{"id":2615,"date":"2020-07-12T20:41:07","date_gmt":"2020-07-12T18:41:07","guid":{"rendered":"https:\/\/tech.lobobrothers.com\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/"},"modified":"2025-02-01T13:07:00","modified_gmt":"2025-02-01T12:07:00","slug":"squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i","status":"publish","type":"post","link":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/","title":{"rendered":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2615\" class=\"elementor elementor-2615 elementor-1281\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7831dad6 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7831dad6\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5d519df1\" data-id=\"5d519df1\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-57cf4758 elementor-widget elementor-widget-text-editor\" data-id=\"57cf4758\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><\/p>\n<h2>Safer navigation<\/h2>\n<div><\/div>\n<div>Due to the great reception that the posts about Suricata and pfBlockerNG have had in pfSense and after the request of several users, we will make 2 posts due to how extensive they can be, the first one covering Squid and ClamAV and the second one SquidGuard and Lightsquid, to increase the security in the navigation of the users using them:<\/div>\n<div><\/div>\n<div style=\"padding-left: 40px;\"><strong>Squid<\/strong>, the most popular open source proxy server born in the 90s, due to its great performance as a proxy cache, the protocols supported HTTP, HTTPS, GOPHER, FTP, IMAP, &#8230;, the ability to limit connections or bandwidth, the option to use it as a transparent proxy and to use it as a reverse proxy, that is, it has it all.<\/div>\n<div><\/div>\n<div style=\"padding-left: 40px;\"><strong> SquidGuard<\/strong>, a filtering system using blacklists. In previous versions of pfSense we also have dansguardian a bit heavier than SquidGuard but also very good.<\/div>\n<div style=\"padding-left: 40px;\"><\/div>\n<div style=\"padding-left: 40px;\"><strong>Clam-AV<\/strong>, open source antivirus very well integrated in pfSense.<\/div>\n<div style=\"padding-left: 40px;\"><\/div>\n<div style=\"padding-left: 40px;\"><strong>Lightsquid<\/strong>, a web application that will generate very detailed reports from Squid logs.<\/div>\n<p>Before we start we will make a brief summary of what is a proxy server in a simple way and that is understandable for everyone, we could say that it is an intermediate server between two machines through which pass all requests made between two machines A and C being the proxy B to allow, deny, limit, . ..these requests, that is to say, the machine A instead of realizing a request to C, realizes it to B and this one to C and depending on the rules that are defined in the proxy server B will give the answer to A as we indicated allowing its connection, denying it, limiting it,&#8230;.<\/p>\n<p>There are several types of proxy depending on what we need, where we will not go into detail, we will only clarify that it is that of transparent proxy, simply that the machine that passes through the proxy does not know it, that is, it is transparent because it does not see it or need specific configuration, while a proxy just need to configure the machine to pass through the proxy. The existence of transparent proxies is one reason why we create rules on business computers so that they can not connect to any WiFi when they are outside the company because you never know what may be behind a free WiFi.<\/p>\n<p>Well after this little intro, let&#8217;s get started.<\/p>\n<p>To start we go to System\/Package Manager\/ Available Packages and we type squid in the search engine<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1287 size-large\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1-1024x562.png\" alt=\"pfsense available packages\" width=\"800\" height=\"439\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1-1024x562.png 1024w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1-300x165.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1-768x421.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1-700x384.png 700w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-1.png 1150w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>And as we can see, everything we need appears, since Clam-AV will install it when we install the Squid package. As simple as clicking on install and confirm for the three packages.<\/p>\n<p>Once installed in the Services menu we will have three new options Squid Proxy Server, Squid Reverse Proxy (which we will not talk about in this post but if you have any doubt write to us) and SquidGuard Proxy Filter. In the Status menu we will have Squid Proxy Reports.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1288 size-large\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2-1024x630.png\" alt=\"pfsense services\" width=\"800\" height=\"492\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2-1024x630.png 1024w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2-300x185.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2-768x473.