pfSense Gold Subscription

Author Topic: is the squidguard package stable at the moment.....  (Read 10149 times)

0 Members and 1 Guest are viewing this topic.

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
is the squidguard package stable at the moment.....
« on: February 17, 2008, 05:17:00 am »
We are planning at the moment to put the squidguard package onto several production pfsense machines.

Is this package error-free to work cleanly with production machines?

heiko

Offline dvserg

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4785
  • Karma: +0/-0
    • View Profile
    • My Homepage
Re: is the squidguard package stable at the moment.....
« Reply #1 on: February 17, 2008, 05:56:26 am »
Known problems and issues:
- have problem with use internel sgerror.php on HTTPS webgui proto: solve problem with using ext error pages (General page option);
- near time will finished global modification blacklist alghorithm ( now i work with rebuild-DB mechanism and blk-list behavior On reinstallation SG).

!Fixed! reboot autostart SG
All others (how know) worked stable.
ps if have any other problems and issues - i ready to fixed this.

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #2 on: February 17, 2008, 06:03:50 am »
Thanks dvserg!

I will test it on one production machine in moscow, and then we will see

greetings
heiko

Offline dvserg

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4785
  • Karma: +0/-0
    • View Profile
    • My Homepage
Re: is the squidguard package stable at the moment.....
« Reply #3 on: February 17, 2008, 06:12:47 am »
If any questions - i have ICQ
Welcome with 10.00-17.00 MSK in work days.

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #4 on: February 17, 2008, 06:15:29 am »
Ok, fine, thanks!
Heiko

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #5 on: February 17, 2008, 08:18:15 am »
if i klick on the "apply" button at the "general settings" -tab, these errors occurs

Warning: Invalid argument supplied for foreach() in /usr/local/pkg/squidguard_configurator.inc on line 540 Warning: implode(): Bad arguments. in /usr/local/pkg/squidguard_configurator.inc on line 320 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/pkg/squidguard_configurator.inc:540) in /usr/local/www/pkg_edit.php on line 35

Greetings
Heiko

Offline gmckinney

  • Jr. Member
  • **
  • Posts: 90
  • Karma: +0/-0
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #6 on: February 17, 2008, 08:50:03 am »
if i klick on the "apply" button at the "general settings" -tab, these errors occurs

Warning: Invalid argument supplied for foreach() in /usr/local/pkg/squidguard_configurator.inc on line 540 Warning: implode(): Bad arguments. in /usr/local/pkg/squidguard_configurator.inc on line 320 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/pkg/squidguard_configurator.inc:540) in /usr/local/www/pkg_edit.php on line 35

Greetings
Heiko

Sounds like "direct" output to web server from the PHP scripts instead of "buffered" output.  I have not looked at the php  configuration in the pfSense system - is it set to buffer output???

Just wondering...

gm...

Offline dvserg

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4785
  • Karma: +0/-0
    • View Profile
    • My Homepage
Re: is the squidguard package stable at the moment.....
« Reply #7 on: February 17, 2008, 09:50:50 am »
if i klick on the "apply" button at the "general settings" -tab, these errors occurs

This new blacklist update  ::) Tomorrow fix it.

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #8 on: February 17, 2008, 10:52:26 am »
Sorry...
if i create an ACL and delete this item, so the ACL list is empty the following error occurs....

Warning: Invalid argument supplied for foreach() in /usr/local/pkg/squidguard.inc on line 414 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/pkg/squidguard.inc:414) in /usr/local/www/pkg.php on line 87

Another blacklist update?

greetings
Heiko

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #9 on: February 17, 2008, 11:25:57 am »
Hello dvserg,
for me it blocks nothing with the default configuration, maybe my fault...
Do you have a small tutorial for starting.
Greetings
Heiko

Offline dvserg

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4785
  • Karma: +0/-0
    • View Profile
    • My Homepage
Re: is the squidguard package stable at the moment.....
« Reply #10 on: February 17, 2008, 11:38:53 am »
Code: [Select]
Warning: Invalid argument supplied for foreach()
Add one entry on Destination page (i will insert checking for empty listing)

Quick start
http://diskatel.narod.ru/sgquick.htm

Probably You have error in config - in this situation SG generated small block config
Check log on thirts page (general) for found error messages.
« Last Edit: February 17, 2008, 11:46:18 am by dvserg »

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #11 on: February 17, 2008, 12:25:28 pm »
I took  a look at you tutorial, but my webgui-log shows errors and says "starts with default". I see the ACL errors, but i didnīt have ACLīs in my config. I have downloaded the shallalist and the logs says that the db is OK. At the End i click on the Apply button and then this happens.

