Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Blocking everything except...

    General pfSense Questions
    block all whitelist
    4
    9
    1.1k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • OceanwatcherO
      Oceanwatcher
      last edited by

      I have a customer that needs to block everything except a few domains.

      So they basically would like to have some whitelisted domains, and the problem of course is that some of these are using a CDN or otherwise use multiple IP addresses.

      I am assuming this is a job for squid? Or do you have any better suggestions? What is the best way of getting this done?

      This block has to happen for all traffic from a specific VLAN. Other VLAN's should not be affected.

      Regards,

      Oceanwatcher
      2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

      1 Reply Last reply Reply Quote 0
      • M
        mare
        last edited by

        Perhapse more pfBlockerNG than Squid. It blocks using DNS Resolver service.

        OceanwatcherO 1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Usually when people ask this they don't really understand what they're asking for. Any site that has a large CDN probably pulls data fro numerous domains to work correctly. Allowing, for example, only *.gmail.com to resolve is not going to end well. ๐Ÿ˜‰

          Steve

          OceanwatcherO 1 Reply Last reply Reply Quote 0
          • OceanwatcherO
            Oceanwatcher @stephenw10
            last edited by Oceanwatcher

            @stephenw10
            Thank you for taking the time to answer. Although, I do not fully understand your answer.

            Was it a hint that I do not understand what I am asking for? Or is it something you wanted me to pass on to my customer? ๐Ÿ˜‰

            Please help me understand how your answer will help me come up with a solution ๐Ÿ˜‰ ๐Ÿ˜‰

            Regards,

            Oceanwatcher
            2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

            1 Reply Last reply Reply Quote 0
            • OceanwatcherO
              Oceanwatcher @mare
              last edited by

              @mare Great. Thank you. Will take my question over to the sub forum for pfBlockerNG.

              Regards,

              Oceanwatcher
              2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                I'm saying what the customer is asking for is probably more complex than they think.
                "Just a few domains" is probably just a few sites which could be a large number of domains and also a moving target.
                It might not be...

                Steve

                OceanwatcherO 1 Reply Last reply Reply Quote 0
                • NollipfSenseN
                  NollipfSense
                  last edited by

                  The same person asked the same question here: https://forum.netgate.com/topic/148392/blocking-everything-except

                  They got a response yet never followed up...that leads me to conclude that OP isn't sure what the alleged customer wants.

                  pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                  pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                  OceanwatcherO 1 Reply Last reply Reply Quote 0
                  • OceanwatcherO
                    Oceanwatcher @NollipfSense
                    last edited by

                    @NollipfSense Please read this whole thread before making any judgement ๐Ÿ˜‰

                    Regards,

                    Oceanwatcher
                    2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

                    1 Reply Last reply Reply Quote 0
                    • OceanwatcherO
                      Oceanwatcher @stephenw10
                      last edited by

                      @stephenw10 said in Blocking everything except...:

                      It might not be...

                      That is correct ๐Ÿ˜‰

                      Regards,

                      Oceanwatcher
                      2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.