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2-700x431.png 700w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-2.png 1160w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1289 size-large\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3-1024x460.png\" alt=\"pfsense status\" width=\"800\" height=\"359\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3-1024x460.png 1024w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3-300x135.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3-768x345.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3-700x314.png 700w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-3.png 1532w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/p>\n<p>We start by configuring Squid in Services\/ Squid Proxy Server\/ Local Cache. In the first section we find the general settings<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1303 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-10.png\" alt=\"squid cache general settings\" width=\"918\" height=\"471\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-10.png 918w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-10-300x154.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-10-768x394.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-10-700x359.png 700w\" sizes=\"(max-width: 918px) 100vw, 918px\" \/><\/p>\n<p>The first is the policy where you decide which objects will remain in the cache and which will be replaced, we have four options where we must put the one that best suits our needs, by default is LFUDA where it keeps the most requested objects in cache regardless of their size, to start is very good option.<\/p>\n<p>Low-Water Mark in % the warning index where it starts to release the cache when the swap is at 90%, here if you do not use SSD disks I advise you to put it at 80%.<\/p>\n<p>High-Water Mark in % the critical index where it releases cache more aggressively, like the previous one if you do not use SSD set the mark to 85%.<\/p>\n<p>Do Not Cache, in each line we would put ips or domains that should not be cached.<\/p>\n<p>Enable Offline Mode, this option can make your cache grow too much and I do not see it very useful, maybe in some specific case you can be useful, basically what it would do is for example, you have squid disconnected from the internet, if a client makes a request would serve the last copy of that web that you have in cache, with it disabled you could not access because squid has no way to verify the cached objects.<\/p>\n<p>External Cache Managers, if we use External Cache Managers.<\/p>\n<p>The next section Hard Disk cache settings.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1306 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-12.png\" alt=\"squid hard disk cache settings\" width=\"916\" height=\"464\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-12.png 916w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-12-300x152.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-12-768x389.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-12-700x355.png 700w\" sizes=\"(max-width: 916px) 100vw, 916px\" \/><\/p>\n<p>In this section we will define in Hard Disk Cache Size the disk space that we will use for the cache in MB, in this case 2 GB.<\/p>\n<p>The type of cache system, where ufs has always worked correctly for me.<\/p>\n<p>A button to clear the cache manually.<\/p>\n<p>The next value is quite critical for the speed of the cache, here we will specify how many directories Level-1 has, each directory has 256 subdirectories of level 2 if we put 16 would be a total of 4096 directories, a value that I consider good for 2048 MB of cache size for example assuming that each object has 16 KB there will be 2048&#215;1024= 2. 097.152 Kb divided by (16Level1x256Level2x16Kb) would make a total of 32 objects per directory a good value for 2GB of cache, the more cache space this level of objects has to increase. This value must be adjusted when you see the average number of objects you have in cache, the more directories the longer it will take to start the service but it will speed up the cache, although in quotes with a very low cache space you will have problems.<\/p>\n<p>The next option is the directory where it will be stored, followed by the minimum and maximum size of the objects.<\/p>\n<p>Then the next section would be the cache in memory much faster than the disk, where I would not assign more than 25% although in the help it says 50% because it is a parameter that then you forget it is there, you start to install services and you have a problem because you run out of RAM and the firewall starts swapping which already makes everything go pretty bad.<\/p>\n<p>The other two values for most scenarios are correct with 256k and GDSF policy.<\/p>\n<p>And the last section as of today I don&#8217;t think anyone is using it.<\/p>\n<p>We have configured the cache first because when configuring the service it will give you errors if it is not defined. With the cache ready we are going to go to the Squid general configuration in the General tab<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1292 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-4.png\" alt=\"pfsense proxy server general settings\" width=\"916\" height=\"827\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-4.png 916w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-4-300x271.