Project

General

Profile

Actions

Bug #17101

open
FA MM

Network access from pfSense ignores proxy configuration

Bug #17101: Network access from pfSense ignores proxy configuration

Added by Florian Apolloner about 19 hours ago. Updated about 4 hours ago.

Status:
Feedback
Priority:
Normal
Assignee:
Category:
Nexus
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Release Notes:
Default
Affected Plus Version:
26.07
Affected Architecture:

Description

Hi there,

after upgrading to pfSense+ 26.07 we see the following IP getting blocked in our (upstream) firewall logs: 208.123.73.87 (port 443). The access to this IP originates directly from the pfSense boxes and seems to ignore the configured HTTP-Proxy. So something something on pfSense now tries to access services.netgate.com and ignores the proxy -- is that on purpose or an oversight?

Additionally pfSense+ 26.07 tries to access:

http://169.254.169.254/latest/api/token
http://169.254.169.254/metadata/attested/document?
http://metadata/computeMetadata/v1/instance/service-accounts/default/identity?

via the proxy, which is probably AWS and GCP cloud discovery. Is there any way to turn this off?

Actions

Also available in: Atom