Jump to content


Photo

pfSense + AirVPN + Squid Proxy? Does that work and how?


  • Please log in to reply
2 replies to this topic

#1 anormalvpnuser

anormalvpnuser

    Newbie

  • Members
  • Pip
  • 4 posts

Posted 16 March 2019 - 08:43 AM

Hi everyone,

'm running a home network with pfSense and AirVPN, and I set this up following the instructions here:

https://airvpn.org/topic/17444-how-to-set-up-pfsense-23-for-airvpn/

pfSense Version: 2.4.4-RELEASE-p2

What I would like to know is how I can set up the Squid Proxy to cache all the frequent web content, without compromising my VPN. I'm fine to start off with HTTP traffic as this is still quite a big chunk in our browsing at home, however ultimately I'd love to cache the HTTPS as well, just conscious that this is a lot more complex, as the certificates will show invalid in the browsers...

 

First question: proxy interface - which one do I bind this to?

- AIRVPN_LAN

- AIRVPN_WAN

- WAN

- loopback

 

(again, the above per the guide I followed to the dot above).

 

Proxy Port: 3128 - is that fine, do I need a NAT rule or anything for this to work?

'm quite lost and it doesn't seem like there is much documentation on how to achieve this.

 

Thanks for your help guys!

Attached Thumbnails

  • 2019-03-16_12-41-26 - Copy.png


#2 go558a83nk

go558a83nk

    Advanced Member

  • Members2
  • PipPipPip
  • 1706 posts

Posted 16 March 2019 - 01:25 PM

In the past squid proxy and openvpn usage didn't play well together.  What was meant to go through openvpn tunnel was in the clear.  I don't know if that's still the case.



#3 zhang888

zhang888

    Donald Trump of IT/Security

  • Moderators
  • 2226 posts

Posted 17 March 2019 - 07:34 PM

Just for caching (and not some filtering/hotspot) it is not recommended to do it.

Unless you frequently download the same content from the same remote origin from multiple devices frequently.

These days browsers and remote servers manage caching in a much more efficient way.


Occasional moderator, sometimes BOFH. Opinions are my own, except when my wife disagrees.






Similar Topics Collapse

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Servers online. Online Sessions: 13648 - BW: 46893 Mbit/sYour IP: 54.82.99.169Guest Access.