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-4-768x693.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-4-700x632.png 700w\" sizes=\"(max-width: 916px) 100vw, 916px\" \/><\/p>\n<p>In the General settings section we find the Enable Squid Proxy option that we will have to activate, the Keep Settings option that as in any other package if activated will preserve Squid configurations, logs, cache and antivirus definitions if we uninstall the package.<\/p>\n<p>In which IP version it will listen, select IPV4.<\/p>\n<p>If we use CARP Squid will only work when this firewall is the Master and will stop when it is as Slave in a HA Master\/Slave architecture, where it is very important to synchronize the local cache if we use it.<\/p>\n<p>Proxy interface, in which interface we will activate the service, in our case we only have an internal LAN we select it and very important the loopback one because without it we will not be able to activate Lightsquid.<\/p>\n<p>The Proxy Port, the port where squid will listen and to which we must connect, by default in squid is 3128.<\/p>\n<p>ICP Port, we will leave it blank but if we use for example HA or remote caches we will put a port number.<\/p>\n<p>Allow Users on interface, we mark it so that the users connected to this interface can use the proxy.<\/p>\n<p>Resolve DNS IPV4 First, as indicated if you have problems accessing HTTPS content activate it, I have never needed it.<\/p>\n<p>Disable ICMP, to disable ping.<\/p>\n<p>Use Alternate DNS Servers for the Proxy Server, that is to say, to use DNS different from those that we have put in the general configuration of the Firewall.<\/p>\n<p>The next section would be Transparent Proxy Settings<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1295 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-5.png\" alt=\"pfsense transparent proxy settings\" width=\"920\" height=\"448\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-5.png 920w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-5-300x146.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-5-768x374.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-5-700x341.png 700w\" sizes=\"(max-width: 920px) 100vw, 920px\" \/><\/p>\n<p>In our case we are not going to activate it but as we explained before it would be for all equipment connected to the interfaces that we select to pass through the proxy without having to configure anything on the machines that are connected and with three options that are very well understood, make a Bypass depending on Private Address Destination, ie, that communication between your internal machines is direct where I advise you to activate it if you want to use transparent proxy. The other 2 options are in function of source or destination adding the ips, networks, host names or aliases separated by semicolon.<\/p>\n<p>The third section of this section is SSL Man In the Middle filtering, very important because nowadays most of the traffic is HTTPS.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1301 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9.png\" alt=\"ssl man in the middle filtering\" width=\"917\" height=\"913\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9.png 917w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9-300x300.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9-150x150.png 150w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9-768x765.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-9-700x697.png 700w\" sizes=\"(max-width: 917px) 100vw, 917px\" \/><\/p>\n<p>Where we are only interested in HTTPS\/SSL Interception have it active, the SSL\/MITM Mode Splice All as we are going to use SquidGuard therefore we will not need a CA, any of the other options you will have to create the CA first in System\/CertManager and then select in CA the entity created and finally select the interfaces where it will be active, it is possible although it says that it is not necessary that even selecting Splice All tells you that you need to install the CA, if so we install it and select it.<\/p>\n<p>Next section logs<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1311 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-13.png\" alt=\"logging settings\" width=\"918\" height=\"273\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-13.png 918w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-13-300x89.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-13-768x228.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-13-700x208.png 700w\" sizes=\"(max-width: 918px) 100vw, 918px\" \/><\/p>\n<p>Little to tell, activate them, path where to save them, how many days we want to have the file (blank will be unlimited, this will be configured depending on your needs and resources) and the last one to include in Squid the denied connections that SquidGuard returns us where it will only work if you follow the instructions detailed in click info&#8230;.<\/p>\n<p>And finally in the section Headers Handling, Language and Other Customizations<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1314 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-14.png\" alt=\"headers handing, languajes and other customizations\" width=\"919\" height=\"392\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-14.png 919w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-14-300x128.