Allow facebook messenger application in phone and laptop.
-
Hi Master,
I already blocked Facebook but I can't login to messenger. I already allowed this dns in whitelist;
.apps.facebook.com
.orcart.facebook.com
.fbstatic-a.akamaihd.net
.api.facebook.com
.orcart.facebook.com
.fbexternal-a.akamaihd.net
.fbcdn-profile-a.akamaihd.net
.graph.facebook.com
.static.xx.fbcdn.net # 123
.scontent.xx.fbcdn.net # CNAME for (static.xx.fbcdn.net)
.edge-mqtt.facebook.com # mssg
.mqtt.c10r.facebook.com # CNAME for (edge-mqtt.facebook.combut still the problem persist. Seeking your help.
-
@romarinas confused. You don’t want .Facebook.com but you do want to use messenger app?
If you want to make an exception for a single machine on your LAN then you can use python mode. That IP will be able to be sinkholed tho -
@michmoor said in Allow facebook messenger application in phone and laptop.:
If you want to make an exception for a single machine on your LAN then you can use python mode. That IP will be able to be sinkholed tho
That 'was' the good advise.
Then this popped up : Problem with Python Group Policy - Cached DomainsThe device member of the Policy list will bypass pfBlockerng.
The requested host name will be resolved.
This host name will be stored in the unbound cache ....
And now its available for all other, non policy listed devices also, as pfBlockerng can stop the resolving, not serving from the unbound DNS cache.@romarinas said in Allow facebook messenger application in phone and laptop.:
I already blocked Facebook but I can't login to messenger. I already allowed this dns in whitelist;
Don't stop there !
You have the IP of the device on which messenger is running.
Use pfSense : packet capturing, and get these DNS (and other ?) packets) and see what it asking for.
It didn't get it, so no ligin.Btw : probably it's asking for *.facebook.com as "blocking facebook" but permitting "messenger" is like asking for apples, but you've cut down the apple tree ^^
-
@Gertjan said in Allow facebook messenger application in phone and laptop.:
And now its available for all other, non policy listed devices also, as pfBlockerng can stop the resolving, not serving from the unbound DNS cache.
I had no idea about this. Interesting......
-
@Gertjan Without modifying the TTL like you did it makes python group whitelisting kinda pointless.....