Community discussions

MikroTik App
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Web Proxy

Sun Apr 02, 2023 2:21 am

Hi,
How to make Web Proxy to work?
I have enabled it, as well created redirect rule to redirect to port 8080.
As i try to add proxy in browser, it doesn't work either (I'm getting timeout), so something with proxy settings, not the NAT rule. Pretty much i didn't do any configuration, just enabled proxy itself.
Just want visited sites to be visible in logs.
 
User avatar
jvanhambelgium
Forum Guru
Forum Guru
Posts: 1114
Joined: Thu Jul 14, 2016 9:29 pm
Location: Belgium

Re: Web Proxy

Sun Apr 02, 2023 10:10 am

Mikrotik should remove this "web proxy" module all together from RouterOS.
It is only for HTTP and does not support HTTPS
Most Internet traffic these days is HTTPS.

To put in some numbers (from Netflow).
The last 24h my router processed about 89.000 flows on port 443 , while "port 80" was about 2.000
So that puts things in perspective, only 2% traffic on destination port "80" (which might then probably be non-encrypted)
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: Web Proxy

Sun Apr 02, 2023 10:56 am

Is there another way to log visited sites?
 
User avatar
jvanhambelgium
Forum Guru
Forum Guru
Posts: 1114
Joined: Thu Jul 14, 2016 9:29 pm
Location: Belgium

Re: Web Proxy

Sun Apr 02, 2023 11:15 am

Is there another way to log visited sites?
You could always go down the DNS path (analyse resolved entries), but that will not give you granularity *what* has been exactly visited.
And off course not all DNS-lookups lead to visited "websites" so no real 100% match for your requirements.

If you run certain Mikrotik models, you could investigate if some container exist that you could use for this "web proxy" function (eg Squid) and then direct traffic to the container.
But performance wise ... dunno .. depends on the expected amount of users.
It is going to be a complex setup...
It is clear that is increasingly difficult to place yourself into the path of "enduser" <> "website" for control/policy/filter reasons.

Do you control all endpoints ? Is this a corporate/enterprise environment or some BYOD-type of deployement ?
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: Web Proxy

Mon Apr 10, 2023 1:54 am

It is actually my home network. Just want to see visited sites.
 
reinerotto
Long time Member
Long time Member
Posts: 523
Joined: Thu Dec 04, 2008 2:35 am

Re: Web Proxy

Mon Apr 10, 2023 8:53 am

Then you should have a look at squid proxy. Not to run on MT, AFAIK, so you will need a small LINUX host.
However, steep learning curve, for what you want to achieve. But doable.

Who is online

Users browsing this forum: voytecky and 25 guests