Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block facebook in 4 ways

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 11 Posters 24.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • N Offline
      Nachtfalke
      last edited by

      If you are blocking all IPs by firewall rules why do you use squid in addition ?

      1 Reply Last reply Reply Quote 0
      • J Offline
        jigpe
        last edited by

        If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.

        1 Reply Last reply Reply Quote 0
        • J Offline
          jigpe
          last edited by

          @jigpe:

          If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.
          In my case, i have exemptions so i really need squid.

          1 Reply Last reply Reply Quote 0
          • S Offline
            syedadi
            last edited by

            @jigpe:

            Hi pFSerians! Good afternoon! :)

            How-to block facebook in 4 ways:

            1st: Get the CIDR of facebook using the domain_whois_tool
                           - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

            2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

            3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

            4th : Install SQUID and block facebook.com there.

            I hope im posting it in a right folder discussion..

            Hope it help all pFSerians!

            Thanks to codemarauder for the additional CIDR :) More beers later man :)

            jigp

            Can you give me the link for the CIDR info?

            1 Reply Last reply Reply Quote 0
            • M Offline
              Metu69salemi
              last edited by

              @syedadi:

              @jigpe:

              Hi pFSerians! Good afternoon! :)

              How-to block facebook in 4 ways:

              1st: Get the CIDR of facebook using the domain_whois_tool
                             - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

              2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

              3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

              4th : Install SQUID and block facebook.com there.

              I hope im posting it in a right folder discussion..

              Hope it help all pFSerians!

              Thanks to codemarauder for the additional CIDR :) More beers later man :)

              jigp

              Can you give me the link for the CIDR info?

              First post image?!?

              1 Reply Last reply Reply Quote 0
              • J Offline
                jigpe
                last edited by

                Sure. http://imageshack.us/f/193/cidr.png :)

                1 Reply Last reply Reply Quote 0
                • T Offline
                  tommyboy180
                  last edited by

                  That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                  -Tom Schaefer
                  SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                  Please support pfBlocker | File Browser | Strikeback

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    johnnybe
                    last edited by

                    @tommyboy180:

                    That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                    Thanks!

                    you would not believe the view up here

                    1 Reply Last reply Reply Quote 0
                    • J Offline
                      jigpe
                      last edited by

                      @tommyboy180

                      Thanks! But in my case i have some exemptions. All users are blocked from accessing fb except me. So im creating a rule to allow it to my IP. And if someone would like to access fb, i will just create a rule to allow the user's IP.

                      jigp

                      1 Reply Last reply Reply Quote 0
                      • P Offline
                        pcbosrders
                        last edited by

                        2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                        if you do this and have a webserver are you going to prevent it to access the net?
                        is the port 80 / 443 instead of 80 / 4443
                        want to try this and see if it interferes

                        don't fix it, if ain't broken !!!

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          jigpe
                          last edited by

                          @pcboarders
                          I have no concern with webserver so i didn't bother to try this.
                          I just want to block facebook and give exemptions to those who want to access facebook,

                          jigp

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            paoloromano
                            last edited by

                            Masters,

                            What if you have multiwan and failover, will it conflict with squid?
                            I would like to block also other sites and facebook but might encounter unwanted conflict with my multiwan and failover.
                            advise please, thanks!

                            1 Reply Last reply Reply Quote 0
                            • J Offline
                              jigpe
                              last edited by

                              Same rule in MultiWan. Use the firewall rule and select the WAN or whichever is your WAN1 and WAN2.

                              1 Reply Last reply Reply Quote 0
                              • K Offline
                                kornelson
                                last edited by

                                Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                1 Reply Last reply Reply Quote 0
                                • M Offline
                                  Metu69salemi
                                  last edited by

                                  @kornelson:

                                  Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                  How do you block http now? Answer depends greatly your blocking method

                                  1 Reply Last reply Reply Quote 0
                                  • N Offline
                                    NOYB
                                    last edited by

                                    Add Facebook CIDR to bogons data.  :o

                                    1 Reply Last reply Reply Quote 0
                                    • J Offline
                                      jigpe
                                      last edited by

                                      Latest IPs of facebook:

                                      IPV4 IPs:
                                      route:      204.15.20.0/22
                                      route:      69.63.176.0/20
                                      route:      66.220.144.0/20
                                      route:      66.220.144.0/21
                                      route:      69.63.184.0/21
                                      route:      69.63.176.0/21
                                      route:      74.119.76.0/22
                                      route:      69.171.255.0/24
                                      route:      173.252.64.0/18
                                      route:      69.171.224.0/19
                                      route:      69.171.224.0/20
                                      route:      103.4.96.0/22
                                      route:      69.63.176.0/24
                                      route:      173.252.64.0/19
                                      route:      173.252.70.0/24
                                      route:      31.13.64.0/18
                                      route:      31.13.24.0/21
                                      route:      66.220.152.0/21
                                      route:      66.220.159.0/24
                                      route:      69.171.239.0/24
                                      route:      69.171.240.0/20
                                      route:      31.13.64.0/19
                                      route:      31.13.64.0/24
                                      route:      31.13.65.0/24
                                      route:      31.13.67.0/24
                                      route:      31.13.68.0/24
                                      route:      31.13.69.0/24
                                      route:      31.13.70.0/24
                                      route:      31.13.71.0/24
                                      route:      31.13.72.0/24
                                      route:      31.13.73.0/24
                                      route:      31.13.74.0/24
                                      route:      31.13.75.0/24
                                      route:      31.13.76.0/24
                                      route:      31.13.77.0/24
                                      route:      31.13.96.0/19
                                      route:      31.13.66.0/24
                                      route:      173.252.96.0/19
                                      route:      69.63.178.0/24
                                      route:      31.13.78.0/24
                                      route:      31.13.79.0/24
                                      route:      31.13.80.0/24
                                      route:      31.13.82.0/24
                                      route:      31.13.83.0/24
                                      route:      31.13.84.0/24
                                      route:      31.13.85.0/24
                                      route:      31.13.86.0/24
                                      route:      31.13.87.0/24
                                      route:      31.13.88.0/24
                                      route:      31.13.89.0/24
                                      route:      31.13.90.0/24
                                      route:      31.13.91.0/24
                                      route:      31.13.92.0/24
                                      route:      31.13.93.0/24
                                      route:      31.13.94.0/24
                                      route:      31.13.95.0/24
                                      route:      69.171.253.0/24
                                      route:      69.63.186.0/24
                                      route:      204.15.20.0/22
                                      route:      69.63.176.0/20
                                      route:      69.63.176.0/21
                                      route:      69.63.184.0/21
                                      route:      66.220.144.0/20
                                      route:          69.63.176.0/20

                                      IPV6 IPs
                                      route6:    2620:0:1c00::/40
                                      route6:    2a03:2880::/32
                                      route6:    2401:DB00::/32
                                      route6:    2a03:2880:fffe::/48
                                      route6:    2a03:2880:ffff::/48
                                      route6:    2620:0:1cff::/48

                                      Hope this help.
                                      jigp

                                      1 Reply Last reply Reply Quote 0
                                      • C Offline
                                        CrimsonMoon79
                                        last edited by

                                        Yes, this definitely helps a lot, thank you very much.

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.