Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Can anyone help me block mobile application like facebook, youtube, & other IM

    Scheduled Pinned Locked Moved General pfSense Questions
    14 Posts 9 Posters 8.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J
      jesense
      last edited by

      Hello PFSENSE Community..

      Please help me im trying to block fb, youtube, messenger, whattsup & other IM application in Android & IOS.

      Please and thank you. . .

      1 Reply Last reply Reply Quote 0
      • V
        VirtualBob
        last edited by

        Hey,

        I managed to do this using SquidGuard.

        https://doc.pfsense.org/index.php/SquidGuard_package

        You will also need to downlaod a white/blacklist and upload it.

        Then there is some monitoring to do and check through logs to add anything that slips past.

        Other way to do it is block everything by default and only allow what matches WAN ip addresses that you want.

        Ive not been playing with pfSense for long but hope that helps move things forwards.

        1 Reply Last reply Reply Quote 0
        • J
          jesense
          last edited by

          Thank you Virtual bob i will try this…

          1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            That will only filter http/https traffic though so not message traffic at least in some cases.

            You might also try using DNS-BL from the pfBlocker package to block domains at the DNS level which obviously works for all protocols but not if apps have hard coded IPs.

            Steve

            1 Reply Last reply Reply Quote 0
            • J
              jesense
              last edited by

              Can you help me to configure the pfblocker? im new to pfsense. .  please

              1 Reply Last reply Reply Quote 0
              • P
                pfBasic Banned
                last edited by

                @jesense:

                Can you help me to configure the pfblocker? im new to pfsense. .  please

                pfBlockerNG has really great info built into the package, just click on the info panes and read for basic setup.

                Here are some additional posts to get you started:
                https://forum.pfsense.org/index.php?topic=102470.msg572943#msg572943

                What you are trying to accomplish goes beyond the basic setup. You'll need to poke around the forums to learn how to do what you need, but it's all laid out very well. Pay extra attention to posts by BBCan177, pfBNG is his.

                Once you've got pfBNG up and running with a basic configuration, check out this thread and the posts it links to. It's focused on blocking porn but you can use the same methods and lists to accomplish your goals.
                https://forum.pfsense.org/index.php?topic=125863.0

                1 Reply Last reply Reply Quote 0
                • P
                  pfBasic Banned
                  last edited by

                  Out of curiosity I'm wondering if it would be possible to somehow hack the Traffic Shaper to effectively block IM services. It allows you to specify services, could you go into a config file or something and limit those services to 0 throughput?

                  Just a thought, I'd be interested in hearing the thoughts of someone smart on this!

                  1 Reply Last reply Reply Quote 0
                  • M
                    marvosa
                    last edited by

                    Is is possible to leverage some existing tools and packages to accomplish what you want… maybe... but you'll be chasing 10's of thousands of IP's,  it'll eat up a bunch of time and will be a management nightmare.

                    The more straight forward approach is to implement a UTM inline with your network.

                    1 Reply Last reply Reply Quote 0
                    • C
                      Chrismallia
                      last edited by

                      marvosa is right. I never found a mature way of doing this type of blocking in pf

                      If you really need this throw in untangle as a bridge install application control and just tick what you want to block

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        One possibility is to use OpenAppID in Snort. You can block with that if a signature exists for the app you want. I'm unsure about marking traffic for shaping using that. It's relatively new in the package.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • C
                          Chrismallia
                          last edited by

                          @stephenw10:

                          One possibility is to use OpenAppID in Snort. You can block with that if a signature exists for the app you want. I'm unsure about marking traffic for shaping using that. It's relatively new in the package.

                          Steve

                          This looks  worth checking out

                          1 Reply Last reply Reply Quote 0
                          • P
                            Presbuteros
                            last edited by

                            @pfBasic:

                            pfBlockerNG has really great info built into the package, just click on the info panes and read for basic setup.

                            I second pfBasic. pfBlockerNG is a great tool to add to your pfSense install.

                            I just confirmed that you can block WhatsApp with pfBlockerNG by adding an IPv4 list. Once pfBlockerNG is installed and running navigate to Firewall>pfBlockerNG>IPv4. Click Add.

                            Alias Name: WhatsApp Block List

                            List Description: Blocking WhatsApp

                            Source:

                            https://www.whatsapp.com/cidr.txt
                            

                            Header Label: WhatsApp

                            List Action: Deny Both

                            Update Frequency: Once a day

                            Click "Save"

                            Navigate to Firewall>pfBlockerNG>Update.

                            Click "Run"

                            Navigate to Diagnostics>States>Reset States

                            Check "Reset the firewall state table" and click "Reset"

                            You must reset the States or the settings will not take place.

                            block_whatsapp.png
                            block_whatsapp.png_thumb

                            A 1 Reply Last reply Reply Quote 0
                            • A
                              Aziz Rahman @Presbuteros
                              last edited by

                              @presbuteros thank you for your nice comment, can you please tell us how to block youtube,facebook and other mobile applications?

                              L 1 Reply Last reply Reply Quote 0
                              • L
                                lcbbcl @Aziz Rahman
                                last edited by

                                @aziz-rahman said in Can anyone help me block mobile application like facebook, youtube, & other IM:

                                @presbuteros thank you for your nice comment, can you please tell us how to block youtube,facebook and other mobile applications?

                                Try to use ASN option from pfblocker , he will create aliase, after you will create your own rule on each interface you need to block using that alias
                                whatsasn.png
                                My rule is to allow to certain ports so i won't be *(everything) . I would love to block the entire facebook but i am maried.

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.