In squidGuard.conf.j2 the per-rule local_block_url branch (else case) writes '!ocal-block-url-' instead of '!local-block-url-'. It is only taken when local-block-url is
the first ACL entry of a rule.
set service webproxy url-filtering squidguard source-group sg1 address 192.0.2.0/24
set service webproxy url-filtering squidguard rule 10 source-group sg1
set service webproxy url-filtering squidguard rule 10 local-block-url example.org/bad
commit
Generated: pass !ocal-block-url-10 any
The commit succeeds silently and the URL is not blocked (squidGuard answers ERR, no redirect).
With a local-block entry before it, the line is correct and the URL is redirected (302).
Fix: '!local-block-url-' + rule