Hola tengo un problema con el Squid modo SSL Bump,
Este es parte del log de cache.log de Squid:
2017/04/07 12:35:24 kid1| ERROR: NAT/TPROXY lookup failed to locate original IPs on local=192.168.101.201:3130 remote=192.168.101.211:3921 FD 24 flags=33
Mi archivo squid.conf:
acl manager proto cache_object
acl localnet src 192.168.101.0/24
acl SSL_ports port 443
acl Safe_ports port 80 # http
acl Safe_ports port 8080
acl Safe_ports port 21 # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70 # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535 # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http
acl CONNECT method CONNECT
acl FTP proto FTP
always_direct allow FTP
http_access deny !Safe_ports
http_access deny CONNECT !SSL_ports
http_access allow localhost manager
http_access deny manager
http_access allow localnet
request_header_access Referer deny all
request_header_access X-Forwarded-For deny all
request_header_access Via deny all
request_header_access Cache-Control deny all
visible_hostname PROXY-LN2
http_port 192.168.101.201:3128
http_port 192.168.101.201:3129 intercept
http_port 192.168.101.201:3130 intercept ssl-bump generate-host-certificates=on dynamic_cert_mem_cache_size=4MB cert=/etc/squid/ssl/squid.pem
sslcrtd_program /usr/lib/squid3/ssl_crtd -s /var/lib/ssl_db -M 4MB
ssl_bump server-first all
sslproxy_cert_error allow all
sslproxy_flags DONT_VERIFY_PEER
forwarded_for off
coredump_dir /var/spool/squid 64 16 256
refresh_pattern ^ftp: 1440 20% 10080
refresh_pattern ^gopher: 1440 0% 1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern (Release|Packages(.gz)*)$ 0 20% 2880
refresh_pattern . 0 20% 4320
El proxy funciona bien con el puerto 3128, pero con el puerto 3130 para SSL no filtra/cachea los https, genere el certificado para los navegadores, en Firefox me tira "Fallo en conexión segura", no se que estare haciendo mal en la configuracion, gracias, saludos
Yo te recomendaria que leyeras esto: https://wiki.squid-cache.org/ConfigExamples/Intercept/SslBumpExplicit, Saludos