squidreversegeneral0.4.5Reverse Proxy Server: General/usr/local/pkg/squid.incGeneral/pkg_edit.php?xml=squid_reverse_general.xml&id=0Web Servers/pkg.php?xml=squid_reverse_peer.xmlMappings/pkg.php?xml=squid_reverse_uri.xmlRedirects/pkg.php?xml=squid_reverse_redir.xmlReal Time/squid_monitor.php?menu=reverseSync/pkg_edit.php?xml=squid_reverse_sync.xml&id=0Squid Reverse Proxy General SettingslisttopicReverse Proxy Interface(s)reverse_interface
Use CTRL + click to select multiple interfaces.
Important: To use Squid as a reverse proxy ONLY: After saving configuration here, you must tick the 'Enable Squid Proxy' checkbox under Services - Squid Proxy Server - General and click Save there. To disable the reverse proxy ONLY (without disabling Squid completely): Unselect all 'Reverse Proxy Interface(s)', uncheck both 'Enable HTTP Reverse Proxy' and 'Enable HTTPS Reverse Proxy' below and click Save.
]]>
interfaces_selectionwanUser Defined Reverse Proxy IPsreverse_ip
Note: Separate entries by semi-colons (;)
Important: Any entry here must be a valid, locally configured IP address.
]]>
input70External FQDNreverse_external_fqdnThe external fully qualified domain name of the WAN IP address.input70Reset TCP Connections on Unauthorized Requestsdeny_info_tcp_resetIf checked, the reverse proxy will reset the TCP connection if the request is unauthorized.checkboxonSquid Reverse HTTP SettingslisttopicEnable HTTP Reverse Proxyreverse_httpImportant: You must add a proper firewall rule with destination matching the 'Reverse Proxy Interface(s)' address.
]]>
checkboxreverse_http_port,reverse_http_defsiteoffReverse HTTP Portreverse_http_port
Default: 80
]]>
input580Reverse HTTP Default Sitereverse_http_defsite
Note: Leave empty to use 'External FQDN' value specified above.
]]>
input70Squid Reverse HTTPS SettingslisttopicEnable HTTPS Reverse Proxyreverse_httpsImportant: You must add a proper firewall rule with destination matching the 'Reverse Proxy Interface(s)' address.
]]>
checkboxreverse_https_port,reverse_https_defsite,reverse_ssl_cert,reverse_int_ca,reverse_ignore_ssl_valid,reverse_check_clientca,reverse_owaoffReverse HTTPS Portreverse_https_port
Default: 443
]]>
input5443Reverse HTTPS Default Sitereverse_https_defsite
Note: Leave empty to use 'External FQDN' value specified in 'Squid Reverse Proxy General Settings'.
]]>
input70Reverse SSL Certificatereverse_ssl_certChoose the SSL Server Certificate here.select_sourcedescrrefidnonenoneIntermediate CA Certificate (If Needed)reverse_int_ca
PEM format here.
]]>
textarea755base64Ignore Internal Certificate Validationreverse_ignore_ssl_validIf checked, internal certificate validation will be ignored.checkboxonCheck Client Certificatereverse_check_clientcaIf checked, clients need a client certificate to authenticate.checkboxoffClient Certificate CAreverse_ssl_clientcaChoose the CA used to issue client authentication certificates.select_sourcedescrrefidnonenoneClient Certificate Revocation Listreverse_ssl_clientcrlNote: This must match the 'Client Certificate CA' selected above!
Important: After updating the CRL in System - Cert Manager - Certificate Revocation, remember to press the 'Refresh CRL' button below.
Otherwise, the updated CRL will not have any effect on Squid reverse proxy users!
]]>
select_sourcedescrrefidnonenoneOWA Reverse Proxy General SettingslisttopicEnable OWA Reverse Proxyreverse_owaIf checked, Squid will act as an accelerator/SSL offloader for Outlook Web App.checkboxreverse_owa_ip,reverse_owa_activesync,reverse_owa_rpchttp,reverse_owa_mapihttp,reverse_owa_webservice,reverse_owa_autodiscoverCAS-Array / OWA Frontend IP Address(es)reverse_owa_ip
Note: Separate entries by semi-colons (;)
]]>
input70Enable ActiveSyncreverse_owa_activesyncIf checked, ActiveSync will be enabled.checkboxEnable Outlook Anywherereverse_owa_rpchttpIf checked, RPC over HTTP will be enabled.checkboxEnable MAPI HTTPreverse_owa_mapihttpThis feature is only available with at least Microsoft Exchange 2013 SP1
]]>
checkboxEnable Exchange WebServicesreverse_owa_webserviceThere are potential DoS side effects to its use. Please avoid unless really required.
]]>
checkboxEnable AutoDiscoverreverse_owa_autodiscoverYou also should set up the autodiscover DNS record to point to you WAN IP.
]]>
checkbox
squid_resync();