Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Want to block shopping sites

    Scheduled Pinned Locked Moved Firewalling
    9 Posts 3 Posters 638 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      thecatsandi
      last edited by

      I am try to block some shopping sites by using the URLs. Funny I know.

      I set up URLs under Firewall, Aliases, URLs.
      I then added a a rule under Firewall, Rules, LAN rejecting the Source as the LAN and the destination addresses or aliases adding the alias I created.

      When I try to go to that site it is not blocked or rejected. it still allows the connection.

      I have read the documentation. It seems I am doing it correctly. However, it still does not work.

      Suggestions?

      1 Reply Last reply Reply Quote 0
      • U
        Uglybrian
        last edited by

        Check to see if your web browser is using Doh.

        T 1 Reply Last reply Reply Quote 0
        • T
          thecatsandi @Uglybrian
          last edited by

          @Uglybrian DoH was on in the browser. I turned it off and restarted the browser. cleared cache. still able to access.
          Windows 11 and Google Chrome.
          Screenshot 2025-02-01 171044.png Screenshot 2025-02-01 170523.png Screenshot 2025-02-01 170435.png

          1 Reply Last reply Reply Quote 0
          • U
            Uglybrian
            last edited by Uglybrian

            Your rule is still being circumvented or the the firewall block list are not complete/incorrect. You can tell by your 0/0B is not showing anything. What are you using as dns and are you blocking any public Doh servers?

            Here is an example of a url table block list:
            Screenshot from 2025-02-01 17-52-19.png

            See the 3KIB...... this rule is working. Its for blocking popular Doh servers on ipv4.

            When i do a DNS look up on qvc I get a different ip address.

            Screenshot from 2025-02-01 18-25-00.png

            T 1 Reply Last reply Reply Quote 0
            • T
              thecatsandi @Uglybrian
              last edited by

              @Uglybrian I was wondering that the QVC IP looking a little off.
              I am using the BIND DNS Server with forwarding to 208.67.220.220 and 208.67.222.222.
              Should I be using DNS resolver or DNS forwarder?

              1 Reply Last reply Reply Quote 0
              • U
                Uglybrian
                last edited by

                I can’t make a suggestion either way, as I do not know the circumstances of your network. Whichever one you prefer and feel comfortable with would be the best one for you. I have no experience with BIND, I use the built-in resolver. No point in referforwarding to a middleman unless you are using some kind of shielding or filtering from them. I just use PF blocker for that. The servers you are forwarding to also do doh.
                doh.opendns.com . It’s a pain to get your clients to follow your rules with doh involved.
                If you resolved, that’s one layer you have to get your clients to behave.
                Next layer would be using the PFS recipes https://docs.netgate.com/pfsense/en/latest/recipes/index.html
                And use the (blocking external client DNS queries). Then find a doh block list that you like on GitHub. Reset your state table and then see how well your shopping block list works

                T 1 Reply Last reply Reply Quote 0
                • T
                  thecatsandi @Uglybrian
                  last edited by

                  @Uglybrian well I have tried every combination of DNS resolver, forwarder, BIND on the netgate, Just can't get the URL filter to work. Diagnostics, DNS lookup works and comes up with a correct response.

                  Time to call it a loss and try something else.

                  GertjanG 1 Reply Last reply Reply Quote 0
                  • GertjanG
                    Gertjan @thecatsandi
                    last edited by

                    @thecatsandi

                    A loss ?
                    If you can use pfBlockerng(-devel), you could uses these :

                    b4a528da-f696-4fa1-8187-6a9088a57b98-image.png

                    I didn't show the entire list, but it is long. Commercial sites are listed in their category.

                    Do not use the XXX list before reading about, as it uses 4++ Mbytes of RAM, (and a big disk).

                    Remember : pfBlockerng is a host name (DNS) or URL filter.

                    No "help me" PM's please. Use the forum, the community will thank you.
                    Edit : and where are the logs ??

                    1 Reply Last reply Reply Quote 0
                    • U
                      Uglybrian
                      last edited by

                      Sorry you couldn’t get things figured out. Is it possible for you to share your current set up.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.