Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block facebook in 4 ways

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 11 Posters 24.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jigpe
      last edited by

      Of course you can add some exemption to certain ips. :)

      Do this: Proto:TCP > Source: Lan IP > Destination: fbips > Port: fbports

      jigp

      1 Reply Last reply Reply Quote 0
      • N Offline
        Nachtfalke
        last edited by

        If you are blocking all IPs by firewall rules why do you use squid in addition ?

        1 Reply Last reply Reply Quote 0
        • J Offline
          jigpe
          last edited by

          If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.

          1 Reply Last reply Reply Quote 0
          • J Offline
            jigpe
            last edited by

            @jigpe:

            If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.
            In my case, i have exemptions so i really need squid.

            1 Reply Last reply Reply Quote 0
            • S Offline
              syedadi
              last edited by

              @jigpe:

              Hi pFSerians! Good afternoon! :)

              How-to block facebook in 4 ways:

              1st: Get the CIDR of facebook using the domain_whois_tool
                             - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

              2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

              3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

              4th : Install SQUID and block facebook.com there.

              I hope im posting it in a right folder discussion..

              Hope it help all pFSerians!

              Thanks to codemarauder for the additional CIDR :) More beers later man :)

              jigp

              Can you give me the link for the CIDR info?

              1 Reply Last reply Reply Quote 0
              • M Offline
                Metu69salemi
                last edited by

                @syedadi:

                @jigpe:

                Hi pFSerians! Good afternoon! :)

                How-to block facebook in 4 ways:

                1st: Get the CIDR of facebook using the domain_whois_tool
                               - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

                2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

                4th : Install SQUID and block facebook.com there.

                I hope im posting it in a right folder discussion..

                Hope it help all pFSerians!

                Thanks to codemarauder for the additional CIDR :) More beers later man :)

                jigp

                Can you give me the link for the CIDR info?

                First post image?!?

                1 Reply Last reply Reply Quote 0
                • J Offline
                  jigpe
                  last edited by

                  Sure. http://imageshack.us/f/193/cidr.png :)

                  1 Reply Last reply Reply Quote 0
                  • T Offline
                    tommyboy180
                    last edited by

                    That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                    -Tom Schaefer
                    SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                    Please support pfBlocker | File Browser | Strikeback

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      johnnybe
                      last edited by

                      @tommyboy180:

                      That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                      Thanks!

                      you would not believe the view up here

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        jigpe
                        last edited by

                        @tommyboy180

                        Thanks! But in my case i have some exemptions. All users are blocked from accessing fb except me. So im creating a rule to allow it to my IP. And if someone would like to access fb, i will just create a rule to allow the user's IP.

                        jigp

                        1 Reply Last reply Reply Quote 0
                        • P Offline
                          pcbosrders
                          last edited by

                          2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                          if you do this and have a webserver are you going to prevent it to access the net?
                          is the port 80 / 443 instead of 80 / 4443
                          want to try this and see if it interferes

                          don't fix it, if ain't broken !!!

                          1 Reply Last reply Reply Quote 0
                          • J Offline
                            jigpe
                            last edited by

                            @pcboarders
                            I have no concern with webserver so i didn't bother to try this.
                            I just want to block facebook and give exemptions to those who want to access facebook,

                            jigp

                            1 Reply Last reply Reply Quote 0
                            • P Offline
                              paoloromano
                              last edited by

                              Masters,

                              What if you have multiwan and failover, will it conflict with squid?
                              I would like to block also other sites and facebook but might encounter unwanted conflict with my multiwan and failover.
                              advise please, thanks!

                              1 Reply Last reply Reply Quote 0
                              • J Offline
                                jigpe
                                last edited by

                                Same rule in MultiWan. Use the firewall rule and select the WAN or whichever is your WAN1 and WAN2.

                                1 Reply Last reply Reply Quote 0
                                • K Offline
                                  kornelson
                                  last edited by

                                  Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                  1 Reply Last reply Reply Quote 0
                                  • M Offline
                                    Metu69salemi
                                    last edited by

                                    @kornelson:

                                    Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                    How do you block http now? Answer depends greatly your blocking method

                                    1 Reply Last reply Reply Quote 0
                                    • N Offline
                                      NOYB
                                      last edited by

                                      Add Facebook CIDR to bogons data.  :o

                                      1 Reply Last reply Reply Quote 0
                                      • J Offline
                                        jigpe
                                        last edited by

                                        Latest IPs of facebook:

                                        IPV4 IPs:
                                        route:      204.15.20.0/22
                                        route:      69.63.176.0/20
                                        route:      66.220.144.0/20
                                        route:      66.220.144.0/21
                                        route:      69.63.184.0/21
                                        route:      69.63.176.0/21
                                        route:      74.119.76.0/22
                                        route:      69.171.255.0/24
                                        route:      173.252.64.0/18
                                        route:      69.171.224.0/19
                                        route:      69.171.224.0/20
                                        route:      103.4.96.0/22
                                        route:      69.63.176.0/24
                                        route:      173.252.64.0/19
                                        route:      173.252.70.0/24
                                        route:      31.13.64.0/18
                                        route:      31.13.24.0/21
                                        route:      66.220.152.0/21
                                        route:      66.220.159.0/24
                                        route:      69.171.239.0/24
                                        route:      69.171.240.0/20
                                        route:      31.13.64.0/19
                                        route:      31.13.64.0/24
                                        route:      31.13.65.0/24
                                        route:      31.13.67.0/24
                                        route:      31.13.68.0/24
                                        route:      31.13.69.0/24
                                        route:      31.13.70.0/24
                                        route:      31.13.71.0/24
                                        route:      31.13.72.0/24
                                        route:      31.13.73.0/24
                                        route:      31.13.74.0/24
                                        route:      31.13.75.0/24
                                        route:      31.13.76.0/24
                                        route:      31.13.77.0/24
                                        route:      31.13.96.0/19
                                        route:      31.13.66.0/24
                                        route:      173.252.96.0/19
                                        route:      69.63.178.0/24
                                        route:      31.13.78.0/24
                                        route:      31.13.79.0/24
                                        route:      31.13.80.0/24
                                        route:      31.13.82.0/24
                                        route:      31.13.83.0/24
                                        route:      31.13.84.0/24
                                        route:      31.13.85.0/24
                                        route:      31.13.86.0/24
                                        route:      31.13.87.0/24
                                        route:      31.13.88.0/24
                                        route:      31.13.89.0/24
                                        route:      31.13.90.0/24
                                        route:      31.13.91.0/24
                                        route:      31.13.92.0/24
                                        route:      31.13.93.0/24
                                        route:      31.13.94.0/24
                                        route:      31.13.95.0/24
                                        route:      69.171.253.0/24
                                        route:      69.63.186.0/24
                                        route:      204.15.20.0/22
                                        route:      69.63.176.0/20
                                        route:      69.63.176.0/21
                                        route:      69.63.184.0/21
                                        route:      66.220.144.0/20
                                        route:          69.63.176.0/20

                                        IPV6 IPs
                                        route6:    2620:0:1c00::/40
                                        route6:    2a03:2880::/32
                                        route6:    2401:DB00::/32
                                        route6:    2a03:2880:fffe::/48
                                        route6:    2a03:2880:ffff::/48
                                        route6:    2620:0:1cff::/48

                                        Hope this help.
                                        jigp

                                        1 Reply Last reply Reply Quote 0
                                        • C Offline
                                          CrimsonMoon79
                                          last edited by

                                          Yes, this definitely helps a lot, thank you very much.

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.