<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[I want to Block all websites and allow only some]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">I am new with Pfsense. Just have installed and added Squid , squidGuard and Lightsquid packages. I have configured them like manual says but the problem is that there are a lot of websites that LAN part can access even I have Deny all categories on blacklist? Can you help how to block all webistes and prevent users from searching from search engines?<br />
Thank you in advance</p>
]]></description><link>https://forum.netgate.com/topic/128290/i-want-to-block-all-websites-and-allow-only-some</link><generator>RSS for Node</generator><lastBuildDate>Thu, 11 Jun 2026 19:44:23 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/128290.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 16 Mar 2018 12:31:46 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Fri, 23 Mar 2018 15:21:50 GMT]]></title><description><![CDATA[<p dir="auto">UPDATE<br />
I have created a CA and activate HTTPS/SSL Interception with this configuration :<br />
SSL/MITM Mode –------------- Splice All<br />
SSL Intercept Interface(s)----------- LAN<br />
SSL Proxy Port----------3129<br />
SSL Proxy Compatibility Mode ----------- Modern<br />
DHParams Key Size-------------2048<br />
CA------------- CA Filter (the cetificate that I have created)</p>
<p dir="auto">other fields are default</p>
<p dir="auto">At this point everything is ok the blacklist is blocked and the whitelist works but after some minutes some of whitelist goes black for example gmail.com. I have add it as gmail.com / mail.google.com in both Target Categories as whitelist and at Squid Proxy as whitelist at ACL.</p>
<ul>
<li>I have export the certificate and installed on Windows computer.</li>
</ul>
]]></description><link>https://forum.netgate.com/post/756994</link><guid isPermaLink="true">https://forum.netgate.com/post/756994</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Fri, 23 Mar 2018 15:21:50 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Wed, 21 Mar 2018 20:16:10 GMT]]></title><description><![CDATA[<p dir="auto">I have successfully done this entirely with aliases and pfsense rules only, on specific LAN interfaces. It is a very time consuming task to do this effectively by just using "Firewall Rules".</p>
<p dir="auto">To be successful, you must be running Wireshark on a workstation on the LAN. Set the filter in Wireshark to DNS only, and resolve names while you browse the target website.  Observe ALL the coincident domains and Content Distribution Service providers ( CDN networks) needed to deliver the target website (Akamai, Fastly, ….)</p>
<p dir="auto">Smaller independent sites are relatively easy to isolate. Anything hosted on AWS is virtually impossible isolate.</p>
<p dir="auto">In some cases the best solution is to derive IP lists in pfblockerng using the ASN lookup feature to create "Aliase permit" list rules which  you can refer to from the firewall configuration screens. For example Facebook has its own ASN so its very easy to filter it either by blocks or permits. (ASN = Autonomous System Number)</p>
<p dir="auto">Anyway that is the concept methodology in broad terms, to achieve your objective by just using "Firewall Rules". It's as much as I can help you with</p>
<p dir="auto">Good luck !!</p>
]]></description><link>https://forum.netgate.com/post/756670</link><guid isPermaLink="true">https://forum.netgate.com/post/756670</guid><dc:creator><![CDATA[[[global:guest]]]]></dc:creator><pubDate>Wed, 21 Mar 2018 20:16:10 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Wed, 21 Mar 2018 09:37:25 GMT]]></title><description><![CDATA[<p dir="auto">I have done all as you said but it still dont work (after every change I click Apply at general settings) the webistes added to whitelist stay always loading and at the end shows that the site take too long to respond. I don't know what to do we are very confused at this point</p>
]]></description><link>https://forum.netgate.com/post/756487</link><guid isPermaLink="true">https://forum.netgate.com/post/756487</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Wed, 21 Mar 2018 09:37:25 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 17:30:00 GMT]]></title><description><![CDATA[<p dir="auto">And each time you're going back to the General settings tab, clicking Save then Apply?</p>
<p dir="auto">It's been awhile since I've setup a whitelist but it was working for me.  Make sure that it's order is first.</p>
]]></description><link>https://forum.netgate.com/post/756202</link><guid isPermaLink="true">https://forum.netgate.com/post/756202</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Mon, 19 Mar 2018 17:30:00 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 16:49:50 GMT]]></title><description><![CDATA[<p dir="auto">Its the same thing even when use allow</p>
]]></description><link>https://forum.netgate.com/post/756196</link><guid isPermaLink="true">https://forum.netgate.com/post/756196</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Mon, 19 Mar 2018 16:49:50 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 16:41:27 GMT]]></title><description><![CDATA[<p dir="auto">What happens if you change the Whitelist selector from Whitelist to Allow in the Target Rules List?</p>