Here my log...


7.02.2008 19:17:16 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:17 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:23 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:28 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:34 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:42 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:45 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:50 : sg_init: ext initialization squidguard_config
17.02.2008 19:17:53 : sg_reconfigure: start.
17.02.2008 19:17:53 : sg_reconfigure_user_db: begin at '/var/db/squidGuard'
17.02.2008 19:17:53 : sg_reconfigure_user_db: STOPPED; User destinations list empty
17.02.2008 19:17:53 : sg_remove_unused_db_entries: begin
17.02.2008 19:17:53 : sg_remove_unused_db_entries: end
17.02.2008 19:17:53 : sg_reconfigure_user_db: end.
17.02.2008 19:17:53 : sg_build_config: create squidGuard config.
17.02.2008 19:17:53 : sg_build_config: checking configuration data.
17.02.2008 19:17:53 : sg_build_config: error configuration data. It's all errors:
SOURCE ''error: Size of name must be between [2..16]. Invalid name . Valid name symbols: ['a-Z', '_', '0-9', '-']. First symbol must be a letter.
ACL '' error: ontime pass list is empty.
17.02.2008 19:17:53 : sg_build_config: terminated.
17.02.2008 19:17:53 : sg_redirector_base_url: select redirector base url (https://192.168.6.1:61003/sgerror.php?url=404%20Check%20proxy%20filter%20settings%20on%20errors.&a=%a&n=%n&i=%i&s=%s&t=%t&u=%u)
17.02.2008 19:17:53 : sg_redirector_base_url: End.
17.02.2008 19:17:53 : sg_build_default_config: ATTENTION! Created default configuration. All content will blocked.
17.02.2008 19:17:53 : sg_build_default_config: End.
17.02.2008 19:17:53 : sg_reconfigure: generate squidGuard config and save to /usr/local/etc/squidGuard/squidGuard.conf.
17.02.2008 19:17:53 : squid_reconfigure: begin
17.02.2008 19:17:53 : squid_reconfigure: remove old redirector options from Squid config.
17.02.2008 19:17:53 : squid_reconfigure: add new redirector options to Squid config.
17.02.2008 19:17:56 : sg_reconfigure: end.
17.02.2008 19:18:08 : sg_init: ext initialization squidguard_config

Greetings
Heiko

Offline heiko

  • Hero Member
  • *****
  • Posts: 663
  • Karma: +0/-0
  • Get a load of that!
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #12 on: February 17, 2008, 01:29:39 pm »
Hello,
last Test:

First of all, i think the acl page have problems. If i delete ACL Lines, the Line shows a blank config. If i restarted squidguard errors appears.

-  Source not found....

Now i edit the acl line and filling a few words in it and checked disable. After that, i have made a restart at the generel page with clicing the apply button.

For me it looks Ok, but also nothing content was blocked...

/var/squidGuard/log/sg_configurator.log
17.02.2008 20:10:25 : sg_reconfigure_user_db: -- add moskau expressions ''spiegel|gmx''
17.02.2008 20:10:25 : sg_rebuild_db: Begin with path '/var/db/squidGuard'.
17.02.2008 20:10:25 : sg_create_rebuild_config: Begin with dbhome='/var/db/squidGuard'.
17.02.2008 20:10:25 : sg_create_rebuild_config: -- added item 'usr_moskau' = '/var/db/squidGuard/moskau'.
17.02.2008 20:10:25 : sg_redirector_base_url: select redirector base url (https://192.168.6.1:61003/sgerror.php?url=404&a=%a&n=%n&i=%i&s=%s&t=%t&u=%u)
17.02.2008 20:10:25 : sg_redirector_base_url: End.
17.02.2008 20:10:25 : sg_create_rebuild_config: End.
17.02.2008 20:10:25 : sg_rebuild_db: Create temporary config '/tmp/squidGuard_rebuild.conf_usrdb'.
17.02.2008 20:10:25 : sg_rebuild_db: Started SH script '/tmp/squidGuard_db_rebuild.sh_usrdb'.
17.02.2008 20:10:25 : sg_rebuild_db: End.
17.02.2008 20:10:25 : sg_remove_unused_db_entries: begin
17.02.2008 20:10:25 : sg_remove_unused_db_entries: end
17.02.2008 20:10:25 : sg_reconfigure_user_db: end.
17.02.2008 20:10:25 : sg_build_config: create squidGuard config.
17.02.2008 20:10:25 : sg_build_config: checking configuration data.
17.02.2008 20:10:25 : sg_build_config: add times
17.02.2008 20:10:25 : sg_build_config: add sources
17.02.2008 20:10:25 : sg_build_config: add blacklist entries
17.02.2008 20:10:25 : sg_build_config: added:
ads; aggressive; audio-video; drugs; gambling; hacking; mail; porn; proxy; violence; warez;

