 1.1.2_2

                1 Reply Last reply Reply Quote 0
                • G
                  gringo13
                  last edited by

                  @Abhishek:

                  @Alfanetindo:

                  SOLVED*

                  I managed to find a simple fix. All I needed to do was create a pass all firewall rule on the (LAN) interface for port 3128 (my proxy port).

                  IPv4 TCP * * * 3128 * none   Rule to allow transparent proxy to work

                  It worked and the speed limiter still works also.

                  anyone else tested this ?

                  Limiter still not working!

                  1 Reply Last reply Reply Quote 0
                  • T
                    techgs
                    last edited by

                    I can confirm that the issue solved 100 %

                    My configuration :

                    1.  Pfsense Version :  2.2.4-RELEASE (amd64)
                    built on Sat Jul 25 19:57:37 CDT 2015

                    2.  Packages Installed :  A.  Squid :  2.7.9 pkg v.4.3.6  ( Do not install squid3 – its very buggy )
                    b.  Squidguard : 1.9.14  -- squid configured as a transparent proxy on lan interface  - rest are default settings.

                    3.  Memory : 1 GB

                    4.  Bandwidth Available :  4 MB

                    5.  Limiter applies for testing :  only to 1 ip  ( 256 kb download and 1 mb upload )

                    6.  Result  tested with speed.net  (  Worked exactly as expected )

                    7.  All test carried when no one else using internet ( doubly confirmed )

                    Please mark that this issue is fully resolved.

                    Kudos and special thanks to  Alfanetindo  for a simple but a great solution.

                    Steps need to be taken...

                    1.  Following rule must be first rule

                    IPv4 TCP    *    *    *    3128    *    none        Rule to allow transparent proxy to work

                    2.  Then you can apply the limiter rule.

                    pfsense-limiter-rule.png_thumb
                    pfsense-limiter-rule.png
                    pfsense-services-status.png
                    pfsense-services-status.png_thumb
                    pfsense-version.png
                    pfsense-version.png_thumb

                    1 Reply Last reply Reply Quote 0
                    • D
                      djzort
                      last edited by

                      the order of the actual pf rules must be the issue then, perhaps someone can post the pf rules of working 2.1.5 and not working 2.2.x

                      1 Reply Last reply Reply Quote 0
                      • E
                        Ecnerwal
                        last edited by

                        Not "solved" and the rule change does not "solve" it. Looks like it just bypasses the limiter.

                        Tried on 2.2.4, squid 3 (what was installed, has not been transparent since I decided that limiter fairness beat the heck out of squid caching if I had to pick only one of those) - traffic limited at 10 and running 10.6 shot above 12, quality shot from 40 to 1500 ms.

                        Uninstalled squid 3, installed 2.7.9.

                        Traffic again shot above 12, quality went to 400, then 1200 ms.

                        Turned off transparent and disabled firewall rule. Traffic remained high, quality low, so I reset states as well to flush it out.

                        Back to 10.4 and 27 ms.

                        Guess I'll have to find a second box to run an independent squid instance between pfSense and the rest of the LAN, since this is not remotely working (on older versions I could have both work, but only when cache hits were shaped, which was NOT the point, and the workarounds some claimed to work for that always left me with a locked up system and no network access.

                        I have been running the limiter (and basically no squid, or only non-transparent squid which is functionally like no squid) since last spring with excellent results on getting fairness while allowing most of the BW to be used (one user gets it all (minus limiter overhead to make the limiter work at all), two users share evenly, 80 users share evenly) and holding quality to a reasonable level.

                        "Quality to a reasonable level" is basically tuning the main limiters' in/out values that are then divided among users.

