![](https://static.wixstatic.com/media/68165d_c79962566f7a4726b7cb10fbccf109c7~mv2.jpg/v1/fill/w_320,h_180,al_c,q_80,enc_auto/68165d_c79962566f7a4726b7cb10fbccf109c7~mv2.jpg)
Trong hướng dẫn này mình cấu hình Squid Proxy mode Transparent
1. Login vào pfSense cài package squid và squidGuard
Vào System > Package Manager
![](https://static.wixstatic.com/media/68165d_d6ff6f3e14e24b7582f3d28cf8078ebd~mv2.png/v1/fill/w_980,h_407,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_d6ff6f3e14e24b7582f3d28cf8078ebd~mv2.png)
Chọn tab Available Packages
Search term: nhập từ khóa vào "squid" rồi bấm Search
Chọn package squid nhấn Install
![](https://static.wixstatic.com/media/68165d_51ad7d9444074dd49c211adc2a81f7e2~mv2.png/v1/fill/w_980,h_474,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_51ad7d9444074dd49c211adc2a81f7e2~mv2.png)
Nhấn Confirm
![](https://static.wixstatic.com/media/68165d_d290e38b0cab4a47bb80ba6ed6a8c34a~mv2.png/v1/fill/w_980,h_272,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_d290e38b0cab4a47bb80ba6ed6a8c34a~mv2.png)
Đợi quá trình cài đặt diễn ra, lưu ý trong quá trình cài đặt không được tắt trang web hoặc refresh
![](https://static.wixstatic.com/media/68165d_23c81b0bbe304464ac25b367cf16ea2b~mv2.png/v1/fill/w_980,h_500,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_23c81b0bbe304464ac25b367cf16ea2b~mv2.png)
Tiếp tục cài squidGuard
![](https://static.wixstatic.com/media/68165d_4e77d910d0ca4d0286f74b1cb8c41ccc~mv2.png/v1/fill/w_980,h_430,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_4e77d910d0ca4d0286f74b1cb8c41ccc~mv2.png)
![](https://static.wixstatic.com/media/68165d_4ef2812314b340898cfffeaf7dd8ed78~mv2.png/v1/fill/w_980,h_297,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_4ef2812314b340898cfffeaf7dd8ed78~mv2.png)
![](https://static.wixstatic.com/media/68165d_acc9b1539357456fb8de603263617be8~mv2.png/v1/fill/w_980,h_496,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_acc9b1539357456fb8de603263617be8~mv2.png)
2. Tạo Certificate Authority cho SSL Man In the Middle Filtering
Vào System > Cert. Manager
![](https://static.wixstatic.com/media/68165d_d218659a6b2c4e2d9a204dd12d211e79~mv2.png/v1/fill/w_980,h_416,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_d218659a6b2c4e2d9a204dd12d211e79~mv2.png)
Tab CAs nhấn Add
![](https://static.wixstatic.com/media/68165d_6174880d5e464658ae2bf14d89e5d81e~mv2.png/v1/fill/w_980,h_352,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_6174880d5e464658ae2bf14d89e5d81e~mv2.png)
Descriptive Name: đặt tên cho CA
Method: chọn Create an internal Certificate Authority
Country Code: chọn VN
![](https://static.wixstatic.com/media/68165d_e103f7d1a3994f5da77c8a1306c1bd1f~mv2.png/v1/fill/w_980,h_483,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_e103f7d1a3994f5da77c8a1306c1bd1f~mv2.png)
![](https://static.wixstatic.com/media/68165d_36973709acc24604963414ba5d5e9820~mv2.png/v1/fill/w_980,h_301,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_36973709acc24604963414ba5d5e9820~mv2.png)
CA sau khi đã tạo xong
![](https://static.wixstatic.com/media/68165d_47001fc95ef44508bfa269cf0c56c984~mv2.png/v1/fill/w_980,h_431,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_47001fc95ef44508bfa269cf0c56c984~mv2.png)
3. Cấu hình Squid Proxy Server
Vào Services > Squid Proxy Server
![](https://static.wixstatic.com/media/68165d_9aef3fd852ce4e069b4d1d3b59e34219~mv2.png/v1/fill/w_980,h_526,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_9aef3fd852ce4e069b4d1d3b59e34219~mv2.png)