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-14-768x328.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-14-700x299.png 700w\" sizes=\"(max-width: 919px) 100vw, 919px\" \/><\/p>\n<p>Basically name that will appear in case of an error, the email address of the admin that users will see, the language and settings on the headers that except for special cases as it is would be correct for most scenarios unless there are pages that do not allow proxy, in that case, we put the X-Forwarder on off and check the box Suppress Squid Version.<\/p>\n<p>We move on to the Antivirus section<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1318 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-16.png\" alt=\"clamav integration using c-icap\" width=\"923\" height=\"725\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-16.png 923w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-16-300x236.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-16-768x603.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-16-700x550.png 700w\" sizes=\"(max-width: 923px) 100vw, 923px\" \/><\/p>\n<p>Where we find the first option to enable or not ClamAV<\/p>\n<p>What data we send from the client to ClamAV to taste of the consumer.<\/p>\n<p>To activate manual mode, why complicate the life in this.<\/p>\n<p>URL where to redirect when it has been blocked by virus very useful to educate the users in the navigation.<\/p>\n<p>Use Google Safe Browsing<\/p>\n<p>If you want to exclude audio and video in Streams from the scans, for performance I would exclude them.<\/p>\n<p>How often we want to update the ClamAV database and a button to do it manually.<\/p>\n<p>The region from where to update and finally alternative database servers.<\/p>\n<p>Let&#8217;s move on to the ACLs section, where the first section is simple to understand.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1320 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-17.png\" alt=\"squid access control lists\" width=\"921\" height=\"944\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-17.png 921w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-17-293x300.png 293w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-17-768x787.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-17-700x717.png 700w\" sizes=\"(max-width: 921px) 100vw, 921px\" \/><\/p>\n<p>In allowed Subnets we introduce the subnets that will be able to use the proxy, in our case as we activated Allow Users on Interfaces&#8221; in the General section we do not need to add any.<\/p>\n<p>Unrestricted IPS, we will add the networks or ips that will not be filtered.<\/p>\n<p>Banned Hosts Addresses, the subnets or ips that will not be allowed to use the proxy.<\/p>\n<p>Whitelist, the white list of target domains that will always be accessible to users.<\/p>\n<p>Blacklist, the opposite of those that will never be accessible.<\/p>\n<p>Block User Agent, to block certain browsers.<\/p>\n<p>Block MIME Types, to block MIME types such as (application\/javascript).<\/p>\n<p>And finally in this section the allowed ports<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1321 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-18.png\" alt=\"squid allowed ports\" width=\"922\" height=\"174\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-18.png 922w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-18-300x57.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-18-768x145.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-18-700x132.png 700w\" sizes=\"(max-width: 922px) 100vw, 922px\" \/><\/p>\n<p>Very useful when for example in SSL we use a different port to those indicated by default (443, 563). Example very used in SSL 8443.<\/p>\n<p>Next section Traffic Mgmt<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1322 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-19.png\" alt=\"squid traffic management settings\" width=\"920\" height=\"317\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-19.png 920w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-19-300x103.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-19-768x265.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-19-700x241.png 700w\" sizes=\"(max-width: 920px) 100vw, 920px\" \/><\/p>\n<p>In this first section the maximum download and upload size will not be used much, I have seen some cases where it is required by company policy but it will be 0.01%.<\/p>\n<p>The Overall Bandwidth will decrease the download bandwidth when the bandwidth usage reaches the specified value.<\/p>\n<p>Per-Host Throttling, the same but per host, if a host reaches the specified speed its download will decrease in speed.<\/p>\n<p>And the last option if we want that within these Throttling limits we include the Unrestricted of the ACLs.<\/p>\n<p>Squid Transfer Extensions Settings Section<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1323 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-20.png\" alt=\"squid transfer extensions settings\" width=\"917\" height=\"251\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-20.png 917w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-20-300x82.