# setup ssl bump acl'sacl bump_step1 at_step SslBump1acl bump_step2 at_step SslBump2acl bump_step3 at_step SslBump3acl bump_nobumpsites ssl::server_name "/usr/local/etc/squid/nobumpsites.acl"# configure bump{% if helpers.exists('OPNsense.proxy.forward.sslurlonly') and OPNsense.proxy.forward.sslurlonly == '1' %}ssl_bump peek bump_step1 allssl_bump splice allssl_bump peek bump_step2 allssl_bump splice bump_step3 allssl_bump bump{% else %}ssl_bump peek bump_step1 allssl_bump peek bump_step2 bump_nobumpsitesssl_bump splice bump_step3 bump_nobumpsitesssl_bump stare bump_step2ssl_bump bump bump_step3{% endif %}
# setup ssl bump acl'sacl bump_step1 at_step SslBump1acl bump_step2 at_step SslBump2acl bump_step3 at_step SslBump3acl bump_nobumpsites ssl::server_name "/usr/local/etc/squid/nobumpsites.acl"acl splice_only src 10.10.10.0/24acl splice_only src 10.10.20.9acl splice_only src 192.168.0.13# configure bump{% if helpers.exists('OPNsense.proxy.forward.sslurlonly') and OPNsense.proxy.forward.sslurlonly == '1' %}ssl_bump peek bump_step1 allssl_bump splice allssl_bump peek bump_step2 allssl_bump splice bump_step3 allssl_bump bump{% else %}ssl_bump peek bump_step1 allssl_bump peek bump_step2 bump_nobumpsitesssl_bump peek bump_step2 splice_onlyssl_bump splice bump_step3 bump_nobumpsitesssl_bump splice bump_step3 splice_onlyssl_bump stare bump_step2ssl_bump bump bump_step3{% endif %}
Do these settings remain after a reboot?
I not 100% on this, but it may help.https://forum.opnsense.org/index.php?topic=6516.msg27986#msg27986