Documente Academic
Documente Profesional
Documente Cultură
http://hubpages.com/hub/How-to-setup-a-transparent-proxy-using-pfSense
by skear 95 Followers
Source: http://www.squid-cache.org/
usage, or filtering the traffic. The proxy server will store local copies of HTML pages, images, and other files in its cache. Caching proxy servers can greatly improve the internet performance of corporate networks or internet cafe's where many users may be requesting similar pages. When a client requests a web page the proxy checks to see if has any of the files stored in cache, if it does it serves them to the client without having to download them from the web server. This reduces latency and saves internet bandwidth. Transparent proxys route the clients traffic through the proxy server automatically, unlike traditional proxys which require configuration changes on the client systems. If you are unfamiliar with pfSense check out an Introduction to pfSense. Getting Started The first thing you'll need to do is install the squid package in pfSense. This can be done from the package manager found under the system menu. Locate the Squid package and click the + symbol next to it to begin the installation. The installation process normally takes a few minutes to complete. Configuration After the installation is completed you will have a new menu option under 'Services' called 'Proxy Server'. Click on the new menu option to bring of the configuration page.
Accessing the proxy server menu Package installation
Here you will need to set the proxy interface which is typically LAN. Next check to box 'Allow users on the interface'. Then check the box 'Enable
1 of 5
15.11.2013 9:33
http://hubpages.com/hub/How-to-setup-a-transparent-proxy-using-pfSense
transparent proxy'. Now scroll down to the bottom and hit save. This will start the squid service using the settings you have defined. At this point you have a fully functional transparent proxy server running on
Squid proxy configuration
pfSense. You do not need to make any changes to the computers on your network for them to use the proxy. Any clients requesting web pages on port 80 will be automatically redirected through the proxy. The users on your network won't even know their traffic is going through a proxy!
Traffic Management
The traffic management tab has some settings that are useful if you want to place bandwidth usage restrictions on the proxy. Using these settings you can configure a maximum download or upload size which will restrict transfers over a certain size limit. You can also set the proxy to throttle
Traffic Management Settings
binary files, cd images, or any other file type that you specify. Per host throttling sets the maximum amount of bandwidth an individual host can use.
Performance Tweaks
There are various options on the cache tab of the squid configuration page that you can modify to improve performance in your environment. Below are some of the settings I recommend modifying. If the computer running the proxy has a limited amount of disk and ram you should be cautious not to use overly aggressive settings. On the other hand if you have lots of resources to spare you can increase the settings to improve performance. Hard disk cache size - This sets the total amount of hard disk space squid will use to cache objects. If you have a large hard drive you can increase this setting to cache more objects. Just remember that objects cached in memory will be retrieved faster than objects on hard disk. Memory cache size - If your pfSense system has plenty of ram I recommend increasing the size of the memory cache. Objects that squid can't store in memory end up getting swapped to disk which is much slower than RAM. Maximum object size -The default of 4K is pretty small, I recommend increasing this to 50. You could set it larger but most cache hits tend to take place on small files anyway. Edit /boot/loader.conf.local - This change needs to be done via SSH. Using a text editor such as vi add kern.ipc.nmbclusters="32768" to the file then save the file and reboot the pfSense router. This increases the total amount of memory used for socket buffers to 32M. Visit the pfSense documentation site for more Squid performance tuning tweaks.
2 of 5
15.11.2013 9:33
http://hubpages.com/hub/How-to-setup-a-transparent-proxy-using-pfSense
Proxy Reports
If you are interested in tracking the usage of your proxy you can install an
3 of 5
15.11.2013 9:33
http://hubpages.com/hub/How-to-setup-a-transparent-proxy-using-pfSense
additional package called Lightsquid. Lightsquid will generate interactive reports that track all of the websites visited by users, as well as a list of top sites. You can even determine which IP visited a certain site, and what time it was visited.
Lightsquid Report
Lightsquid can be installed through the pfSense package manager the same way you installed squid. After installation a new menu item will be created under Status called Proxy Report. On the settings page you can set the report refresh schedule to an interval between 10 minutes and 24 hours. This determines how often Lightsquid generates a new report. You can manually refresh the report using the refresh now button. To view the report click on the Lightsquid Report tab.
Lots of 5 Soekris Net4521-30 Board Only W/CF card Current Bid: $80.00
4 of 5
15.11.2013 9:33
http://hubpages.com/hub/How-to-setup-a-transparent-proxy-using-pfSense
5 of 5
15.11.2013 9:33