Hi, versuche mich zum ersten mal am OPNsense.Die Installation verlief reibungslos und hatte auch sofort Zugang zum Internet.Wan -> Fritzbox (DHCP) -> OPNsense (DHCP) -> Client.
squid -k parse2017/01/04 15:15:09| Startup: Initializing Authentication Schemes ...2017/01/04 15:15:09| Startup: Initialized Authentication Scheme 'basic'2017/01/04 15:15:09| Startup: Initialized Authentication Scheme 'digest'2017/01/04 15:15:09| Startup: Initialized Authentication Scheme 'negotiate'2017/01/04 15:15:09| Startup: Initialized Authentication Scheme 'ntlm'2017/01/04 15:15:09| Startup: Initialized Authentication.2017/01/04 15:15:09| Processing Configuration File: /usr/local/etc/squid/squid.conf (depth 0)2017/01/04 15:15:09| Processing: http_port 127.0.0.1:3128 intercept2017/01/04 15:15:09| Starting Authentication on port 127.0.0.1:31282017/01/04 15:15:09| Disabling Authentication on port 127.0.0.1:3128 (interception enabled)2017/01/04 15:15:09| Processing: http_port [::1]:3128 intercept2017/01/04 15:15:09| Starting Authentication on port [::1]:31282017/01/04 15:15:09| Disabling Authentication on port [::1]:3128 (interception enabled)2017/01/04 15:15:09| Processing: http_port 192.168.1.1:31282017/01/04 15:15:09| Processing: acl ftp proto FTP2017/01/04 15:15:09| Processing: http_access allow ftp2017/01/04 15:15:09| Processing: acl localnet src 192.168.1.0/24 # Possible internal network2017/01/04 15:15:09| Processing: acl localnet src fc00::/7 # RFC 4193 local private network range2017/01/04 15:15:09| Processing: acl localnet src fe80::/10 # RFC 4291 link-local (directly plugged) machines2017/01/04 15:15:09| Processing: acl SSL_ports port 443 # https2017/01/04 15:15:09| Processing: acl Safe_ports port 80 # http2017/01/04 15:15:09| Processing: acl Safe_ports port 21 # ftp2017/01/04 15:15:09| Processing: acl Safe_ports port 443 # https2017/01/04 15:15:09| Processing: acl Safe_ports port 70 # gopher2017/01/04 15:15:09| Processing: acl Safe_ports port 210 # wais2017/01/04 15:15:09| Processing: acl Safe_ports port 1025-65535 # unregistered ports2017/01/04 15:15:09| Processing: acl Safe_ports port 280 # http-mgmt2017/01/04 15:15:09| Processing: acl Safe_ports port 488 # gss-http2017/01/04 15:15:09| Processing: acl Safe_ports port 591 # filemaker2017/01/04 15:15:09| Processing: acl Safe_ports port 777 # multiling http2017/01/04 15:15:09| Processing: acl CONNECT method CONNECT2017/01/04 15:15:09| Processing: icap_enable off2017/01/04 15:15:09| Processing: http_access deny !Safe_ports2017/01/04 15:15:09| Processing: http_access deny CONNECT !SSL_ports2017/01/04 15:15:09| Processing: http_access allow localhost manager2017/01/04 15:15:09| Processing: http_access deny manager2017/01/04 15:15:09| Processing: http_access deny to_localhost2017/01/04 15:15:09| Processing: http_access allow localnet2017/01/04 15:15:09| Processing: http_access allow localhost2017/01/04 15:15:09| Processing: http_access deny all2017/01/04 15:15:09| Processing: cache_mem 256 MB2017/01/04 15:15:09| Processing: coredump_dir /var/squid/cache2017/01/04 15:15:09| Processing: refresh_pattern ^ftp: 1440 20% 100802017/01/04 15:15:09| Processing: refresh_pattern ^gopher: 1440 0% 14402017/01/04 15:15:09| Processing: refresh_pattern -i (/cgi-bin/|\?) 0 0% 02017/01/04 15:15:09| Processing: refresh_pattern . 0 20% 43202017/01/04 15:15:09| Processing: access_log /var/log/squid/access.log squid2017/01/04 15:15:09| Processing: cache_store_log /var/log/squid/store.log2017/01/04 15:15:09| Processing: uri_whitespace strip2017/01/04 15:15:09| Processing: forwarded_for on2017/01/04 15:15:09| Processing: logfile_rotate 02017/01/04 15:15:09| Processing: visible_hostname localhost2017/01/04 15:15:09| Processing: cache_mgr admin@localhost.local2017/01/04 15:15:09| Initializing https proxy context
* * * LAN Address 44380222 * Anti-Lockout Rule Deaktiviert => IPv4 * LAN net * * * * Default allow LAN to any rule IPv4 UDP LAN net * * 53 (DNS) * DNS -> any IPv4 TCP LAN net * * 443 (HTTPS) * HTTPS -> any Deaktieviert => IPv6 * LAN net * * * * Default allow LAN IPv6 to any rule IPv4 TCP LAN net * 127.0.0.1 3128 * NAT redirect traffic to proxy
Die Firewall arbeitet die Regeln von Oben nach unten ab! Da die ANY-Regel bereits alle Ports beinhaltet, werden alle Regeln die nach der ANY-Regel kommen nicht verarbeitet bzw. sind obsolet! Der Port 80 wird daher nie an den Proxy umgeleitet!