                        pfSense on i5 3470/DQ77MK/16GB/500GB

                        1 Reply Last reply Reply Quote 0
                        • D
                          debianxp
                          last edited by

                          Finally the only way to fix this was installing the old version of pfsense 2.1.5. I tested with squid transparent mode, dansguardian and Limiters and everything works fine. I was reading the pfsense Digest and there are many security issues and bugs from the old version 2.1.5 to the last version 2.2.4, like a multiple Cross-Site Scripting (XSS) vulnerabilities were found in the pfSense WebGUI, and OpenSSL “FREAK” vulnerability (If packages include a web server or similar component, such as a proxy, an improper user configuration may be affected. Consult the package documentation or forum for details.)

                          My question, is there any secure way to keep this old version for remote access?

                          Regards!

                          1 Reply Last reply Reply Quote 0
                          • C
                            chris4916
                            last edited by

                            That's a pretty strange technical debate here about rule handling access to port 3128 while idea is to use transparent proxy which is, by design, implemented in such a way that proxy port is unknown browser side and accessed only internally.

                            Not reading even further, when I saw such proposal in term of FW rule associated with transparent proxy, I was…  :o ???....  ::)

                            If issue is with transparent proxy only, why don't you move to explicit proxy with is definitely far better, in any case?

                            Jah Olela Wembo: Les mots se muent en maux quand ils indisposent, agressent ou blessent.

                            1 Reply Last reply Reply Quote 0
                            • E
                              Ecnerwal
                              last edited by

                              Explicit proxy is fine for my fixed machines that won't be on another network; and it's set up on them, in fact.

                              Setting up explicit proxy on mobile machines tends to break them when they go elsewhere. The user base not being all that savvy, various possible schemes of network settings to implement explicit proxy here that they would change away from when elsewhere might work for 2% of them. And it would be a pain for that 2%, even - Oh, I switched networks. Now I need to switch network settings. Oh, Joy.

                              Auto Proxy discovery is a delightfully kludgy old process (netscape - that brings back memories) and not turned on by default for most systems.

                              So, for effective proxy that actually works for the majority of a mobile user-base, transparent is useful (when it works.)

                              Your environment may differ.

                              pfSense on i5 3470/DQ77MK/16GB/500GB

                              1 Reply Last reply Reply Quote 0
                              • K
                                killmasta93
                                last edited by

                                Also just want to point out that limiter also break NAT Reflection mode for port forwards  :-[

                                Tutorials:

                                https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                                1 Reply Last reply Reply Quote 0
                                • J
                                  JDvD
                                  last edited by

                                  Has it been solved for the new version 2.2.4?

                                  USER ERROR: Replace user and press any key to continue …

                                  1 Reply Last reply Reply Quote 0
                                  • K
                                    killmasta93
                                    last edited by

                                    nah not sure  maybe for 2.2.5 :)

                                    I would love to have limiter to work with NAT reflection

                                    Tutorials:

                                    https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                                    1 Reply Last reply Reply Quote 0
                                    • DerelictD
                                      Derelict LAYER 8 Netgate
                                      last edited by

                                      As far as I know this problem is punted to 2.3, unfortunately.

                                      Chattanooga, Tennessee, USA
                                      A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                      DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                      Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                      1 Reply Last reply Reply Quote 0
                                      • K
                                        killmasta93
                                        last edited by

                                        So on 2.2.2 Limiter does not have any issue with NAT reflection? on 2.2.4 still theres issues

                                        Tutorials:

                                        https://www.mediafire.com/folder/v329emaz1e9ih/Tutorials

                                        1 Reply Last reply Reply Quote 0
                                        • DerelictD
                                          Derelict LAYER 8 Netgate
                                          last edited by

                                          I think it's 2.2.X.

                                          Chattanooga, Tennessee, USA
                                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                          1 Reply Last reply Reply Quote 0
                                          • E
                                            Ecnerwal
                                            last edited by

                                            @JDvD:

                                            Has it been solved for the new version 2.2.4?

                                            I'm having the problem on 2.2.4, so, no.

                                            pfSense on i5 3470/DQ77MK/16GB/500GB

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.