• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Limiter blocks internet access (Squid transparent proxy)

Scheduled Pinned Locked Moved Traffic Shaping
73 Posts 34 Posters 34.6k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • G
    gmar15
    last edited by Feb 10, 2016, 8:21 PM

    finley SOLUTION  here

    https://forum.pfsense.org/index.php?topic=106640.0

    1 Reply Last reply Reply Quote 0
    • R
      Riroxi
      last edited by Mar 28, 2016, 9:28 PM Mar 15, 2016, 5:42 PM

      @Alfanetindo:

      SOLVED*

      I managed to find a simple fix. All I needed to do was create a pass all firewall rule on the (LAN) interface for port 3128 (my proxy port).

      IPv4 TCP * * * 3128 * none   Rule to allow transparent proxy to work

      It worked and the speed limiter still works also.

      Hello!

      I made some adjusts to this rule, and worked! thx!

      Just point the rule to 127.0.0.1, and will work!

      Don't forget, the rule must be at top, and the rule with limiter must be below

      Some screenshots below to help.

      I hope this can help someone. Srry for my bad english.

      :)

      [EDIT]

      Hello Again!

      I tested this workaround for a few days and some apps like download managers can bypass limiters. :(

      Looking for another temp solution.

      Cya!

      PROXY_RULE.png
      PROXY_RULE.png_thumb
      LIMITER_RULE.png
      LIMITER_RULE.png_thumb
      LIMITER_DOWN.png
      LIMITER_DOWN.png_thumb
      LIMITER_UP.png
      LIMITER_UP.png_thumb

      1 Reply Last reply Reply Quote 0
      • G
        geovaneg
        last edited by Mar 30, 2016, 8:11 PM

        I suggest, as workaround, that you limit the client bandwidth through squid "Traffic Mgmt" tab, "Per-host throttling" option, on "Proxy server: General settings". For me, it is running ok. Sorry by my bad english too :-)

        1 Reply Last reply Reply Quote 0
        • O
          ohbobva
          last edited by Apr 15, 2016, 11:14 PM

          For years, I've limited Squid (transparent) bandwidth using Squid "delay pools" in "Custom Options" on the "General" tab of Squid's settings.  I researched and set this up years ago, and don't remember the details, so you'll need to check Squid's documentation for info on the various options.  Here is what I've been using in the "Custom Options" box…

          positive_dns_ttl 90 seconds
          delay_class 1 3
          delay_parameters 1 1572864/1966080 1572864/1966080 524288/655360
          quick_abort_min 1024 KB
          quick_abort_max 2048 KB
          quick_abort_pct 90

          If I remember correctly, among other things, this limits the download speed of the browser, but allows some amount of bursting.

          More info at http://wiki.squid-cache.org/Features/DelayPools

          It looks like this when added to the "Custom Options" box on the "General" tab of Squid's settings in PFSense's GUI...

          positive_dns_ttl 90 seconds;delay_class 1 3;delay_parameters 1 1572864/1966080 1572864/1966080 524288/655360;quick_abort_min 1024 KB;quick_abort_max 2048 KB;quick_abort_pct 90
          
          1 Reply Last reply Reply Quote 0
          • G
            GraKa
            last edited by May 23, 2016, 12:14 PM

            Hello,

            is the problem, that the Limiters are not working with the transparent proxy solved in pfSense 2.3?
            And I mean without any workarounds.

            Thanks!

            1 Reply Last reply Reply Quote 0
            • J
              JDvD
              last edited by May 25, 2016, 6:47 PM

              @GraKa:

              Hello,

              is the problem, that the Limiters are not working with the transparent proxy solved in pfSense 2.3?
              And I mean without any workarounds.

              Thanks!

              No yet. Unfortunately…

              @gmar15:

              finley SOLUTION  here

              And the gmar15 solution not work for each IP, only makes a single pipe…

              USER ERROR: Replace user and press any key to continue …

              1 Reply Last reply Reply Quote 0
              • A
                alfredopea
                last edited by Jun 3, 2016, 5:24 PM Jun 3, 2016, 4:42 PM

                Check this issue:

                https://redmine.pfsense.org/issues/4325

                Just change the transfer rate from megabits to kilobits in you limiters (download/upload) and everything will work fine again.

                The problem is with squid 2.7.9+ and ipfw limiters.

                Example 1.5 Mbps (1536 Kbps) Download and 1 Mbps (1024 Kbps) limiters:

                Hope this help and sorry about my english.

                Limiter_Kbps.png
                Limiter_Kbps.png_thumb
                Firewall_Rule.png
                Firewall_Rule.png_thumb

                Ing. Alfredo Peña Ramos
                Viva el Software Libre!

                1 Reply Last reply Reply Quote 0
                • F
                  felipemb
                  last edited by Jun 12, 2016, 5:08 AM

                  Hi Alfredo,

                  This solution not worked on 2.3.1  :(

                  In this video: https://www.youtube.com/watch?v=wcSyGDXkJ9A

                  How i create queue on interface LAN in 2.3.1?

                  Thanks for the help!!

                  1 Reply Last reply Reply Quote 0
                  • E
                    elic
                    last edited by Jul 15, 2016, 9:13 AM

                    Any solution?

                    1 Reply Last reply Reply Quote 0
                    • C
                      Cergoo
                      last edited by Jul 28, 2016, 7:04 AM

                      2.3.2-RELEASE  Limiter+Squid still not working

                      1 Reply Last reply Reply Quote 0
                      • J
                        jbx907
                        last edited by Aug 1, 2016, 4:34 PM

                        hi guys, some showed me this link and am also have problems, it is mostly with slow site links, facebook youtube opens but slow sites it does not open, im using 2.3.2 latest but still no luck, i have to just give up squid since the limiter already save the bandwidth

                        1 Reply Last reply Reply Quote 0
                        • S
                          shapoval
                          last edited by Oct 10, 2016, 10:17 PM Oct 10, 2016, 10:12 PM

                          Working (for me on 2.3.2) by simply adding a LAN rule at the top, Destination, Any, From (other) 3128 to (other) 3128 Custom.

                          Credit to: Adrea Guglielmini http://guglio.xyz/pfsense-2-3-limiters-and-squid-bugfix/

                          1 Reply Last reply Reply Quote 0
                          • C
                            Cergoo
                            last edited by Oct 13, 2016, 6:31 AM

                            @shapoval:

                            Working (for me on 2.3.2) by simply adding a LAN rule at the top, Destination, Any, From (other) 3128 to (other) 3128 Custom.

                            Credit to: Adrea Guglielmini http://guglio.xyz/pfsense-2-3-limiters-and-squid-bugfix/

                            It really works. Thank you for your message.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              [[user:consent.lead]]
                              [[user:consent.not_received]]