Menu

Show posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Show posts Menu

Messages - bmail

#31
Hello Franco and thanks for your answer.

Yes, i mean "clear all" under the multiselect, and even the grey cross at the end of each item does'nt work.

If I answer "yes" to the pop-up asking me if I really want, nothing is deleted.
I I click "apply" at the bottom of page, the same thing: nothing change.

I didn't write three times the rules ... Just copy/paste the example rule with "mydomain" and another copy/paste with "youtube" in order to test. By the way, it does'nt work ... youtube is always available ...
Opnsense GUI duplicate it.

I tried to remove it in squid.conf, but it's rewritten.
So, If you have an idea... Now, I don't dare add a new config rule for squid.

Thanks to you.
Have a good day
Bertrand

By the way: Since 2 days, there are difficulties to get the web pages of the forum, DNS Ok, ping Ok, but no answer from the webserver. And few minutes later, everything is good. But I think you are aware of it.
#32
Hello,

I'm sorry to come back another time on this issue, but I really don't understand why the GUI does'nt execute these modifications...

I use firefox 60.0.1. Nothing which could be strange in "development tools".
No error in log for configd.

I don't known where to search !

Have you got some ideas ?

Thanks ever so much.
Bertrand
#33
Hello,

Did you experiment this issue with 18.1.8 ?

I definitely can't clear config about acl I putted in squid configuration: the individual closing cross near each element doesn't work, and tne glogal "clear / remove cross" leads me to a pop up asking me if I'm sure to deselect or remove all items".
Click on "yes" closes this pop-up but it doesn't work.

configd log after this action:     configd.py: [0d623e91-5a65-4a98-902b-5774751148bf] request proxy status

Where can I search the reason ?

Thanks a lot for any help !
bertrand
#34
Hello,

I have exactly the same issue with 18.1.7 and 18.1.8 : unable to clear a blacklist via the GUI ...
No error in configd.log (gui)
And of course, disable it in squid.conf doesn't help since it's overwritten.

Thanks if anyone can help us !
#35
Found !

Ok, how can I be so stupid ?
Just adding the web site in the "SSL no bump sites", so the real certificat is transmitted and can be drop by suricata.

#36
Hello,

I think I need help to understand how Opnsense is processing...

I use squid with https inspection. So I created an self signed authority inside Opnsense (called internal-ca).
When a user visits an https web page, every site show a certificat provided by my organisation, with, of course, a unique SHA1 fingerprint. I think this is normal. But ...
I try to block some site using "user defined rules" with Suricata. I give the fingerprint of the website I want to block, but no success ... the website isn't block by suricata.

Suricata works on wan interface only. If it works on wan + lan interface, no more access to Opnsense GUI caused by a rule:

   SERVER-OTHER OpenSSL TLSv1.2 ChangeCipherSpec man-in-the-middle exploitation attempt
Alert sid   31484

Is there a way to use drop action based on ssl fingerprint if we want to use ssl inspection with Squid ?

Thank a lot for any advice.
Bertrand
#37
Bonjour,

Tout est à peu près dans le titre ...
J'utilisais cette fonctionnalité de Suricata pour bloquer facebook, et depuis la version 18.1.7, cela ne fonctionne plus...

Je suis un peu confus avec ce disfonctionnement car lorsque j'affiche les détails du certificat de facebook dans un navigateur, il est indiqué qu'il a été émis par l'autorité de certif que j'ai créé dans opnsense. Etrange, non ?

J'utilise squid avec l'inspection en ssl, avec cette même AC.

Je dois passer à coté d'un concept important...

Merci pour vos éventuelles lumières.
Bertrand



Résolu, voir:
https://forum.opnsense.org/index.php?topic=8740.0