OPNsense Forum

Archive => 16.1 Legacy Series => Topic started by: Julien on July 03, 2016, 09:38:35 pm

Title: Proxy server
Post by: Julien on July 03, 2016, 09:38:35 pm
Hi guys,
i have proxy server configured, everything works fine.
i want to apply the proxy over the openvpn, whenever a user create a openvpn tunnel over the firewall the proxy will apply to the openvpn interface.
we dont want to fource the tunnel over the gateway on the VPN Server, why dont i want to force the tunnel ? because it will route everything behind the firewall and will cause some slawness .
on the proxy interface can't seem to add the openvpn interface .

is this even possible ? if yes hope someone can put me on the right direction.
Title: Re: Proxy server
Post by: Julien on July 06, 2016, 08:40:21 pm
any suggestions ?
Title: Re: Proxy server
Post by: abel408 on July 06, 2016, 08:48:55 pm
Are you configuring a transparent proxy? If so, that will never work unless you force all traffic through the tunnel.
Title: Re: Proxy server
Post by: Julien on July 06, 2016, 08:53:37 pm
i just forced the whole traffic on the tunnel, and the test user can open sex.com over the VPN.
local got the block page.
i've added the openvpn interface to the proxy server interface with the LAN but it still does not works :(
Title: Re: Proxy server
Post by: abel408 on July 07, 2016, 10:35:19 pm
Hmmm.. That's not what I would expect. Are you sure the web traffic is going through the tunnel? If you look at your public IP, does it show you the public IP of your opnsense router, or the router on your VPN?

Why not try something like opendns? It's a free dns server that will allow you to customize blacklists and whitelists. Also does HTTPS filtering without MITM certificates.
Title: Re: Proxy server
Post by: Julien on July 08, 2016, 04:49:12 pm
Hmmm.. That's not what I would expect. Are you sure the web traffic is going through the tunnel? If you look at your public IP, does it show you the public IP of your opnsense router, or the router on your VPN?

Why not try something like opendns? It's a free dns server that will allow you to customize blacklists and whitelists. Also does HTTPS filtering without MITM certificates.
Thank you Adel,
We would like to use our proxy for this , and use our local cashing.
hope this even possible.