Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block only google drive upload

    Firewalling
    6
    6
    1.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • K
      koko_adams
      last edited by

      Hi

      I would block upload file to cloud provider sush as Dropbox, Google Drive, etc

      I can block dropbox traffic

      but , with google drive , i think it is not easy, many web site is in the same ip range with drive (youtube , google doc , ...)

      how i can block only google drive ?

      Thank You

      M JKnottJ 2 Replies Last reply Reply Quote 0
      • bmeeksB
        bmeeks
        last edited by

        You somewhat answered you own question with these words:

        not easy, many web site is in the same ip range with drive (youtube , google doc , ...)

        You need a DPI (deep packet inspection) engine to accomplish this and possibly even a MITM (man-in-the-middle) certificate proxy system so you can inspect payloads in cleartext. You could try the OpenAppID functionality within the Snort package, but I don't recall if there are any existing Google Drive rules in that rule set.

        1 Reply Last reply Reply Quote 1
        • GertjanG
          Gertjan
          last edited by Gertjan

          Hi,

          Well ... as you said yourself, you can't use destination-IP-list discrimination, otherwise it would be as easy of finding all the Google-drive IP's, throwing them in an Firewall alias and using this alias in a firewall block rule.
          Although I do think that Google services like the web search egnin, Youtube, Gmail, etc do not use the same IP's as Google drive.

          The next step would be : finding out what Google drive (for example : login phase) packets have in common : this means your have to to filter on IDS/IPS level - see the sub forum for information. This can be done, and certainly not in a lost afternoon.
          See also this one to get the picture.

          edit : @bmeeks types faster ^^

          No "help me" PM's please. Use the forum, the community will thank you.
          Edit : and where are the logs ??

          1 Reply Last reply Reply Quote 0
          • A
            akuma1x
            last edited by akuma1x

            If it's as simple as drive.google.com, you could set the Domain Override in Services -> DNS Forwarder to resolve it to nothing. That's the "!" character in that entry.

            I say simple above, but it's probably not that cut-and-dry... I don't know for sure if google drive has a much larger reach, domain or IP address-wise.

            Read more about dns forwarder here:
            https://docs.netgate.com/pfsense/en/latest/dns/dns-forwarder.html

            Jeff

            1 Reply Last reply Reply Quote 0
            • M
              Moeamed @koko_adams
              last edited by

              @koko_adams said in Block only google drive upload:

              Hi

              I would block upload file to cloud provider sush as Dropbox, Google Drive, etc

              I can block dropbox traffic

              but , with google drive , i think it is not easy, many web site is in the same ip range with drive (youtube , google doc , ...)

              how i can block only google drive ?

              Thank You

              Hello Koko_adams,

              I am very curious about this subject. Do you find a solution/work around ?

              Thank you,

              1 Reply Last reply Reply Quote 0
              • JKnottJ
                JKnott @koko_adams
                last edited by

                @koko_adams said in Block only google drive upload:

                I would block upload file to cloud provider sush as Dropbox, Google Drive, etc

                You want to block upload and not download???

                I doubt that would be possible with a firewall, as you'd have to filter the traffic in an encrypted https stream. You might be able to get a proxy to do that, but not a plain firewall.

                PfSense running on Qotom mini PC
                i5 CPU, 4 GB memory, 32 GB SSD & 4 Intel Gb Ethernet ports.
                UniFi AC-Lite access point

                I haven't lost my mind. It's around here...somewhere...

                1 Reply Last reply Reply Quote 0
                • First post
                  Last post
                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.