Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
pfSense Forum
pfSense English Support
»
Routing and Multi WAN
»
2.0 Multi-WAN + squid (not transparent)
Username:
Password:
1 Hour
1 Day
1 Week
1 Month
Forever
Home
Help
Search
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: 2.0 Multi-WAN + squid (not transparent) (Read 4592 times)
0 Members and 1 Guest are viewing this topic.
MrsPotter
Jr. Member
Offline
Posts: 33
2.0 Multi-WAN + squid (not transparent)
«
on:
November 27, 2011, 05:02:02 am »
Hi,
I've searched/read all threads about multi-wan within the forum/wiki/howto. Many posts concern 1.2.x. Also, it seems all of them are concerned with squid running in transparent mode. I've started a new thread on this old topic to try and:
a) summarize the current state of what works and what doesn't.
b) determine if multi-WAN will behave differently under squid (not transparent)?
It seems the general consensus is that:
1) 2.0 Multi-WAN + firewall + loadbalance + failover:
Works great
2) 2.0 Multi-WAN + firewall + failover + squid (transparent):
Seems to work for most users, others experience problems after some time (down link not coming back up again etc), yet others can't get it to work altogether (probably due to weird scenarios or wrong settings).
3) 2.0 Multi-WAN + firewall + failover + loadbalance + squid (transparent):
Found one post that claims it works,
others experience problems after some time (yet it seems these cases weren't tested properly to ascertain that the setup worked in the first place)
, yet most users can't get it to work altogether. Problem seems to be squid always using the default WAN, thus balancing doesn't work for HTTP data. Or, squid not understanding balancing? However, it seems very logical to me that floating rules should solve this?
4) 2.0 Multi-WAN + firewall + squid (not transparent) (loadbalance + failover):
Any comments? Anyone tried this? How would this behave differently than squid (transparent)?
In my scenario I can't use squid transparently. I'd like to add load balancing to a working server, but can't get much down time on it, thus will have small window within which to deploy it. Thus, any pre-knowledge would be of great help.
Cheers,
MrsPotter
«
Last Edit: November 28, 2011, 05:30:54 am by MrsPotter
»
Logged
mzaaa
Newbie
Offline
Posts: 4
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #1 on:
November 28, 2011, 05:35:32 am »
I have also this issue.anyone can help us.
Logged
MrsPotter
Jr. Member
Offline
Posts: 33
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #2 on:
November 30, 2011, 02:18:22 am »
OK -obviously very few have tried this:
2.0 Multi-WAN + firewall + squid (not transparent) (loadbalance + failover)
So, I'll have a test run in a week or so - will report back.
It'll be cool if we could put together a more comprehensive Multi-WAN howto, that discusses the finer details.
Logged
pubmsu
Newbie
Offline
Posts: 9
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #3 on:
January 09, 2012, 06:30:10 am »
Hi MrsPotter,
Could you finally get it working on transparent mode? We're struggling exactly with this.
Thanks,
pub
Logged
MrsPotter
Jr. Member
Offline
Posts: 33
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #4 on:
January 09, 2012, 11:20:45 am »
Hi,
Sorry, I have not yet had the chance to try it - it will most likely happen within the next 2 weeks. I was kind of hoping that someone would post their successes in the meanwhile.
I recently ran the 2.01 update - so hopefully it works in this later version.
The way I understand it: this should be possible using the floating rule function. And then point squid and whatever else to the floating rule (which represent the balanced gateway). People were complaining that squid doesn't want to except anything other than the default gateway. But, it seemed to me that this is due to a bug in the way gateways are defined. Since, one should be able to set the balanced gateway as the default. I remember having difficulty with two gateways etc. But, from the release doc this seems to be improved in 2.01 - so fingers crossed this might work.
Running squid in transparent mode result in quite a few head aches (for me at least). Video streaming is slow, some software times out (especially when searching for a licensing server) - so I'm using a non-transparent proxy configured via WPAD. Works just as well if not better. I was hoping that it is the transparent part that produces the balancing issues.
If I can't get the balancing to work - I'm going to (as a next resort) route mail through the one gateway, and other traffic through the other. Half of our traffic consists of email - so as a next best this makes sense.
I'll report back on my results.
Anyone else that got this working yet?
Cheers,
MrsPotter.
«
Last Edit: January 09, 2012, 11:24:04 am by MrsPotter
»
Logged
pubmsu
Newbie
Offline
Posts: 9
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #5 on:
January 10, 2012, 01:40:20 am »
Thanks @MrsPotter, apparently there's an "easy" method here, to which I posted some questions, too:
http://forum.pfsense.org/index.php/topic,38882.msg233730.html#msg233730
BTW, we could make failover work with transparent proxy, but still didn't test loadbalancing thoroughly. Will report back.
