Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How can we block specific sites? SOLVED. Thanks.

    Scheduled Pinned Locked Moved pfSense Packages
    23 Posts 5 Posters 27.0k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Cry HavokC
      Cry Havok
      last edited by

      Are you using Squid?  Firewall rules for the LAN interface don't apply to Squid's outgoing traffic.

      I'd suggest you look to using Squid and Squidguard (and blocking port 80) or use OpenDNS.

      1 Reply Last reply Reply Quote 0
      • O
        odods77
        last edited by

        @Cry:

        Are you using Squid?  Firewall rules for the LAN interface don't apply to Squid's outgoing traffic.

        I'd suggest you look to using Squid and Squidguard (and blocking port 80) or use OpenDNS.

        Here is the setup i want in my network:

        Fileserver
                                                          v
        internet –> DNS(server 2003) --> switch --> LAN1             
                                                                -->  pfSense --------> switch --> LAN2
                                                          ^                                      ^
                                                          l                                        l
                                          active directory (server 2003)                  l
                                                                                    child domain (server2003 AD for LAN2)

        Where can i insert the OpenDNS/squid?  i want to secure my LAN2.  I don't want it to access to some websites.

        1 Reply Last reply Reply Quote 0
        • Cry HavokC
          Cry Havok
          last edited by

          You install the Squid package on pfSense.

          You would use OpenDNS as the DNS forwarder for your entire network, so at your primary DNS server.

          1 Reply Last reply Reply Quote 0
          • O
            odods77
            last edited by

            @Cry:

            You install the Squid package on pfSense.

            You would use OpenDNS as the DNS forwarder for your entire network, so at your primary DNS server.

            Im done installing squid in pfsense package. I don't know were to blocked a site.
            Please help me…

            Thanks....

            1 Reply Last reply Reply Quote 0
            • Cry HavokC
              Cry Havok
              last edited by

              Now install SquidGuard (as I'd previously said).

              1 Reply Last reply Reply Quote 0
              • P
                Perry
                last edited by

                http://doc.pfsense.org/index.php/Setup_Squid_as_a_Transparent_Proxy
                http://diskatel.narod.ru/sgquick.htm
                http://diskatel.narod.ru/pfSense/doc/squidGuard/squidGuardQuick.htm

                /Perry
                doc.pfsense.org

                1 Reply Last reply Reply Quote 0
                • O
                  odods77
                  last edited by

                  In Proxy Content Filter SquidGuard –> General Settings.

                  What Blacklist URL am i gona type? I'm confused.

                  Thanks...

                  1 Reply Last reply Reply Quote 0
                  • C
                    ColdFusion
                    last edited by

                    Under Destinations tab hit the + key and name Blacklist.
                    Under domain fields add the site you want to Blacklist…......example youporn.com...do not add the http://www.

                    urls list..just what it says.

                    Redirect field...add error code or redirect to another website.

                    Read the previous links as stated above to the quick guides.

                    1 Reply Last reply Reply Quote 0
                    • O
                      odods77
                      last edited by

                      im done following the instructions from those materials.  Still in won't block sites.  What am i gonna do? Please help.
                      Thanks…

                      1 Reply Last reply Reply Quote 0
                      • Cry HavokC
                        Cry Havok
                        last edited by

                        You have configured clients to use the proxy?

                        1 Reply Last reply Reply Quote 0
                        • O
                          odods77
                          last edited by

                          @Cry:

                          You have configured clients to use the proxy?

                          i didnt configure proxy in clients side.  Do we need to configure it in to proxy server, the ip address and port of the pfsense?  Am I correct?

                          1 Reply Last reply Reply Quote 0
                          • Cry HavokC
                            Cry Havok
                            last edited by

                            Yes.  The port if you haven't changed it is 3128.

                            Don't forget to create a firewall rule to block 80/TCP outbound to force people to use the proxy.

                            1 Reply Last reply Reply Quote 0
                            • O
                              odods77
                              last edited by

                              Do i need to configure the LAN interface as Bridge with WAN?

                              1 Reply Last reply Reply Quote 0
                              • Cry HavokC
                                Cry Havok
                                last edited by

                                What gave you that impression?  Nobody mentioned bridging in this thread.

                                No - don't bridge unless you know what you're doing.

                                1 Reply Last reply Reply Quote 0
                                • O
                                  odods77
                                  last edited by

                                  @Cry:

                                  What gave you that impression?  Nobody mentioned bridging in this thread.

                                  No - don't bridge unless you know what you're doing.

                                  Sorry i just saw it.  okey i'll not enable bridge.
                                  I'll try….
                                  thanks.

                                  1 Reply Last reply Reply Quote 0
                                  • O
                                    odods77
                                    last edited by

                                    I'm done setting up client workstation proxy in internet browsers. In setting up proxy, it should be the LAN ip address of the pfsense and port is 3128?  Am i right?

                                    Still it won't work.  :(

                                    Did i miss some steps?

                                    Thanks…

                                    1 Reply Last reply Reply Quote 0
                                    • Cry HavokC
                                      Cry Havok
                                      last edited by

                                      A good starting point would be what you mean when you say "it won't work".  Are you still able to access the sites you're trying to block, are you failing to reach the Internet at all, what?  We don't have a crystal ball or mind reading abilities.

                                      1 Reply Last reply Reply Quote 0
                                      • O
                                        odods77
                                        last edited by

                                        i'm sorry.  i mean, the squidguard isn't working.  It won't blocked site. :(

                                        1 Reply Last reply Reply Quote 0
                                        • O
                                          odods77
                                          last edited by

                                          THANK YOU SO MUCH GUYS! :)

                                          It's working already.

                                          Thanks…........

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.