Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block layer 7 on websites

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 7 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by

      Snort and the openappid streaming media rule.

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 0
      • D
        dma11
        last edited by

        Thanks @NogBadTheBad

        Do you know if there is any documentation available on how to create this rule?

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by

          The rules are there, i think you need to select it then unselect everything you want to pass in the actual rule.

          Then enable blocking in the interface.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by NogBadTheBad

            0_1549370926021_Screenshot 2019-02-05 at 12.43.43.png

            0_1549370930780_Screenshot 2019-02-05 at 12.44.16.png

            0_1549370942821_Screenshot 2019-02-05 at 12.44.57.png

            0_1549370948103_Screenshot 2019-02-05 at 12.45.13.png

            0_1549370952875_Screenshot 2019-02-05 at 12.45.51.png

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            A 1 Reply Last reply Reply Quote 0
            • D
              dma11
              last edited by

              @NogBadTheBad

              Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

              Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

              bmeeksB 1 Reply Last reply Reply Quote 0
              • bmeeksB
                bmeeks @dma11
                last edited by bmeeks

                @dma11 said in Block layer 7 on websites:

                @NogBadTheBad

                Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                S 1 Reply Last reply Reply Quote 0
                • S
                  susamlicubuk @bmeeks
                  last edited by

                  @bmeeks said in Block layer 7 on websites:

                  @dma11 said in Block layer 7 on websites:

                  @NogBadTheBad

                  Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                  Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                  Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                  hi bmeeks;

                  Can you share a sample packet listening and blocking path detail. chrome, opera, firewfox vpn apps etc. (not the rule listed, the new custom rule)
                  thanks.

                  bmeeksB 1 Reply Last reply Reply Quote 0
                  • bmeeksB
                    bmeeks @susamlicubuk
                    last edited by

                    @susamlicubuk said in Block layer 7 on websites:

                    @bmeeks said in Block layer 7 on websites:

                    @dma11 said in Block layer 7 on websites:

                    @NogBadTheBad

                    Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                    Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                    Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                    hi bmeeks;

                    Can you share a sample packet listening and blocking path detail. chrome, opera, firewfox vpn apps etc. (not the rule listed, the new custom rule)
                    thanks.

                    Sorry, I am not a rule writer. Never bothered to learn the syntax in detail. You should be able to find some examples with a Google search, and then maybe build off the rules included in the OpenAppID package with pfSense.

                    1 Reply Last reply Reply Quote 0
                    • A
                      ammar177 @NogBadTheBad
                      last edited by

                      @NogBadTheBad Does this also block all the video streaming apps installed on smart phones (etc. tiktok, likee, snackvideo and other like these)?

                      GertjanG 1 Reply Last reply Reply Quote 0
                      • GertjanG
                        Gertjan @ammar177
                        last edited by Gertjan

                        @ammar177

                        You're waking up forum threads more then 4 years old ...
                        Much has changed since then.

                        No "help me" PM's please. Use the forum, the community will thank you.
                        Edit : and where are the logs ??

                        A 1 Reply Last reply Reply Quote 0
                        • A
                          ammar177 @Gertjan
                          last edited by

                          @Gertjan you are right. please guide how can I block streaming apps installed on smart phones using pgblockerNG or snort.

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            michmoor LAYER 8 Rebel Alliance @ammar177
                            last edited by

                            @ammar177 Using pfBlockerNG. Create an alias of ASNs you want to block (netflix,hulu,peacock,etc..). Apply that alias to the IPs that should be blocked.
                            There isnt a clean way to block streaming sites on pfsense. Snort openapp.id rules have not been updated in some time (over 5 years) so they will not account for the latest streaming sites. You will need to write your own rules for that.

                            If you are looking to block streaming media sites on a phone its probably best to point that client to openDNS or NextDNS where you can do category-based blocking and not use pfSense for DNS. That's the best recommendation i can give.

                            Firewall: NetGate,Palo Alto-VM,Juniper SRX
                            Routing: Juniper, Arista, Cisco
                            Switching: Juniper, Arista, Cisco
                            Wireless: Unifi, Aruba IAP
                            JNCIP,CCNP Enterprise

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.