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-20-768x210.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-20-700x192.png 700w\" sizes=\"(max-width: 917px) 100vw, 917px\" \/><\/p>\n<p>If we want only some specific extensions we must activate the first checkbox which will activate the following ones that we are not going to explain because it is very clear.<\/p>\n<p>And finally in this section Squid Transfer Abort Settings<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1324 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-21.png\" alt=\"squid transfer quick abort settings\" width=\"920\" height=\"330\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-21.png 920w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-21-300x108.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-21-768x275.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-21-700x251.png 700w\" sizes=\"(max-width: 920px) 100vw, 920px\" \/><\/p>\n<p>This option has its crumb in each scenario, I recommend you to leave everything to 0 because the users are currently used to that everything goes very fast and if we activate the limitations of Throttling to a very low bandwidth, they will cancel the download, they will give it again, to resume and so several times, the cache by default will continue downloading the canceled requests, if a user cancels it 5 times then 5 downloads if we do not set this value to 0. On the other hand we can also tell it to continue the downloads from the cache if there are less than x Kb left. It is an option that, as I say, has its importance depending on the scenario.<\/p>\n<p>Let&#8217;s move on to the Authentication section. In all proxy of companies or clients we must have an authentication system to allow us to create rules depending on the type of user, because they are going to require it. With squid we have four methods, local users that would be added in the section Users, Active Directoruy, Radius or Captive Portal, in this section the options will be activated according to the chosen method, let&#8217;s select Local to not take much more time.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1328 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-23.png\" alt=\"squid authentication general settings\" width=\"919\" height=\"580\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-23.png 919w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-23-300x189.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-23-768x485.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-23-700x442.png 700w\" sizes=\"(max-width: 919px) 100vw, 919px\" \/><\/p>\n<p>Donde se nos activa 5 opciones, la primera Authentication Prompt donde pondremos lo que ver\u00e1n los usuarios en la ventana que les saltar\u00e1 como por ejemplo &#8220;Por favor introduce tu usuario y contrase\u00f1a&#8221;<\/p>\n<p>El n\u00famero de procesos para autenticar, si tenemos muchos usuarios y todos entran de golpe aumentarlo porque se quejar\u00e1n en funci\u00f3n de vuestro hardware.<\/p>\n<p>El tiempo tras el cual un Autenticaci\u00f3n TTL ser\u00e1 v\u00e1lida, al gusto de consumidor, hemos puesto 8 horas.<\/p>\n<p>Si le requerimos autenticaci\u00f3n a los Unrestricted IPs que tengamos en las ACLs y si queremos evitar que se tengan que autenticar ciertas ips o subredes.<\/p>\n<p>Ya nos queda menos de la parte Squid jejeje.\u00a0 Ahora en Users como hemos seleccionado Local vamos a introducir alguno haciendo click en Add y luego en Save<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1331 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-24.png\" alt=\"proxy server edit users\" width=\"921\" height=\"315\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-24.png 921w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-24-300x103.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-24-768x263.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-24-700x239.png 700w\" sizes=\"(max-width: 921px) 100vw, 921px\" \/><\/p>\n<p>In Real Time, as its name indicates, we will see what is happening through Squid in real time, differentiated in several sections such as the cache table, SquidGuard, Virus&#8230;..<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1332 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-25.png\" alt=\"squid monitor real time\" width=\"914\" height=\"961\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-25.png 914w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-25-285x300.png 285w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-25-768x807.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-25-700x736.png 700w\" sizes=\"(max-width: 914px) 100vw, 914px\" \/><\/p>\n<p>And at the top right the first icon restart service, second stop service, third general configuration, fourth status of services and fifth where we are.<\/p>\n<p>And finally if we use a HA scenario the Synchronization very important to configure.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1334 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-27.png\" alt=\"proxy server sync\" width=\"921\" height=\"387\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-27.png 921w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-27-300x126.