Netgate SG-1000 microFirewall

Author Topic: squid to whatismyproxy results  (Read 141 times)

0 Members and 1 Guest are viewing this topic.

Offline brcisna

  • Full Member
  • ***
  • Posts: 220
  • Karma: +0/-0
    • View Profile
squid to whatismyproxy results
« on: December 03, 2017, 08:48:34 am »
Hello All,

Been using pfsense-(now) 2.2-x on two school websites for 12 years now,,for a brief background.
packages installed: Squid-2.x) , squidGuard, lightsquid., in transparent proxy mode
As of a few days ago all clients are not being blocked at all to any restricted websites
have changed nothing in nat/firewall rules,FYI.
Have went through many many times , including remove/install of squid & squidGuard ,also.

went to whatismyproxy  com and shows indeed the webbrowser is using squid as proxy,,,but a couple entries has be baffled.

The HTTP_CACHE_CONTROL header exists, and is non zero. This may indicate a caching proxy.
HTTP/1.0 protocol does not include the HOST header, but we have received one. This indicates a proxy server receiving a HTTP/1.1 header from you and passing it on, while claiming only HTTP/1.0 for itself.
The header HTTP_X_FORWARDED_FOR may include an IP address other than the one you are coming from: internal_ip
In addition, the header HTTP_X_FORWARDED_FOR seems to be leaking a private IP address: internal_ip
The header: HTTP_X_FORWARDED_FOR is present with the value:internal_ip
The header: HTTP_VIA is present with the value:1.1 mail:8080 (squid/2.7.STABLE9).

Does the HTTP_X_FORWADED_FOR look correct,saying 'a leaking internal ip"?

Also in the "server" entry in return information it show :   Server   nginx/1.6.2

pfSense & squid & squidGuard has luckily always "just worked" so have never even tried the whatismyproxy website until a couple days ago.

Why is the SERVER entry showing nginx or is this just a generic return from that websites review.. Does the http_x_forwarded header entry look correct to anyone? yes our proxy port is 8080 for completeness.

Thank You