Jump to content

Recommended Posts

Posted

Hello everyone,

 

I am currently in the process of getting my head around pfSense and doing some testing with it before we deploy it onto our network. However, we would like it for external users to access web servers, etc that are behind the pfSense box. I have set this up as:

 

1). Create a virtual IP on the WAN interface

2). Create a 1:1 NAT Mapping from that WAN address to the Web Server address: External: 1.1.1.1 Internal: 10.0.0.10

3). Create the appropriate Firewall rule

 

This all works as expected.

 

However, squid is running on this box in transparent mode, and although we can access HTTP websites from the web server, we are unable to access HTTPS websites. I appreciate that transparent proxy cannot proxy HTTPS so something is stopping this traffic from going direct when in transparent mode. However, when explicitly defining the proxy settings it all functions as expected.

 

I have narrowed it down to the point where the 1:1 NAT Mapping is created - if I remove this, I can access HTTPS without having to explicitly define any proxy settings.

 

Has anyone else come across this issue? If so, did you manage to solve and how?

 

Many thanks in advance.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...