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-27-768x323.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-27-700x294.png 700w\" sizes=\"(max-width: 921px) 100vw, 921px\" \/><\/p>\n<p>where we will choose the type, how often and the address of the servers to synchronize.<\/p>\n<p>And to finish this first part as in any service that we raise in pfSense and we want to be always raised we go to Service\/Service Watchdog and add the service Squid Proxy Server, ClamAV Antivirus, ICAP Interface for Squid and ClamAV, being as follows after our different posts in this same pfsense.<\/p>\n<p><img decoding=\"async\" class=\"aligncenter wp-image-1335 size-full\" src=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-28.png\" alt=\"pfsense service watchdog\" width=\"926\" height=\"432\" srcset=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-28.png 926w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-28-300x140.png 300w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-28-768x358.png 768w, https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2020\/07\/squid-28-700x327.png 700w\" sizes=\"(max-width: 926px) 100vw, 926px\" \/><\/p>\n<p>I hope you liked this first part, it won&#8217;t take long to make the second one. Have a nice day and enjoy it. <a href=\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-ii\/\"><strong>(Second part made by clicking here)<\/strong><\/a><\/p>\n<p>TL.<\/p>\n<p><\/p>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Safer navigation Due to the great reception that the posts about Suricata and pfBlockerNG have had in pfSense and after the request of several users, we will make 2 posts due to how extensive they can be, the first one covering Squid and ClamAV and the second one SquidGuard and Lightsquid, to increase the security [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3001,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[49,50,51],"tags":[],"class_list":["post-2615","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux-world","category-open-source","category-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT<\/title>\n<meta name=\"description\" content=\"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT\" \/>\n<meta property=\"og:description\" content=\"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\" \/>\n<meta property=\"og:site_name\" content=\"Blog sobre linux y el mundo opensource\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/LoboBrothers\/\" \/>\n<meta property=\"article:published_time\" content=\"2020-07-12T18:41:07+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-02-01T12:07:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1920\" \/>\n\t<meta property=\"og:image:height\" content=\"1280\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TL\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TL\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"17 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\"},\"author\":{\"name\":\"TL\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/11c359ab9896aa196007651fa6208beb\"},\"headline\":\"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I\",\"datePublished\":\"2020-07-12T18:41:07+00:00\",\"dateModified\":\"2025-02-01T12:07:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\"},\"wordCount\":2643,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#organization\"},\"image\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp\",\"articleSection\":[\"Linux World\",\"Open Source\",\"Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\",\"url\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\",\"name\":\"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT\",\"isPartOf\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp\",\"datePublished\":\"2020-07-12T18:41:07+00:00\",\"dateModified\":\"2025-02-01T12:07:00+00:00\",\"description\":\"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...\",\"breadcrumb\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage\",\"url\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp\",\"contentUrl\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp\",\"width\":1920,\"height\":1280,\"caption\":\"Squid\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Portada\",\"item\":\"https:\/\/tech.lobobrothers.com\/en\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#website\",\"url\":\"https:\/\/tech.lobobrothers.com\/en\/\",\"name\":\"Tech LBT\",\"description\":\"Como apasionados de la tecnolog\u00eda y amantes del open source creamos este blog con art\u00edculos interesantes obre linux, cloud, open source, criptomonedas y ciberseguridad\",\"publisher\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/tech.lobobrothers.com\/en\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#organization\",\"name\":\"Lobo Brothers Technology\",\"url\":\"https:\/\/tech.lobobrothers.com\/en\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2019\/06\/logo_red.png\",\"contentUrl\":\"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2019\/06\/logo_red.png\",\"width\":110,\"height\":50,\"caption\":\"Lobo Brothers Technology\"},\"image\":{\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/LoboBrothers\/\",\"https:\/\/www.linkedin.com\/company\/lobobrothers\/about\/?viewAsMember=true\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/11c359ab9896aa196007651fa6208beb\",\"name\":\"TL\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a2d3b9e0b67bd28fe8248346c09cbe07?