Chọn tab Local Cache
Các thông số chúng ta để mặc định
![](https://static.wixstatic.com/media/68165d_738b05a7bc4040fca8d3ff310868f55b~mv2.png/v1/fill/w_980,h_499,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_738b05a7bc4040fca8d3ff310868f55b~mv2.png)
Hard Disk Cache Size: chỉ định dung lượng disk để lưu cache
![](https://static.wixstatic.com/media/68165d_b4b9b85e71cd464ab37eaa96e2b7c8f2~mv2.png/v1/fill/w_980,h_424,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_b4b9b85e71cd464ab37eaa96e2b7c8f2~mv2.png)
![](https://static.wixstatic.com/media/68165d_052aac66d5fd4a2aa1dcb7ac9631ffb6~mv2.png/v1/fill/w_980,h_549,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_052aac66d5fd4a2aa1dcb7ac9631ffb6~mv2.png)
![](https://static.wixstatic.com/media/68165d_a680a15513e64efabd3191028a7f7d8a~mv2.png/v1/fill/w_980,h_364,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_a680a15513e64efabd3191028a7f7d8a~mv2.png)
Chọn tab General
Enable Squid Proxy: tick chọn
Proxy Interface(s): chọn interface sẽ qua proxy
![](https://static.wixstatic.com/media/68165d_5b80837f80434dc79ed5ff8a1a5db5ef~mv2.png/v1/fill/w_980,h_415,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_5b80837f80434dc79ed5ff8a1a5db5ef~mv2.png)
![](https://static.wixstatic.com/media/68165d_f70a3a7062264e4db8870e11118a6843~mv2.png/v1/fill/w_980,h_337,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_f70a3a7062264e4db8870e11118a6843~mv2.png)
Transparent HTTP Proxy: check chọn
Transparent Proxy Interface(s): chọn interface đi qua proxy
![](https://static.wixstatic.com/media/68165d_f411aa084b6d4a0bbaadaf590012cef1~mv2.png/v1/fill/w_980,h_479,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_f411aa084b6d4a0bbaadaf590012cef1~mv2.png)
HTTPS/SSL Interception: check chọn
SSL Intercept Interface(s): chọn interface đi qua proxy
CA: chọn CA đã tạo từ đầu
![](https://static.wixstatic.com/media/68165d_ce71ea0680fc4d9fa72fd644931fe4ff~mv2.png/v1/fill/w_980,h_492,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_ce71ea0680fc4d9fa72fd644931fe4ff~mv2.png)
Rotate Logs: số ngày log sẽ được giữ lại
![](https://static.wixstatic.com/media/68165d_9dfbe81f48f349f7b93ec2bcffa6da49~mv2.png/v1/fill/w_980,h_447,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_9dfbe81f48f349f7b93ec2bcffa6da49~mv2.png)
![](https://static.wixstatic.com/media/68165d_58186e56a50743b8b5fb4dcef446b7f0~mv2.png/v1/fill/w_980,h_462,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_58186e56a50743b8b5fb4dcef446b7f0~mv2.png)
4. Cấu hình SquidGuard Proxy Filter
Vào Services > SquidGuard Proxy Filter
![](https://static.wixstatic.com/media/68165d_bf0d6b3e846c48888da7bf12bcb45562~mv2.png/v1/fill/w_980,h_489,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_bf0d6b3e846c48888da7bf12bcb45562~mv2.png)
Qua tab Target categories > Add
![](https://static.wixstatic.com/media/68165d_d5e776a8d19141e38232c69dcdc52d7a~mv2.png/v1/fill/w_980,h_301,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_d5e776a8d19141e38232c69dcdc52d7a~mv2.png)
Name: đặt tên cho rule
Domain List: nhập tên domain, ở đây mình muốn cấm truy cập facebook và youtube
![](https://static.wixstatic.com/media/68165d_a76f1ad48db44429b3d0840310a843fb~mv2.png/v1/fill/w_980,h_530,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_a76f1ad48db44429b3d0840310a843fb~mv2.png)
![](https://static.wixstatic.com/media/68165d_63a2e7e385824820823f8b66983c213b~mv2.png/v1/fill/w_980,h_529,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_63a2e7e385824820823f8b66983c213b~mv2.png)
