Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block layer 7 on websites

    Scheduled Pinned Locked Moved pfSense Packages
    13 Posts 7 Posters 1.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dma11
      last edited by

      Hi,

      Is there a package within pfSense that lets you block layer 7 streaming on website?

      For example: blocking an embedded video player on website without actually blocking the whole website.

      Thanks in advance,
      Darren

      1 Reply Last reply Reply Quote 0
      • NogBadTheBadN
        NogBadTheBad
        last edited by

        Snort and the openappid streaming media rule.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        1 Reply Last reply Reply Quote 0
        • D
          dma11
          last edited by

          Thanks @NogBadTheBad

          Do you know if there is any documentation available on how to create this rule?

          1 Reply Last reply Reply Quote 0
          • NogBadTheBadN
            NogBadTheBad
            last edited by

            The rules are there, i think you need to select it then unselect everything you want to pass in the actual rule.

            Then enable blocking in the interface.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad
              last edited by NogBadTheBad

              0_1549370926021_Screenshot 2019-02-05 at 12.43.43.png

              0_1549370930780_Screenshot 2019-02-05 at 12.44.16.png

              0_1549370942821_Screenshot 2019-02-05 at 12.44.57.png

              0_1549370948103_Screenshot 2019-02-05 at 12.45.13.png

              0_1549370952875_Screenshot 2019-02-05 at 12.45.51.png

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              A 1 Reply Last reply Reply Quote 0
              • D
                dma11
                last edited by

                @NogBadTheBad

                Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                bmeeksB 1 Reply Last reply Reply Quote 0
                • bmeeksB
                  bmeeks @dma11
                  last edited by bmeeks

                  @dma11 said in Block layer 7 on websites:

                  @NogBadTheBad

                  Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                  Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                  Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    susamlicubuk @bmeeks
                    last edited by

                    @bmeeks said in Block layer 7 on websites:

                    @dma11 said in Block layer 7 on websites:

                    @NogBadTheBad

                    Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                    Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                    Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                    hi bmeeks;

                    Can you share a sample packet listening and blocking path detail. chrome, opera, firewfox vpn apps etc. (not the rule listed, the new custom rule)
                    thanks.

                    bmeeksB 1 Reply Last reply Reply Quote 0
                    • bmeeksB
                      bmeeks @susamlicubuk
                      last edited by

                      @susamlicubuk said in Block layer 7 on websites:

                      @bmeeks said in Block layer 7 on websites:

                      @dma11 said in Block layer 7 on websites:

                      @NogBadTheBad

                      Brilliant m8. Thanks for the input. Much appreciated. It works perfectly :)

                      Now I'm trying to see whether you can manually add rules to the list because there were some embedded video players that weren't blocked since there were no signatures combined to them.

                      Provided you know and follow the required syntax, you can create your own custom rules and add them to the list of enforced rules in Snort. Go to the RULES tab (first EDIT an interface and then choose the RULES tab) and choose Custom in the Category selection drop-down. Type your rules into the text area box. Save them and restart Snort on the interface.

                      hi bmeeks;

                      Can you share a sample packet listening and blocking path detail. chrome, opera, firewfox vpn apps etc. (not the rule listed, the new custom rule)
                      thanks.

                      Sorry, I am not a rule writer. Never bothered to learn the syntax in detail. You should be able to find some examples with a Google search, and then maybe build off the rules included in the OpenAppID package with pfSense.

                      1 Reply Last reply Reply Quote 0
                      • A
                        ammar177 @NogBadTheBad
                        last edited by

                        @NogBadTheBad Does this also block all the video streaming apps installed on smart phones (etc. tiktok, likee, snackvideo and other like these)?

                        GertjanG 1 Reply Last reply Reply Quote 0
                        • GertjanG
                          Gertjan @ammar177
                          last edited by Gertjan

                          @ammar177

                          You're waking up forum threads more then 4 years old ...
                          Much has changed since then.

                          No "help me" PM's please. Use the forum, the community will thank you.
                          Edit : and where are the logs ??

                          A 1 Reply Last reply Reply Quote 0
                          • A
                            ammar177 @Gertjan
                            last edited by

                            @Gertjan you are right. please guide how can I block streaming apps installed on smart phones using pgblockerNG or snort.

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              michmoor LAYER 8 Rebel Alliance @ammar177
                              last edited by

                              @ammar177 Using pfBlockerNG. Create an alias of ASNs you want to block (netflix,hulu,peacock,etc..). Apply that alias to the IPs that should be blocked.
                              There isnt a clean way to block streaming sites on pfsense. Snort openapp.id rules have not been updated in some time (over 5 years) so they will not account for the latest streaming sites. You will need to write your own rules for that.

                              If you are looking to block streaming media sites on a phone its probably best to point that client to openDNS or NextDNS where you can do category-based blocking and not use pfSense for DNS. That's the best recommendation i can give.

                              Firewall: NetGate,Palo Alto-VM,Juniper SRX
                              Routing: Juniper, Arista, Cisco
                              Switching: Juniper, Arista, Cisco
                              Wireless: Unifi, Aruba IAP
                              JNCIP,CCNP Enterprise

                              1 Reply Last reply Reply Quote 0
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.