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a2d3b9e0b67bd28fe8248346c09cbe07?s=96&d=mm&r=g\",\"caption\":\"TL\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT","description":"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/","og_locale":"en_US","og_type":"article","og_title":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT","og_description":"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...","og_url":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/","og_site_name":"Blog sobre linux y el mundo opensource","article_publisher":"https:\/\/www.facebook.com\/LoboBrothers\/","article_published_time":"2020-07-12T18:41:07+00:00","article_modified_time":"2025-02-01T12:07:00+00:00","og_image":[{"width":1920,"height":1280,"url":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg","type":"image\/jpeg"}],"author":"TL","twitter_card":"summary_large_image","twitter_misc":{"Written by":"TL","Est. reading time":"17 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#article","isPartOf":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/"},"author":{"name":"TL","@id":"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/11c359ab9896aa196007651fa6208beb"},"headline":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I","datePublished":"2020-07-12T18:41:07+00:00","dateModified":"2025-02-01T12:07:00+00:00","mainEntityOfPage":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/"},"wordCount":2643,"commentCount":0,"publisher":{"@id":"https:\/\/tech.lobobrothers.com\/en\/#organization"},"image":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage"},"thumbnailUrl":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp","articleSection":["Linux World","Open Source","Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/","url":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/","name":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I - LBT","isPartOf":{"@id":"https:\/\/tech.lobobrothers.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage"},"image":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage"},"thumbnailUrl":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp","datePublished":"2020-07-12T18:41:07+00:00","dateModified":"2025-02-01T12:07:00+00:00","description":"Before we start, we will make a brief summary of what a proxy server is in a simple way that is understandable for everyone, we could say...","breadcrumb":{"@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#primaryimage","url":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp","contentUrl":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2021\/07\/squid.jpg.webp","width":1920,"height":1280,"caption":"Squid"},{"@type":"BreadcrumbList","@id":"https:\/\/tech.lobobrothers.com\/en\/squid-squidguard-lightsquid-and-clam-av-in-pfsense-part-i\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Portada","item":"https:\/\/tech.lobobrothers.com\/en\/"},{"@type":"ListItem","position":2,"name":"Squid, SquidGuard, Lightsquid and Clam-AV in pfSense Part I"}]},{"@type":"WebSite","@id":"https:\/\/tech.lobobrothers.com\/en\/#website","url":"https:\/\/tech.lobobrothers.com\/en\/","name":"Tech LBT","description":"Como apasionados de la tecnolog\u00eda y amantes del open source creamos este blog con art\u00edculos interesantes obre linux, cloud, open source, criptomonedas y ciberseguridad","publisher":{"@id":"https:\/\/tech.lobobrothers.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/tech.lobobrothers.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/tech.lobobrothers.com\/en\/#organization","name":"Lobo Brothers Technology","url":"https:\/\/tech.lobobrothers.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2019\/06\/logo_red.png","contentUrl":"https:\/\/tech.lobobrothers.com\/wp-content\/uploads\/2019\/06\/logo_red.png","width":110,"height":50,"caption":"Lobo Brothers Technology"},"image":{"@id":"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/LoboBrothers\/","https:\/\/www.linkedin.com\/company\/lobobrothers\/about\/?viewAsMember=true"]},{"@type":"Person","@id":"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/11c359ab9896aa196007651fa6208beb","name":"TL","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/tech.lobobrothers.com\/en\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a2d3b9e0b67bd28fe8248346c09cbe07?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a2d3b9e0b67bd28fe8248346c09cbe07?s=96&d=mm&r=g","caption":"TL"}}]}},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/posts\/2615","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/comments?post=2615"}],"version-history":[{"count":0,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/posts\/2615\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/media\/3001"}],"wp:attachment":[{"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/media?parent=2615"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/categories?post=2615"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/tech.lobobrothers.com\/en\/wp-json\/wp\/v2\/tags?post=2615"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}