Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Custom aliases using domain name

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    32 Posts 5 Posters 4.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      Su30MKI @NogBadTheBad
      last edited by Su30MKI

      @nogbadthebad Hi, I tried doing it, But it is not blocking facebook. Please find the screenshots.1_1543414765834_IPv4-list-2.PNG 0_1543414765815_IPv4-list1.PNG

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by NogBadTheBad

        It's deny outbound.

        Get it working with ASN numbers they play with the social networking source after.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad
          last edited by NogBadTheBad

          I've just tried it and its an issue with your block list as it doesn't contain valid IP addresses just 0.0.0.0 FQDN.

          PfB_Test_v4 Table
          IP Address
          123.41.54.45
          130.211.230.53
          160.41.54.45
          163.41.54.45
          194.41.54.45

          Rather than using IP try using the DBNS

          0_1543416681468_Screenshot 2018-11-28 at 14.50.13.png

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          1 Reply Last reply Reply Quote 1
          • S
            Su30MKI
            last edited by

            Can you please suggest any list?

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @Su30MKI
              last edited by

              @su30mki

              Have you tried blocking facebook by ASN numbers or like I suggested try the using the list your using in the DBNSL section as per my screenshot.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              S 1 Reply Last reply Reply Quote 0
              • S
                Su30MKI @NogBadTheBad
                last edited by

                @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @Su30MKI
                  last edited by

                  @su30mki said in Custom aliases using domain name:

                  @nogbadthebad Thank you very much.. It is working. Saved my reputation.

                  via IP and ASN number or DNSBL ?

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  S 1 Reply Last reply Reply Quote 1
                  • S
                    Su30MKI @NogBadTheBad
                    last edited by

                    @nogbadthebad Now how do I segregate different rules for different vlans?

                    NogBadTheBadN 1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad @Su30MKI
                      last edited by

                      @su30mki

                      Use alias permit, alias deny, alias match & alias native.

                      That will just create an alias you can use in firewall rules.

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      S 1 Reply Last reply Reply Quote 1
                      • S
                        Su30MKI @NogBadTheBad
                        last edited by

                        @nogbadthebad Can you please help me with a screenshot?

                        1 Reply Last reply Reply Quote 0
                        • NogBadTheBadN
                          NogBadTheBad
                          last edited by NogBadTheBad

                          0_1543419206004_Screenshot 2018-11-28 at 15.32.37.png

                          Only allow GB access to my SFTP server:-

                          0_1543419347807_Screenshot 2018-11-28 at 15.33.03.png

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          S 1 Reply Last reply Reply Quote 1
                          • S
                            Su30MKI @NogBadTheBad
                            last edited by

                            @nogbadthebad Thank you for your effort. But that is Geoip. Imagine I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? How can I do different rules for different vlan via DNSBL?

                            A 1 Reply Last reply Reply Quote 0
                            • NogBadTheBadN
                              NogBadTheBad
                              last edited by

                              Use ASN if you want to block a specific company.

                              DBNSL alters DNS so x.y.z.abc.com resolves to an internal ip address on your router.

                              IP creates tables that can be used in firewall rules.

                              The example I gave you was a GeoIP one I use but ASN based ones are no different, rather than containing a countries IP range it contains a companies IP range.

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              1 Reply Last reply Reply Quote 0
                              • A
                                Alexismurphy @Su30MKI
                                last edited by

                                @su30mki said in Custom aliases using domain name:

                                I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it?

                                First at all, you have to configure your vlan.
                                After that, you have to create an ACL in order to provide internet access to one vlan and block it in the other vlans.
                                Remember set your device as a “Layer 3” device.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.