Modify

Ticket #4150 (closed defect: duplicate)

Opened 13 months ago

Last modified 13 months ago

Proxy filter is not working if you access proxy from VPN

Reported by: juan.jramos@… Owned by: jamor@…
Milestone: 2.2.X Component: squid
Severity: major Keywords: Proxy vpn filter
Cc:

Description

If the user is inside the network (10.0.0.X) the proxy works as i want: Ask password and filter, BUT if the user is connected using VPN (pptp) the proxy asks the password BUT allows access to everywhere! :\

this screenshot shows the problem: http://s14.postimage.org/xoh8qbxip/Untitled.jpg

A new test: I created a Network Object named "Red VPN". that network object should cover any request that comes from the vpn.

http://s15.postimage.org/tysjjbk23/Network_Object.jpg

Then i go to: Gateway > HTTP Proxy > Object's policy and created this object policy: http://s14.postimage.org/mwgvfdbwx/Proxy_Object_Policy.jpg

As you can see, that object says that for any request coming from "Red VPN", the policy is to "Filter", using the filter profile "Filtrados".

That filter profile, looks like this: http://s8.postimage.org/ubgkzrqdh/Filtrados_Profile.jpg

As you can see, the policy for Facebook, Youtube, Twitter etc is to "Always Deny"

Then... If i go to a computer connected from the vpn and try to access Facebook, this is what happens... The request is accepted anyway: http://s18.postimage.org/4qopmjbvd/Http_Log.jpg

Note: If i change the "Policy" from "Filter" to "Always deny", it works. It denies the access to any page. So, the problem is with the "Filter" policy

Attachments

Change History

comment:1 Changed 13 months ago by jamor@…

  • Status changed from new to closed
  • Resolution set to duplicate

Thanks a lot for the report Juan Jramos.

We have already tracked this issue in ticket #3892

Regards,

Javier

View

Add a comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.