Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    The game needs a blocklist.

    Scheduled Pinned Locked Moved pfBlockerNG
    16 Posts 8 Posters 1.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • AndyRHA
      AndyRH
      last edited by

      Not a direct answer to your question.
      Is there a company policy against using company equipment to play games? Where I work this is a short path to termination.
      Is there a reason most users need more the ports 80 & 443? My company blocks all but 80 & 443 unless there is an approved reason to allow another port.

      o||||o
      7100-1u

      1 Reply Last reply Reply Quote 0
      • M
        mickilangelo
        last edited by

        This post is deleted!
        1 Reply Last reply Reply Quote 0
        • F
          FrostElara
          last edited by

          How can we block employees from playing games like Zula, PUBG, and Valorant during work hours, and do these games offer any built-in block or restriction features?

          M S E 4 Replies Last reply Reply Quote 0
          • JonathanLeeJ
            JonathanLee
            last edited by JonathanLee

            DoH causes lots of issues. Squid is still useable and you can lock down by https get requests and forget about the dns stuff. It’s a step before dns resolves. Also it has times for ACLs to be set so working hours could block the requests etc. That package still works has some small bugs in the new pfSense version I think they are working on it. I know it’s not a security issue anymore as it was fully updated upstream to fix all the concerns, again the package needs to be fine tuned to address the changes.

            Make sure to upvote

            1 Reply Last reply Reply Quote 0
            • M
              michmoor LAYER 8 Rebel Alliance @FrostElara
              last edited by

              @FrostElara endpoint content filtering. There are many tools out there (Zorus, Umbrella, DNSfilter)
              Pfsense can not do any content filtering and Squid is not at all recommended for this solution.

              Firewall: NetGate,Palo Alto-VM,Juniper SRX
              Routing: Juniper, Arista, Cisco
              Switching: Juniper, Arista, Cisco
              Wireless: Unifi, Aruba IAP
              JNCIP,CCNP Enterprise

              1 Reply Last reply Reply Quote 0
              • JonathanLeeJ
                JonathanLee
                last edited by JonathanLee

                Squid could do it, all he would need is the http get request and have a block or that url request. Done. Again I agree Squids not some plug and play package you have to be a level 100 wizard to use it.

                What about Snort? It can do AppID detect but you need to create a detect file for it. I use snort to do blocks by content.

                If you can run inline mode this might work…

                Check this out.. but the database would need the game in it
                https://forum.netgate.com/topic/183210/guide-snort-s-appid-custom-rules-quick-guide-to-blocking-example-shows-openai-chatgpt-or-itunes

                Make sure to upvote

                M 1 Reply Last reply Reply Quote 0
                • S
                  smolka_J @FrostElara
                  last edited by

                  @FrostElara As long as you're enforcing pfSense as your local DNS with NAT and have DoH/DoT/DoQ blocked/reject on LAN side, you can use OpenDNS/Cisco Umbrella for your upstream DNS/TLS, they have a game filter category and many other related time-waster categories that can help improve productivity. UT1 has a game category also in the built-in DNSBL Category lists but its a little bit more region based to a degree tailored around where its being maintained, Cisco/OpenDNS usually covers a wider spectrum being developed moreso worldwide

                  1 Reply Last reply Reply Quote 0
                  • M
                    michmoor LAYER 8 Rebel Alliance @JonathanLee
                    last edited by

                    @JonathanLee
                    Ultimately what the OP and many others are asking for is content filtering categorization.
                    Folks want to click a box that says 'games' and all game sites and services are blocked.
                    In 2024, Squid cant do this. UT1 is not to be used in any commercial sense so that leaves paid options which are typically very good at filtering because that's what you are paying for.
                    I would take Cisco Umbrella Free over a Squid implementation. That takes out the certificate management and broken websites and use purely domain based control which is optimal.

                    Firewall: NetGate,Palo Alto-VM,Juniper SRX
                    Routing: Juniper, Arista, Cisco
                    Switching: Juniper, Arista, Cisco
                    Wireless: Unifi, Aruba IAP
                    JNCIP,CCNP Enterprise

                    JonathanLeeJ S 2 Replies Last reply Reply Quote 0
                    • JonathanLeeJ
                      JonathanLee @michmoor
                      last edited by

                      @michmoor Alot of people do not want to put that amount of effort into creating customized lists like I have, it takes a while. But it does work. Again your right they want that plug and play radio button option.

                      Make sure to upvote

                      1 Reply Last reply Reply Quote 0
                      • S
                        smolka_J @michmoor
                        last edited by

                        @michmoor Granted UT1 Blacklist is not to be sold as a commercial product itself to gain a profit from, under its "Creative Commons Contract" it is allowed to be shared and used for any purpose, even for commercial applications and use scenarios. The one restriction users of UT1 will notice just like the restrictions Shallalist imposed for "free" users is the update frequency allowed, if you set it to daily updates like most companies usually will desire and configure for all feeds/updates, your IP will get blacklisted temporarily to prevent abusers from updating too often, Shallalist used to state that any IP found to be updating any more often than once per month will automatically get flagged to be blacklisted temporarily until the next allowed cycle. I shoot for more of a trifecta effect for "parental restrictions" using all three collaborations of category filters: OpenDNS/Cisco-Umbrella for upstream DNS, UT1's blacklist for what it offers to add, and use the last known Shallalist.tar.gz I saved from WayBackMachine web archives uploaded to pfSense as a static file after I modified it to about 85Mb adding to existing categories and added additional categories to for private use.
                        Shallalist is the one that is limited as far as "commercial" use is concerned as the maintainer can no longer be contacted presently for reseller licenses and fees or to be able to register for company/government/school use by requesting their "usage contract" to sign

                        JonathanLeeJ 1 Reply Last reply Reply Quote 1
                        • S
                          smolka_J @FrostElara
                          last edited by

                          @FrostElara In addition to the category filters available, it may help adding a few lines of Regex for domain name filtering of specific keywords like:

                          ((^)|(.))game.
                          ((^)|(.))casino.
                          ((^)|(.))play.
                          ((^)|(.))pubg.
                          ((^)|(.))steam.
                          ((^)|(.))youtu.
                          ((^)|(.))ytimg.
                          ((^)|(.))ytstatic.
                          ((^)|(.))googlevideo.
                          ((^)|(.))proxy.
                          ((^)|(.))vpn.
                          ((^)|(.))doh.
                          

                          Also, since most employees whom already like to waste company time/break company rules will try to continue to do so then by attempting to bypass your company firewall, it may be worth also to enable all category and feed lists for proxies, VPNs, DoH, URL shorteners, and redirectors to seal off all common-known back-doors that rule-breakers will attempt and maybe OISDs NSFW list too for other time-wasters. Hagezi has good lists too for DoH and proxies.

                          1 Reply Last reply Reply Quote 0
                          • JonathanLeeJ
                            JonathanLee @smolka_J
                            last edited by

                            @smolka_J I did the same thing a while back, saved the shallalist. I really think they had great blacklists.

                            Make sure to upvote

                            1 Reply Last reply Reply Quote 0
                            • E
                              enesas @FrostElara
                              last edited by

                              @FrostElara Activate the TLD in pfblockerng and add it to the blocklist. pubgmobile.com I solved it by adding the address. Of course, it works by blocking external DNSs.

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.