Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Internet access restricts for kids

    pfSense Packages
    4
    9
    14.0k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • A
      ajeeb
      last edited by

      hello,
      I have pfsense install + squid + SG , everything just works ok .

      but I need one more thing to make an Internet supervisor and open it 8 hour for kids cause sometimes I wake up early and find my kid surf ,

      any idea how to make policy according to Machine mac address and block the internet several hours at night !

      BR

      1 Reply Last reply Reply Quote 0
      • R
        rjcrowder
        last edited by

        One easy way is to use a firewall rule that blocks outbound access to port 80 and 443 and apply it based on a schedule. You can also do it with squidguard - but I couldn't tell you exactly how.

        1 Reply Last reply Reply Quote 0
        • A
          ajeeb
          last edited by

          I think it's will block all clients !
          and I don't use squidguard ! am using squid+SG

          so … that was simple thing , my router-box EA4500 could do that
          now I don't have any control about timed access

          BR

          1 Reply Last reply Reply Quote 0
          • R
            rjcrowder
            last edited by

            @ajeeb:

            I think it's will block all clients !
            and I don't use squidguard ! am using squid+SG

            so … that was simple thing , my router-box EA4500 could do that
            now I don't have any control about timed access

            BR

            OK… I'm a little confused here. You can assign MAC addresses to specific IP's. Then you can block or allow specific IP's, ranges of IP's, etc. on any timeframe that you want. Squidguard can do the same thing. You could also authenticate users by user name (multiple ways to do it) and use squidguard or dansguardian to control access by user.

            The bottom line is that you have the ability to control access at any level that you want. I've used multiple open source firewall distributions and commercial or open source router firmwares - and I don't think that any of them give you the breadth of options that pfSense does... Just because you don't understand my answer or can't figure out how to implement the solution - don't blame the platform!

            1 Reply Last reply Reply Quote 0
            • D
              Derf
              last edited by

              The solution I use to control kid's surfing time is as following:

              • Create an alias named 'Kids' wich contains all the IP adresses of kid's devices (PCs, game consoles, …)
              • Create a schedule named 'AccessDenied' with the denied timeframes
              • Create some rules on the firewall to block/reject any connection to/from 'Kids' during 'AccessDenied'

              As rjcrowder said, there is plenty of different solutions to achieve what you want to do: you can for example use squidguard (I think the 'SG' you use should mean 'SquidGuard' but doing it that way would only allow you to control the web traffic (HTTP).
              Using firewall rules and schedules will allow you to block ALL kids traffic (including xbox/playstation/wii, p2p and so on).

              1 Reply Last reply Reply Quote 0
              • A
                ajeeb
                last edited by

                ok thanks for your reply but am little confused !!!
                I install ClearOS ! it can restricts IP,Mac address but disadvantage secure website can pass even when IP,Mac blocked !
                this is really stupid why could not they just block this mac address from entering the network !!

                I think am moving back to PFsense …

                @Derf plz tell me it's really works cause 2 things are really important for me (Web content filter + restricts surf time) and
                ClearOS kill my internet .... !!! and they are Corporate !! everything $$$ !! WTH !
                I just to keep my kids out of this sh*t around , I can make it easy by hocking up my linksys EA4500 but it disaster

                again thanks for help (@rjcrowder,Derf)
                BR

                1 Reply Last reply Reply Quote 0
                • L
                  Liath.WW
                  last edited by

                  The solution given by Derf will work, if you follow them word for word.
                  I use the same exact setup he mentioned to block access for my daughter – as there is a lot of trash out on the 'net.

                  1 Reply Last reply Reply Quote 0
                  • A
                    ajeeb
                    last edited by

                    indeed ! it's works perfect TY all .

                    BR

                    1 Reply Last reply Reply Quote 0
                    • R
                      rjcrowder
                      last edited by

                      @Derf:

                      The solution I use to control kid's surfing time is as following:

                      • Create an alias named 'Kids' wich contains all the IP adresses of kid's devices (PCs, game consoles, …)
                      • Create a schedule named 'AccessDenied' with the denied timeframes
                      • Create some rules on the firewall to block/reject any connection to/from 'Kids' during 'AccessDenied'

                      As rjcrowder said, there is plenty of different solutions to achieve what you want to do: you can for example use squidguard (I think the 'SG' you use should mean 'SquidGuard' but doing it that way would only allow you to control the web traffic (HTTP).
                      Using firewall rules and schedules will allow you to block ALL kids traffic (including xbox/playstation/wii, p2p and so on).

                      I do the same thing as Derf for time based access. If you want to keep you kids "safe" while they are surfing, there are a couple of other things that I HIGHLY recommend.

                      1.) OpenDNS. Gives you a great set of DNS based blacklists and performs well. I just can't see any reason not to use it.
                      2.) Dansguardian. For dg, I usually download the Shalla blacklists and also use the weighted phraselists. Blacklists are only as good as they are kept up to date and dg phrase checking does a very good job at catching the rest…

                      Something else you might want to condider is turning on Clamav in dg.  It does a great job of realtime virus scanning. However, you will perceive some lag from it - especially when downloading large files.

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.