Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  General Category» General Discussion» https://www.facebook .com is working even i blocked facebook by proxy filtering
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: https://www.facebook .com is working even i blocked facebook by proxy filtering  (Read 15799 times)
0 Members and 1 Guest are viewing this topic.
aby
Newbie
*
Offline Offline

Posts: 14


View Profile
« on: November 10, 2011, 06:41:10 am »

https://www.facebook .com is working even i blocked facebook by proxy filtering.what should i do to block this??/
Logged
dhatz
Hero Member
*****
Offline Offline

Posts: 931


View Profile
« Reply #1 on: November 10, 2011, 08:16:00 am »

Put the IP ranges of Facebook e.g.

66.220.144.0/21   Facebook, Inc.
66.220.152.0/21   Facebook, Inc.
69.63.176.0/21   Facebook, Inc.
69.63.184.0/21   Facebook, Inc.
69.171.224.0/20   Facebook, Inc.
69.171.239.0/24   Facebook, Inc.
69.171.240.0/20   Facebook, Inc.

in a pfsense Alias e.g. FBNets, and then add a firewall rule to block traffic to FBNets for ports 80 & 443.
Logged
Cry Havok
Global Moderator
Hero Member
*****
Offline Offline

Posts: 2772


Backup: n. What you should have done yesterday.


View Profile
« Reply #2 on: November 10, 2011, 02:22:43 pm »

Are you forcing people to use the proxy? How have you blocked Facebook?
Logged

If you're planning on PMing me to ask me to look at a thread, or for individual support, don't.
Metu69salemi
Hero Member
*****
Offline Offline

Posts: 1560


View Profile
« Reply #3 on: November 11, 2011, 03:40:04 pm »

You can't proxy https trafic so you have to use aliases as dhatz sayed
Logged
Cry Havok
Global Moderator
Hero Member
*****
Offline Offline

Posts: 2772


Backup: n. What you should have done yesterday.


View Profile
« Reply #4 on: November 11, 2011, 04:24:25 pm »

You can proxy HTTPS traffic (using the CONNECT method), but the proxy only gets to know the hostname being connected to. This means that, if correctly configured, you can block HTTPS traffic.
Logged

If you're planning on PMing me to ask me to look at a thread, or for individual support, don't.
Metu69salemi
Hero Member
*****
Offline Offline

Posts: 1560


View Profile
« Reply #5 on: November 12, 2011, 02:41:11 pm »

You can proxy HTTPS traffic (using the CONNECT method), but the proxy only gets to know the hostname being connected to. This means that, if correctly configured, you can block HTTPS traffic.

Ok this was new to me, so i'll check this little further when i got some time
Logged
Cry Havok
Global Moderator
Hero Member
*****
Offline Offline

Posts: 2772


Backup: n. What you should have done yesterday.


View Profile
« Reply #6 on: November 12, 2011, 03:51:19 pm »

If you think about it, how else could you configure a proxy for use in your browser (check it's settings)?
Logged

If you're planning on PMing me to ask me to look at a thread, or for individual support, don't.
aby
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #7 on: November 14, 2011, 08:09:40 am »

can any one tell me how to make this stuff using aliases?Huh
Logged
fluca1978
Full Member
***
Offline Offline

Posts: 133


View Profile
« Reply #8 on: November 14, 2011, 11:52:40 am »

Doing aliases you have to create a new alias, of type net, add all the hosts and their ips and then place a rule in the LAN to block traffic to that alias.
This is useful also to avoid people being blocked from the proxy but being able to use the chat or other applications.
Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.028 seconds with 19 queries.