17.02.2008 20:10:25 : sg_build_config: add destinations
17.02.2008 20:10:25 : sg_build_config: added:
moskau;

17.02.2008 20:10:25 : sg_build_config: add ACL
17.02.2008 20:10:25 : sg_build_config: added:
test1; test;

17.02.2008 20:10:25 : sg_build_config: add Default
17.02.2008 20:10:25 : sg_redirector_base_url: select redirector base url (https://192.168.6.1:61003/sgerror.php?url=http://www.google.ru&a=%a&n=%n&i=%i&s=%s&t=%t&u=%u)
17.02.2008 20:10:25 : sg_redirector_base_url: End.
17.02.2008 20:10:26 : sg_redirector_base_url: select redirector base url (https://192.168.6.1:61003/sgerror.php?url=404%20overtime&a=%a&n=%n&i=%i&s=%s&t=%t&u=%u)
17.02.2008 20:10:26 : sg_redirector_base_url: End.
17.02.2008 20:10:26 : sg_reconfigure: generate squidGuard config and save to /usr/local/etc/squidGuard/squidGuard.conf.
17.02.2008 20:10:26 : squid_reconfigure: begin
17.02.2008 20:10:26 : squid_reconfigure: remove old redirector options from Squid config.
17.02.2008 20:10:26 : squid_reconfigure: add new redirector options to Squid config.
17.02.2008 20:10:29 : sg_reconfigure: end.
17.02.2008 20:10:29 : sg_init: ext initialization squidguard_config
17.02.2008 20:11:14 : sg_init: ext initialization squidguard_config
17.02.2008 20:11:14 : sg_init: ext initialization squidguard_config
17.02.2008 20:16:49 : sg_init: ext initialization squidguard_config
17.02.2008 20:17:01 : sg_init: ext initialization squidguard_config
17.02.2008 20:17:01 : sg_init: ext initialization squidguard_config
17.02.2008 20:17:23 : sg_init: ext initialization squidguard_config
17.02.2008 20:17:26 : sg_init: ext initialization squidguard_config
17.02.2008 20:18:10 : sg_init: ext initialization squidguard_config
17.02.2008 20:18:10 : sg_init: ext initialization squidguard_config

I donīt know where my config is buggy. Maybe, take a look at the screenshots
I donīt use the transparent proxy feature but local user authentication.

Greetings
Heiko
« Last Edit: February 17, 2008, 01:31:43 pm by heiko »

Offline ColdFusion

  • Full Member
  • ***
  • Posts: 168
  • Karma: +0/-0
    • View Profile
Re: is the squidguard package stable at the moment.....
« Reply #13 on: February 18, 2008, 09:51:17 am »
I'm getting something similar...all was well until recently..... After awhile the error stops showing and Squidguard is apparently running, but no content gets blocked. If I re-install I get the same issue.

Warning: implode(): Bad arguments. in /usr/local/pkg/squidguard_configurator.inc on line 367 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/pkg/squidguard_configurator.inc:367) in /usr/local/www/pkg_edit.php on line 35

Offline dvserg

  • Global Moderator
  • Hero Member
  • *****
  • Posts: 4785
  • Karma: +0/-0
    • View Profile
    • My Homepage
Re: is the squidguard package stable at the moment.....
« Reply #14 on: February 18, 2008, 10:32:35 am »
Thanks. I will test this too.