Can some one guide me how to make rule for mime type in pfsense, i had gon through many docs, but all r on SQUID
You don't. You use the MIME blocking for Squid installed as a package in pfSense. However, this will block normal browsers from viewing youtube as well. That's that. No buts.
Short of actually sniffing traffic and writing your own layer7 patterns to block YTD, you're out of luck.
Even so, I believe that YTD, like most download software can spoof normal browser traffic so you would be out of luck there as well.What you have isn't a network policy problem. It's a system policy problem.
If you want to stop YTD, get on the systems and actually amend the GPs to prevent it from installing or running to begin with. Alternatively, use a software firewall on the system that simply drops traffic originating from the YTD software.
You use the MIME blocking for Squid installed as a package in pfSense. However, this will block normal browsers from viewing youtube as well.
What u said is also the good method to block some other websites like onlinegames, porn websites. But how can i do that in pfsense.