Logged
MrsPotter
Jr. Member
Offline
Posts: 33
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #6 on:
February 14, 2012, 10:34:48 am »
Hi,
I couldn't even get multi-WAN going. See
http://forum.pfsense.org/index.php/topic,46160.msg241851.html#msg241851
for the problem I encountered.
Haven't been able to solve that yet.
Cheers,
Logged
MrsPotter
Jr. Member
Offline
Posts: 33
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #7 on:
February 21, 2012, 08:10:23 am »
2.0 Multi-WAN + firewall + squid (not transparent) + squid filter (loadbalance + failover):
Ok - got this to work
Must say that I'm pleasantly impressed by this software - so far so good, been running for about a week now.
I followed the information found in
http://forum.pfsense.org/index.php/topic,38882.msg233730.html#msg233730
BTW: I'm using sticky connections to avoid issues with https banking site etc. And, this seems to do the trick as well.
«
Last Edit: February 21, 2012, 08:14:32 am by MrsPotter
»
Logged
denvel
Newbie
Offline
Posts: 1
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #8 on:
March 02, 2012, 03:32:21 am »
Hi all, i had manage to configure internet load balancing + squid(not transparent) + squidguard using pfsense. But my problem is when i try to browse some websites it stocks or freezes then when i refresh my web browser it will load the webpages. I think there is a problem with the floating rules..because when i disabled the floating rules i can web browse normally. Anybody had experience this kind of problem about floating rules??
Logged
jikjik101
Full Member
Offline
Posts: 191
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #9 on:
March 02, 2012, 08:33:46 pm »
I am using 2.0.1-RELEASE (i386) with 3 WANs+load balance+squid transparent.
The only problem I have is I can't use policy routing. To fix that, need to customize the tcp_outgoing_address.
Logged
onkeldave83
Full Member
Offline
Posts: 214
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #10 on:
April 05, 2012, 08:00:13 am »
heh how you realized load balancing +failover +squid +squid filter +havp
?
what is the thing i missing?
floating rules?
i dont have one!!!
my system preferences in words:
1) squid transparent
2) havp antivirus as parent for squid
3) in the new release i dont need port forward to squid port - with tranparency is preference complete and it works great!
4) loadbalancing group create and failover group create
5) in firewall rules under lan, i have create access rules to use loadbalancing and failover
-----------------------------------------------------------------------------------------------
6) without squid it works! it changes the gateway from 1&1 server in whatismyip.com
7) with squid it dont work! only over other ports i can use paralell the two gateways! f.e. jdownloader or other downloadtools with more connections to destination.
HOW CAN I REALIZED over port 80 / http that squid uses loadbalancing group gateways and not only the default gateway?
?
thanks for any help!!!!
Logged
Kyushu
Newbie
Offline
Posts: 22
Re: 2.0 Multi-WAN + squid (not transparent)
«
Reply #11 on:
August 01, 2012, 02:07:07 am »
Quote from: denvel on March 02, 2012, 03:32:21 am
Hi all, i had manage to configure internet load balancing + squid(not transparent) + squidguard using pfsense. But my problem is when i try to browse some websites it stocks or freezes then when i refresh my web browser it will load the webpages. I think there is a problem with the floating rules..because when i disabled the floating rules i can web browse normally. Anybody had experience this kind of problem about floating rules??
We also experience this. I think it would be advisable to run squid on a different machine rather than running it inside the pfsense machine. Though I am not sure about the settings since we are only new in using pfsense. Maybe there's another way to configure loadbalancing+failover+squid to make it work properly.
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Administrative
-----------------------------
=> Forum rules
=> Messages from the pfSense Team
=> Feedback
-----------------------------
pfSense English Support
-----------------------------
=> Installation and Upgrades
=> General Questions
=> 2.1 Snapshot Feedback and Problems
=> Post a bounty
===> Completed Bounties
===> Expired/Withdrawn Bounties
=> Hardware
=> Firewalling
=> NAT
=> CARP/VIPs
=> Routing and Multi WAN
=> Traffic Shaping
=> DHCP and DNS
=> IPv6
=> IPsec
=> PPTP
=> PPPoE Server
=> Captive Portal
=> webGUI
=> Wireless
=> SNMP
=> Packages
=> Virtualization installations and techniques
=> OpenVPN
=> Gaming
-----------------------------
Development/Documentation
-----------------------------
=> Documentation
=> Development
-----------------------------
General Category
-----------------------------
=> General Discussion
-----------------------------
International Support
-----------------------------
=> Indonesian
=> Deutsch
=> Español
=> Français
=> Italiano
=> Russian
=> Nederlands
=> Norwegian
=> Portuguese
=> Polish
=> Romanian
=> Swedish
=> Turkish
-----------------------------
Retired
-----------------------------
=> 1.2.3-PRERELEASE-TESTING snapshots - RETIRED
=> 1.2.1-RC Snapshot Feedback and Problems-RETIRED
=> 2.0-RC Snapshot Feedback and Problems - RETIRED
=> DNS Server testing area - RETIRED
Loading...