![](https://static.wixstatic.com/media/68165d_f6f5ed6472a144d288d1cd33d6177da8~mv2.png/v1/fill/w_980,h_316,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_f6f5ed6472a144d288d1cd33d6177da8~mv2.png)
Mình tạo thêm một rule cấm URL
![](https://static.wixstatic.com/media/68165d_baef8ea70f9345719b624ec149d16cb7~mv2.png/v1/fill/w_980,h_498,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_baef8ea70f9345719b624ec149d16cb7~mv2.png)
![](https://static.wixstatic.com/media/68165d_22c198bee35344259ea39f07042ba380~mv2.png/v1/fill/w_980,h_341,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_22c198bee35344259ea39f07042ba380~mv2.png)
Qua tab Common ACL
Bấm dấu + phần Target Rules List
Những rule nào muốn cấm thì chọn deny, rule cuối cùng sẽ allow
![](https://static.wixstatic.com/media/68165d_32cbac13acc0418299d5fefb31e660e6~mv2.png/v1/fill/w_980,h_456,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_32cbac13acc0418299d5fefb31e660e6~mv2.png)
Hiện thông báo khi user truy cập vào những trang bị chặn
![](https://static.wixstatic.com/media/68165d_3d48408813cf4d9da9a58db4e5742286~mv2.png/v1/fill/w_980,h_405,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_3d48408813cf4d9da9a58db4e5742286~mv2.png)
Qua tab General settings
Check Enable squidGuard
![](https://static.wixstatic.com/media/68165d_8ba592a794914ef4842afc179e9e0fb8~mv2.png/v1/fill/w_980,h_360,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_8ba592a794914ef4842afc179e9e0fb8~mv2.png)
![](https://static.wixstatic.com/media/68165d_6c1463b2573b49a2b914c4f1646cbb8a~mv2.png/v1/fill/w_980,h_299,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_6c1463b2573b49a2b914c4f1646cbb8a~mv2.png)
![](https://static.wixstatic.com/media/68165d_91a52bfea09f4147af3a749fc67c31ff~mv2.png/v1/fill/w_980,h_567,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_91a52bfea09f4147af3a749fc67c31ff~mv2.png)
![](https://static.wixstatic.com/media/68165d_88f90bcef0ac48b0aa165adc93aceca9~mv2.png/v1/fill/w_980,h_353,al_c,q_85,usm_0.66_1.00_0.01,enc_auto/68165d_88f90bcef0ac48b0aa165adc93aceca9~mv2.png)
5. Cài CA cho user
Nếu chúng ta không cài CA thì khi truy cập vào những trang https thì sẽ bào lỗi Certificate Authority
![](https://static.wixstatic.com/media/68165d_3f0f6c770ef1439dbd641b934d783fbd~mv2.png/v1/fill/w_775,h_540,al_c,q_90,enc_auto/68165d_3f0f6c770ef1439dbd641b934d783fbd~mv2.png)
Có hai cách cài CA, chúng ta export CA từ pfSense xuống rồi copy vào máy user cài (cách này không khả thi nếu có nhiều user). Cách thứ hai là deploy CA bằng GPO (mình sẽ hướng dẫn cách này)
Export CA
Vào System > Cert. Manager
![](https://static.wixstatic.com/media/68165d_d218659a6b2c4e2d9a204dd12d211e79~mv2.png/v1/fill/w_980,h_416,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_d218659a6b2c4e2d9a204dd12d211e79~mv2.png)
Chọn CA lúc nãy chúng ta dùng cho Squid Proxy rồi export
![](https://static.wixstatic.com/media/68165d_47c2819907434f7f821c44b5ae0ad60d~mv2.png/v1/fill/w_980,h_477,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_47c2819907434f7f821c44b5ae0ad60d~mv2.png)
Copy CA đã export bỏ vào AD
Login vào AD vào Server Manager > Tools > Group Policy Managerment
![](https://static.wixstatic.com/media/68165d_f8cd264f3da648579d9f734f63e79e6a~mv2.png/v1/fill/w_980,h_427,al_c,q_90,usm_0.66_1.00_0.01,enc_auto/68165d_f8cd264f3da648579d9f734f63e79e6a~mv2.png)
Click chuột phải vào OU (All Computer) chọn Create a GPO in this domain...
