Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How do I block mobile apps like Facebook, Instagram, and Amazon with OpenAppID?

    Scheduled Pinned Locked Moved Firewalling
    4 Posts 4 Posters 2.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • O
      onurturali
      last edited by

      Hello to everyone

      I want to block Internet access for mobile applications like Facebook, Twitter, and Amazon using Snort and OpenAppID . There are no enough OpenAppID settings in Snort's General Settings and Snort interfaces. I can only enable OpenAppID in Snort General settings and Snort interfaces. There's nothing else.

      By the way, I can block websites like Facebook, Twitter, and Amazon in the browser using E2Guardian and Squid. For example, when I access facebook.com from a browser, I block all URIs in SQStat in the ACLs of E2Guardian - In this way, even if the website has SSL, I can block that website - After blocking whole facebook.com URIs with E2Guardian, I also noticed that the data traffic of the Facebook mobile application is cut. It's also the same with the Facebook application in Windows 10.

      I want to block mobile application with OpenAppID, not the E2Guardian. I couldn't find any up-to-date and relevant resources on the Internet. Can you help me on this issue?

      1 Reply Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by bmeeks

        Did you review the OpenAppID setup instructions in the pfSense documentation? Here is a link: https://docs.netgate.com/pfsense/en/latest/ids-ips/setup-snort-package.html?highlight=openappid#application-id-detection-with-openapp-id.

        You have to enable the OpenAppID rules download (along with the OpenAppID detector stubs), update the rules on the UPDATES tab to download the necessary files, then go to the RULES tab and select which OpenAppID categories you want to use. Sounds like, from your description of things, that you have not done all of these steps.

        Also, you will find that Snort and OpenAppID will work better with the new Inline IPS Mode feature available in the Snort 4.0_6 package on pfSense-2.5-DEVEL.

        1 Reply Last reply Reply Quote 0
        • BerryHornB
          BerryHorn
          last edited by

          This post is deleted!
          1 Reply Last reply Reply Quote 0
          • AudreyTerryA
            AudreyTerry Banned
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.