admin@OPNsense:~ % sudo sockstat -l | egrep '(clamav|icap|squid)'c_icap c-icap 35415 5 tcp6 *:1344 *:*c_icap c-icap 28209 5 tcp6 *:1344 *:*c_icap c-icap 57726 5 tcp6 *:1344 *:*c_icap c-icap 3990 5 tcp6 *:1344 *:*clamav clamd 78715 4 tcp4 127.0.0.1:3310 *:*clamav clamd 78715 5 stream /var/run/clamav/clamd.socksquid squid 68856 11 udp46 *:25886 *:*squid squid 68856 20 udp4 *:58766 *:*squid squid 68856 47 tcp4 127.0.0.1:3128 *:*squid squid 68856 48 tcp6 ::1:3128 *:*squid squid 68856 49 tcp4 127.0.0.1:3129 *:*squid squid 68856 50 tcp6 ::1:3129 *:*squid squid 68856 51 tcp4 192.168.20.1:3128 *:*squid squid 68856 52 tcp4 192.168.1.1:3128 *:*squid squid 88504 9 dgram (not connected)
admin@OPNsense:~ % cat /usr/local/etc/squid/squid.conf http_port 127.0.0.1:3128 intercept ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onhttp_port [::1]:3128 intercept ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onhttps_port 127.0.0.1:3129 intercept ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onhttps_port [::1]:3129 intercept ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onhttp_port 192.168.20.1:3128 ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onhttp_port 192.168.1.1:3128 ssl-bump cert=/var/squid/ssl/ca.pem dynamic_cert_mem_cache_size=10MB generate-host-certificates=onsslcrtd_program /usr/local/libexec/squid/security_file_certgen -s /var/squid/ssl_crtd -M 4MBsslcrtd_children 5tls_outgoing_options options=NO_TLSv1 cipher=HIGH:MEDIUM:!RC4:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!SRP:!DSSacl bump_step1 at_step SslBump1acl bump_step2 at_step SslBump2acl bump_step3 at_step SslBump3acl bump_nobumpsites ssl::server_name "/usr/local/etc/squid/nobumpsites.acl"ssl_bump peek bump_step1 allssl_bump splice allssl_bump peek bump_step2 allssl_bump splice bump_step3 allssl_bump bumpsslproxy_cert_error deny allacl ftp proto FTPhttp_access allow ftpacl localnet src 192.168.20.0/24 # Possible internal network (interfaces v4)acl localnet src 192.168.1.0/24 # Possible internal network (interfaces v4)acl localnet src fc00::/7 # RFC 4193 local private network rangeacl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machinesacl remoteblacklist_Shallalist.de dstdomain "/usr/local/etc/squid/acl/Shallalist.de"acl SSL_ports port 443 # httpsacl Safe_ports port 80 # httpacl Safe_ports port 21 # ftpacl Safe_ports port 443 # httpsacl Safe_ports port 70 # gopheracl Safe_ports port 210 # waisacl Safe_ports port 1025-65535 # unregistered portsacl Safe_ports port 280 # http-mgmtacl Safe_ports port 488 # gss-httpacl Safe_ports port 591 # filemakeracl Safe_ports port 777 # multiling httpacl CONNECT method CONNECTicap_enable onicap_default_options_ttl 60adaptation_send_client_ip onadaptation_send_username officap_client_username_encode officap_client_username_header X-Usernameicap_preview_enable onicap_preview_size 1024icap_service response_mod respmod_precache icap://[::1]:1344/avscanicap_service request_mod reqmod_precache icap://[::1]:1344/avscaninclude /usr/local/etc/squid/pre-auth/*.confadaptation_access response_mod deny remoteblacklist_Shallalist.deadaptation_access request_mod deny remoteblacklist_Shallalist.dehttp_access deny remoteblacklist_Shallalist.deadaptation_access response_mod deny !Safe_ports adaptation_access request_mod deny !Safe_ports http_access deny !Safe_ports adaptation_access response_mod deny CONNECT !SSL_ports adaptation_access request_mod deny CONNECT !SSL_ports http_access deny CONNECT !SSL_ports adaptation_access response_mod allow localhost manageradaptation_access request_mod allow localhost manageradaptation_access response_mod deny manageradaptation_access request_mod deny managerhttp_access allow localhost managerhttp_access deny manageradaptation_access response_mod deny to_localhostadaptation_access request_mod deny to_localhosthttp_access deny to_localhostinclude /usr/local/etc/squid/auth/*.confadaptation_access response_mod allow localnetadaptation_access request_mod allow localnethttp_access allow localnetadaptation_access response_mod allow localhostadaptation_access request_mod allow localhosthttp_access allow localhostadaptation_access response_mod deny alladaptation_access request_mod deny allhttp_access deny allinclude /usr/local/etc/squid/post-auth/*.confcache_mem 256 MBcache_dir ufs /var/squid/cache 100 16 256coredump_dir /var/squid/cacherefresh_pattern pkg\.tar\.xz$ 0 20% 4320 refresh-imsrefresh_pattern d?rpm$ 0 20% 4320 refresh-imsrefresh_pattern deb$ 0 20% 4320 refresh-imsrefresh_pattern udeb$ 0 20% 4320 refresh-imsrefresh_pattern Packages\.bz2$ 0 20% 4320 refresh-imsrefresh_pattern Sources\.bz2$ 0 20% 4320 refresh-imsrefresh_pattern Release\.gpg$ 0 20% 4320 refresh-imsrefresh_pattern Release$ 0 20% 4320 refresh-imsrefresh_pattern -i microsoft.com/.*\.(cab|exe|ms[i|u|f]|[ap]sf|wm[v|a]|dat|zip|esd) 4320 80% 129600 reload-into-imsrefresh_pattern -i windowsupdate.com/.*\.(cab|exe|ms[i|u|f]|[ap]sf|wm[v|a]|dat|zip|esd) 4320 80% 129600 reload-into-imsrefresh_pattern -i windows.com/.*\.(cab|exe|ms[i|u|f]|[ap]sf|wm[v|a]|dat|zip|esd) 4320 80% 129600 reload-into-imsrefresh_pattern ^ftp: 1440 20% 10080refresh_pattern ^gopher: 1440 0% 1440refresh_pattern -i (/cgi-bin/|\?) 0 0% 0refresh_pattern . 0 20% 4320dns_v4_first onaccess_log stdio:/var/log/squid/access.log squid cache_store_log stdio:/var/log/squid/store.loghttpd_suppress_version_string onuri_whitespace stripforwarded_for onlogfile_rotate 0cache_mgr root@home.lanerror_directory /usr/local/etc/squid/errors/en-us