Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid Tproxy, DynamicSSLCert & SslPeekAndSplice support

    Scheduled Pinned Locked Moved Cache/Proxy
    9 Posts 6 Posters 2.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • B Offline
      bwf.it35218
      last edited by

      Hi

      Does the squid support Tproxy mode?

      According to http://wiki.squid-cache.org/ConfigExamples/Intercept/OpenBsdPf the newest versions of squid has the "–enable-pf-transparent" flag to use Tproxy mode with pf

      Has the pfSense squid package been built with this flag enabled?

      For SSLBump there are two new features in squid that helps with the certificate errors when proxying https - DynamicSslCert http://wiki.squid-cache.org/Features/DynamicSslCert & PeekAndSplice http://wiki.squid-cache.org/Features/SslPeekAndSplice

      Does the pfSense squid package support these features?

      1 Reply Last reply Reply Quote 0
      • B Offline
        bwf.it35218
        last edited by

        Any feedback guys?

        1 Reply Last reply Reply Quote 0
        • P Offline
          P1
          last edited by

          i have squid 3.5.19 –disable-ipf-transparent still there and i am waiting for it to be enabled or the way that makes it so

          did you get any solution for that yet ?

          1 Reply Last reply Reply Quote 0
          • B Offline
            bwf.it35218
            last edited by

            Nope, still waiting to hear from the devs.

            1 Reply Last reply Reply Quote 0
            • B Offline
              bwf.it35218
              last edited by

              Bump

              1 Reply Last reply Reply Quote 0
              • K Offline
                Kababayan
                last edited by

                @bwf.it35218:

                Hi

                According to http://wiki.squid-cache.org/ConfigExamples/Intercept/OpenBsdPf the newest versions of squid has the "–enable-pf-transparent" flag to use Tproxy mode with pf

                Has the pfSense squid package been built with this flag enabled?

                If you use the latest pfsense squid 3.5.19  '–enable-pf-transparent'  yes it is enabled

                1 Reply Last reply Reply Quote 0
                • C Offline
                  cistech
                  last edited by

                  Guys,
                  In this case, HTTPS sites can be proxed/filtered using Transparent proxy mode?
                  Just to confirm, users need to use a local certificate to do SSLBump anyway, right?

                  thanks in advance

                  1 Reply Last reply Reply Quote 0
                  • V Offline
                    Valeriy
                    last edited by

                    TRPOXY mode currently is not supported on pfsense, according to my experience.

                    1 Reply Last reply Reply Quote 0
                    • D Offline
                      doktornotor Banned
                      last edited by

                      tproxy is not used anywhere in the package, plus not really sure why are people pulling SSL/MITM/certs to the topic (which has long been available in the package and is working)

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.