Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Firewalling» How to block facebook in 4 ways
Username:
Password:
 
 

Pages: [1] 2   Go Down
  Print  
Author Topic: How to block facebook in 4 ways  (Read 8766 times)
0 Members and 1 Guest are viewing this topic.
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« on: August 12, 2011, 02:55:42 am »

Hi pFSerians! Good afternoon! Smiley

How-to block facebook in 4 ways:

1st: Get the CIDR of facebook using the domain_whois_tool
                - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png


2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

4th : Install SQUID and block facebook.com there.

I hope im posting it in a right folder discussion..

Hope it help all pFSerians!

Thanks to codemarauder for the additional CIDR Smiley More beers later man Smiley

jigp
« Last Edit: August 12, 2011, 08:51:28 am by jigpe » Logged
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #1 on: August 12, 2011, 04:45:45 am »

Of course you can add some exemption to certain ips. Smiley

Do this: Proto:TCP > Source: Lan IP > Destination: fbips > Port: fbports

jigp
Logged
Nachtfalke
Hero Member
*****
Offline Offline

Posts: 2425


View Profile
« Reply #2 on: August 12, 2011, 01:40:50 pm »

If you are blocking all IPs by firewall rules why do you use squid in addition ?
Logged
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #3 on: August 12, 2011, 06:49:40 pm »

If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.
Logged
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #4 on: August 12, 2011, 07:08:18 pm »

If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.
In my case, i have exemptions so i really need squid.
Logged
syedadi
Full Member
***
Offline Offline

Posts: 127



View Profile WWW
« Reply #5 on: August 12, 2011, 09:30:35 pm »

Hi pFSerians! Good afternoon! Smiley

How-to block facebook in 4 ways:

1st: Get the CIDR of facebook using the domain_whois_tool
                - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png


2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

4th : Install SQUID and block facebook.com there.

I hope im posting it in a right folder discussion..

Hope it help all pFSerians!

Thanks to codemarauder for the additional CIDR Smiley More beers later man Smiley

jigp

Can you give me the link for the CIDR info?
Logged
Metu69salemi
Hero Member
*****
Offline Offline

Posts: 1560


View Profile
« Reply #6 on: August 13, 2011, 12:23:58 am »

Hi pFSerians! Good afternoon! Smiley

How-to block facebook in 4 ways:

1st: Get the CIDR of facebook using the domain_whois_tool
                - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png


2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

4th : Install SQUID and block facebook.com there.

I hope im posting it in a right folder discussion..

Hope it help all pFSerians!

Thanks to codemarauder for the additional CIDR Smiley More beers later man Smiley

jigp

Can you give me the link for the CIDR info?

First post image?!?
Logged
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #7 on: August 13, 2011, 12:40:20 am »

Sure. http://imageshack.us/f/193/cidr.png Smiley
Logged
tommyboy180
Global Moderator
Hero Member
*****
Offline Offline

Posts: 976



View Profile WWW
« Reply #8 on: August 13, 2011, 02:44:23 pm »

That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz
Logged

-Tom Schaefer
SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM
TomSchaefer.org/pfsense
Please support Countryblock | IP-Blocklist | File Browser | Strikeback Here
johnnybe
Hero Member
*****
Offline Offline

Posts: 1149


I've got... a head with wings


View Profile WWW
« Reply #9 on: August 13, 2011, 02:52:53 pm »

That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

Thanks!
Logged

you would not believe the view up here
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #10 on: August 13, 2011, 08:51:13 pm »

@tommyboy180

Thanks! But in my case i have some exemptions. All users are blocked from accessing fb except me. So im creating a rule to allow it to my IP. And if someone would like to access fb, i will just create a rule to allow the user's IP.

jigp
Logged
pcboarders
Jr. Member
**
Offline Offline

Posts: 50


View Profile WWW
« Reply #11 on: August 14, 2011, 05:24:35 pm »

2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

if you do this and have a webserver are you going to prevent it to access the net?
is the port 80 / 443 instead of 80 / 4443
want to try this and see if it interferes


 
Logged

don't fix it, if ain't broken !!!
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #12 on: August 15, 2011, 01:53:23 am »

@pcboarders
I have no concern with webserver so i didn't bother to try this.
I just want to block facebook and give exemptions to those who want to access facebook,

jigp
Logged
paoloromano
Newbie
*
Offline Offline

Posts: 10


View Profile
« Reply #13 on: October 19, 2011, 06:21:53 am »

Masters,

What if you have multiwan and failover, will it conflict with squid?
I would like to block also other sites and facebook but might encounter unwanted conflict with my multiwan and failover.
advise please, thanks!
Logged
jigpe
Sr. Member
****
Offline Offline

Posts: 371


View Profile
« Reply #14 on: October 23, 2011, 12:58:11 am »

Same rule in MultiWan. Use the firewall rule and select the WAN or whichever is your WAN1 and WAN2.
Logged
Pages: [1] 2   Go Up
  Print  
 
Jump to:  

 

Page created in 0.033 seconds with 19 queries.