OPNsense Forum

English Forums => General Discussion => Topic started by: gobris on May 24, 2019, 08:46:31 am

Title: Transparent Proxy and Redirect Problem
Post by: gobris on May 24, 2019, 08:46:31 am
Hello,
I installed the opnsense and, configured the transparent proxy(checked the option)
added webfilters... And at first try when manually entering the proxy information on client browser, I can see the web block works well.

After that, I clicked the (i) next to transparent proxy and added the port forwarding rule..

But it seems it does not port forward via proxy.
When I remove accept anything rule at the end of the firewall rule set.. browser simply cant go anywhere.

I dont know where to check
Out of options..
Anybody have an idea?

Title: Re: Transparent Proxy and Redirect Problem
Post by: mimugmail on May 24, 2019, 10:13:52 am
It seems you only have transparent for HTTP and not HTTPS, while manually adding proxy would also add HTTPS. So you maybe test with HTTPS sites and it doesn't work?
Title: Re: Transparent Proxy and Redirect Problem
Post by: gobris on May 24, 2019, 02:52:12 pm
Thats a possibility.. But this creates another problem that i can not figure out.

I enable the ssl proxy option..
then move the ssl port forward rule to the upper levels on ruleset..

Even my first rule is allow any/any to 127.0.0.1

I got
   192.168.1.100:14124   192.168.1.1:443   tcp   Default deny rule
which blocks me both from reaching firewall

I also added a manual rule to allow from lan to 192.168.1.1 any any  to accept this connections..
Everything seems to be working now.
Title: Re: Transparent Proxy and Redirect Problem
Post by: mimugmail on May 24, 2019, 08:16:16 pm
Port forward has to go to ssl Port and not the one for http
Title: Re: Transparent Proxy and Redirect Problem
Post by: gobris on May 24, 2019, 09:08:09 pm
Port forward has to go to ssl Port and not the one for http
got two port forwards

one is 80 -->3128
other is 443 to 3129

rules created automatically from that (i) menu at transparent proxy + ssl inspection menus

My workaround was adding accept rule for 192.168.1.1 also as 127.0.01...

But....

This made another problem.. This time i had SSL error..
And i switched management interface to port 80 and solved it also.

Title: Re: Transparent Proxy and Redirect Problem
Post by: mimugmail on May 24, 2019, 09:23:45 pm
So you are good now?
Title: Re: Transparent Proxy and Redirect Problem
Post by: gobris on May 24, 2019, 09:24:44 pm
not the solution i expected but yes..

Sure i had other problems but not for this topic  ;)