![](https://static.wixstatic.com/media/68165d_68fb7987f57545f8a6244c728e2a6d3e~mv2.png/v1/fill/w_787,h_500,al_c,q_90,enc_auto/68165d_68fb7987f57545f8a6244c728e2a6d3e~mv2.png)
Name: đặt tên cho GPO
![](https://static.wixstatic.com/media/68165d_d5d77426c9f146a2ad40bca58f1e76f1~mv2.png/v1/fill/w_765,h_503,al_c,q_90,enc_auto/68165d_d5d77426c9f146a2ad40bca58f1e76f1~mv2.png)
Chuột phải vào tên GPO vừa tạo chọn Edit
![](https://static.wixstatic.com/media/68165d_d1da2b67f91f4f54a79ed5aa26c1847c~mv2.png/v1/fill/w_764,h_507,al_c,q_90,enc_auto/68165d_d1da2b67f91f4f54a79ed5aa26c1847c~mv2.png)
Vào Computer Configuration > Policies > Security Settings > Public Key Policies > Trusted Root Certification Authorities
![](https://static.wixstatic.com/media/68165d_7b27c45d9d2342f5bdce2add9daf4e6e~mv2.png/v1/fill/w_800,h_500,al_c,q_90,enc_auto/68165d_7b27c45d9d2342f5bdce2add9daf4e6e~mv2.png)
Chuột phải chọn Import...
![](https://static.wixstatic.com/media/68165d_498f0ae44d3e45e79ffe0e574736bdaa~mv2.png/v1/fill/w_802,h_487,al_c,q_90,enc_auto/68165d_498f0ae44d3e45e79ffe0e574736bdaa~mv2.png)
Next
![](https://static.wixstatic.com/media/68165d_89184e2c98514a4f87ad56cb2553e7c8~mv2.png/v1/fill/w_552,h_510,al_c,q_85,enc_auto/68165d_89184e2c98514a4f87ad56cb2553e7c8~mv2.png)
Nhấn Browse... chọn đường dẫn lưu CA đã copy từ pfSense xuống
![](https://static.wixstatic.com/media/68165d_7c9f5b0ee8a24a7fa47051bf6424a441~mv2.png/v1/fill/w_554,h_509,al_c,q_85,enc_auto/68165d_7c9f5b0ee8a24a7fa47051bf6424a441~mv2.png)
![](https://static.wixstatic.com/media/68165d_8e62bc076bdf492790d60bf1ce319255~mv2.png/v1/fill/w_551,h_510,al_c,q_85,enc_auto/68165d_8e62bc076bdf492790d60bf1ce319255~mv2.png)
![](https://static.wixstatic.com/media/68165d_9cbc5c0c95474735ab088d4adc5ef125~mv2.png/v1/fill/w_546,h_502,al_c,q_85,enc_auto/68165d_9cbc5c0c95474735ab088d4adc5ef125~mv2.png)
![](https://static.wixstatic.com/media/68165d_1d67da00a3cf4740801d160a3f1ce43d~mv2.png/v1/fill/w_799,h_508,al_c,q_90,enc_auto/68165d_1d67da00a3cf4740801d160a3f1ce43d~mv2.png)
Trên computer áp GPO gõ lệnh gpupdate /force hoặc restart lại máy
Chúng ta vào thử trang facebook.com
Trang facebook đã bị chặn
![](https://static.wixstatic.com/media/68165d_ae6b10a7a70d4eacae9226720c37d0db~mv2.png/v1/fill/w_780,h_537,al_c,q_90,enc_auto/68165d_ae6b10a7a70d4eacae9226720c37d0db~mv2.png)
Vào trang youtube.com
Trang này cũng bị chặn
![](https://static.wixstatic.com/media/68165d_9421a4370be24578bcaf900789c75ef8~mv2.png/v1/fill/w_783,h_538,al_c,q_90,enc_auto/68165d_9421a4370be24578bcaf900789c75ef8~mv2.png)
Thử vào trang hsbc.com.vn
Chúng ta vào được bình thường, nhưng chúng ta thử bấm sang tab Cá nhân trên trang web
![](https://static.wixstatic.com/media/68165d_0225f4a9436b4ffb9197a8ab70d4db48~mv2.png/v1/fill/w_779,h_539,al_c,q_90,enc_auto/68165d_0225f4a9436b4ffb9197a8ab70d4db48~mv2.png)
Đường link sẽ bị chặn
![](https://static.wixstatic.com/media/68165d_f4dfeb5233e6494283cc73d79def48a7~mv2.png/v1/fill/w_783,h_538,al_c,q_90,enc_auto/68165d_f4dfeb5233e6494283cc73d79def48a7~mv2.png)
Tất cả các trang web còn lại chúng ta sẽ vào được bình thường
Comments