Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Packages» havp package with trasparent squid proxy
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: havp package with trasparent squid proxy  (Read 3004 times)
0 Members and 1 Guest are viewing this topic.
hdavy2002
Jr. Member
**
Offline Offline

Posts: 42


View Profile
« on: May 30, 2009, 09:09:56 am »

Hi all,

I have a dell Poweredge with 2gh Dual core and 4 gb ram. I have 60 gb on raid 0 (config's are backed up)

I have Squid in transparent proxy more. It is running great. I decided to install the Antivirus: HTTP proxy (havp + clamav) package.

I configured as the snips says. My squid proxxy is 3218 and antivirus is 3219. The services for AV is up. I went to http://www.eicar.org/anti_virus_test_file.htm and tried to download a test file and it just downloaded it. I thought the havp would block it. Am I missing something.



Logged
dvserg
Global Moderator
Hero Member
*****
Offline Offline

Posts: 4292



View Profile WWW
« Reply #1 on: May 30, 2009, 09:22:49 am »

Transparent maybe only one proxy. If squid is transparent - havp ignored transparent option and work as standard proxy.
Logged

SquidGuardDoc EN  RU Tutorial
SQStat
hdavy2002
Jr. Member
**
Offline Offline

Posts: 42


View Profile
« Reply #2 on: May 30, 2009, 10:09:08 am »

Done as suggested. Still no luck. I can still download the virus file. Do I need to change the port to the squid port? that is 3218. I tried to redirect the browser to the proxy ip address:port and it worked.

since I do not want to go an configure all the browsers ( I cannot do this via GP as I have a software which uses local admin right and the GP never updates on them, still working on it)

IS there any other way this can be achieved using transparent squid? pfsense is really stuff. I am really happy with it.
« Last Edit: May 30, 2009, 12:05:52 pm by hdavy2002 » Logged
dvserg
Global Moderator
Hero Member
*****
Offline Offline

Posts: 4292



View Profile WWW
« Reply #3 on: May 30, 2009, 02:09:48 pm »

http://doc.pfsense.org/index.php/HAVP_Package_for_HTTP_Anti-Virus_Scanning
Logged

SquidGuardDoc EN  RU Tutorial
SQStat
tester_02
Full Member
***
Offline Offline

Posts: 176


View Profile
« Reply #4 on: May 31, 2009, 09:39:19 am »

  I played with this package a few months ago and did not have luck with it.
Tried it again after reading this post. (dvserg's point to doc post).

It works great transparent off on squid, on on hvap.

Did a proxy test and found hvap, and did an ecar test and hvap blocked the page.  It did let the download go though though (client antivirus got it), so I know I have a bit more to play with the file setting....

  What I did not get to work was hvap + squid + squidguard.  When hvap is off, and I just use squid+squidguard everything works.  If I turn transparent off in sqid and turn on hvap in transparent, I see that hvap is found as the proxy and I can browse.  The problem is that there is no blocking via squidguard.   Any way to enable squid + sqidguard?

  General question, how do I tell if squid is even working behind hvap?  Maybe hvap is doing the proxy, but bypassing squid altogether?
Logged
ColdFusion
Full Member
***
Offline Offline

Posts: 168


View Profile
« Reply #5 on: May 31, 2009, 10:13:30 am »

I have squid,havp,squidguard installed. The only way it works for me quite well is:

Squid transparent off
Havp transparent on
Havp parent proxy field (lan ip:squid port) ex. 192.168.0.1:3128
Havp forwarded ip checked
Squid Disable X-Forward unchecked
                  Disable VIA unchecked

Squid, Squidguard, Havp works perfectly now.

John
Logged
tester_02
Full Member
***
Offline Offline

Posts: 176


View Profile
« Reply #6 on: May 31, 2009, 11:54:12 am »

Thanks Coldfusion!  That did the trick...  I was missing the parent proxy field...

Now I have hvap+squd+squidguard working great under transparent!

I even got hvap to block the ecair test virus, and it's even blocking the ads again.

What a nice system!!!!!

Congrats to dvserg for getting it to work!
Logged
ColdFusion
Full Member
***
Offline Offline

Posts: 168


View Profile
« Reply #7 on: May 31, 2009, 12:02:57 pm »

Great..some of the things you might see in the logs sometimes is "can't send header or body to browser and also server number low spawning new..You can still increase the min/max servernumber in havp.inc.........I guess a still a WIP, but even with that it still works everytime.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.028 seconds with 19 queries.