0

Here's my config

pfSense LAN's Real Interface IP: 192.168.1.1/22 Virtual IP1: 10.1.1.1/24

Client PC 1 LAN IP: 10.1.1.2/24

Client PC 2 LAN IP: 192.168.1.2/22

Client PC 1 cannot access HTTPS websites (connection timeout). Normal HTTP is OK.

Client PC 2 can access both HTTP and HTTPS.

Squid is set to Transparent.

What seems to be the problem here? I'm not sure if this is a pfSense problem or a Squid problem, but I'm leaning towards Squid problem.

stramatum
  • 27
  • 2
  • 5

1 Answers1

0

Squid can't handle HTTPS trafiic transparently* so pfSense forwards only plain HTTP traffic to Squid. This means that your problem lies with pfSense's firewall rules and I would check there. You should allow HTTPS traffic for Client PC 1 ass well.

_* This is because of the nature of HTTPS traffic. It is encrypted so that no-one can intercept it and that's exactly what Squid does in transparent mode. It intercepts web traffic. There are ways to terminate the HTTPS tunnel to your proxy and then pass it through Squid (what in reality is a Man In The Middle attack) but I think this is beyond your case.

AlexTsr
  • 606
  • 3
  • 5