Project

General

Profile

Actions

Bug #17101

open
FA MM

Network access from pfSense ignores proxy configuration

Bug #17101: Network access from pfSense ignores proxy configuration

Added by Florian Apolloner about 18 hours ago. Updated about 3 hours ago.

Status:
Feedback
Priority:
Normal
Assignee:
Category:
Nexus
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Release Notes:
Default
Affected Plus Version:
26.07
Affected Architecture:

Description

Hi there,

after upgrading to pfSense+ 26.07 we see the following IP getting blocked in our (upstream) firewall logs: 208.123.73.87 (port 443). The access to this IP originates directly from the pfSense boxes and seems to ignore the configured HTTP-Proxy. So something something on pfSense now tries to access services.netgate.com and ignores the proxy -- is that on purpose or an oversight?

Additionally pfSense+ 26.07 tries to access:

http://169.254.169.254/latest/api/token
http://169.254.169.254/metadata/attested/document?
http://metadata/computeMetadata/v1/instance/service-accounts/default/identity?

via the proxy, which is probably AWS and GCP cloud discovery. Is there any way to turn this off?

MM Updated by Marcos M about 3 hours ago Actions #1

  • Category changed from Unknown to Nexus
  • Status changed from New to Feedback
  • Assignee set to Marcos M
  • Target version set to 26.10
  • % Done changed from 0 to 100

The extra cloud API requests is already fixed in the latest Nexus version (26.07_2). Proxy support has been added to 26.10.

Actions

Also available in: Atom