]]></description><link>https://forum.netgate.com/post/756195</link><guid isPermaLink="true">https://forum.netgate.com/post/756195</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Mon, 19 Mar 2018 16:41:27 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 16:32:08 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto">Next, show screens for squidguard: Common ACL and Target Categories.</p>
</blockquote>
<p dir="auto">![common acl-1.png](/public/<em>imported_attachments</em>/1/common acl-1.png)<br />
![common acl-1.png_thumb](/public/<em>imported_attachments</em>/1/common acl-1.png_thumb)<br />
![common acl-2.png](/public/<em>imported_attachments</em>/1/common acl-2.png)<br />
![common acl-2.png_thumb](/public/<em>imported_attachments</em>/1/common acl-2.png_thumb)<br />
![common acl-3.png](/public/<em>imported_attachments</em>/1/common acl-3.png)<br />
![common acl-3.png_thumb](/public/<em>imported_attachments</em>/1/common acl-3.png_thumb)<br />
![Target Cat-1.png](/public/<em>imported_attachments</em>/1/Target Cat-1.png)<br />
![Target Cat-1.png_thumb](/public/<em>imported_attachments</em>/1/Target Cat-1.png_thumb)<br />
![Target Cat-2.png](/public/<em>imported_attachments</em>/1/Target Cat-2.png)<br />
![Target Cat-2.png_thumb](/public/<em>imported_attachments</em>/1/Target Cat-2.png_thumb)</p>
]]></description><link>https://forum.netgate.com/post/756191</link><guid isPermaLink="true">https://forum.netgate.com/post/756191</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Mon, 19 Mar 2018 16:32:08 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 14:27:57 GMT]]></title><description><![CDATA[<p dir="auto">You need to set rotation on your squid logs or they will fill up your drive eventually.  You also might want to edit the X-Forward headers to delete, disable VIA mode and suppress squid version.</p>
<p dir="auto">Next, show screens for squidguard: Common ACL and Target Categories.</p>
]]></description><link>https://forum.netgate.com/post/756157</link><guid isPermaLink="true">https://forum.netgate.com/post/756157</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Mon, 19 Mar 2018 14:27:57 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 14:19:41 GMT]]></title><description><![CDATA[<p dir="auto">Attached I have send the conf for Squid proxy and Squid Guard. I have used as BlackList http://www.shallalist.de/Downloads/shallalist.tar.gz</p>
<p dir="auto">After every change I click the Apply button  :)</p>
<p dir="auto"><img src="/public/_imported_attachments_/1/1.png" alt="1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/1.png_thumb" alt="1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/2.png" alt="2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/2.png_thumb" alt="2.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/3.png" alt="3.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/3.png_thumb" alt="3.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/4.png" alt="4.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/4.png_thumb" alt="4.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/sg-1.png" alt="sg-1.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/sg-1.png_thumb" alt="sg-1.png_thumb" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/sg-2.png" alt="sg-2.png" class=" img-fluid img-markdown" /><br />
<img src="/public/_imported_attachments_/1/sg-2.png_thumb" alt="sg-2.png_thumb" class=" img-fluid img-markdown" /></p>
]]></description><link>https://forum.netgate.com/post/756152</link><guid isPermaLink="true">https://forum.netgate.com/post/756152</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Mon, 19 Mar 2018 14:19:41 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 13:27:54 GMT]]></title><description><![CDATA[<p dir="auto">Post screens of your config.  Remember that with squidguard, you must go back to the <strong>General settings</strong> tab and click <em>Save</em> then <em>Apply</em> for changes on any other tab to take effect.</p>
<p dir="auto">By the way, there is a dedicated forum for squid &amp; squidguard, the <a href="https://forum.pfsense.org/index.php?board=60.0" target="_blank" rel="noopener noreferrer nofollow ugc">Cache/Proxy forum</a>.</p>
]]></description><link>https://forum.netgate.com/post/756140</link><guid isPermaLink="true">https://forum.netgate.com/post/756140</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Mon, 19 Mar 2018 13:27:54 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 10:40:57 GMT]]></title><description><![CDATA[<p dir="auto">We use opendns and want to pass to Pfsense but the problem now is that the whitelist is not working</p>
<blockquote>
<p dir="auto">Closing 80/443 doesn't shut down you internet connection. Just all connections with a destination using port 80 and 443. These are the two that web servers - and web browsers use .<br />
mail, dns, frp, ssh, vpn, etc etc etc etc will still work.</p>
</blockquote>
<p dir="auto">I know that other services will still work I only want to restrict them using the websites that the company dont allow.</p>
<blockquote>
<p dir="auto">I have blocked traffic for ports TCP 80/443 and it all fine with blocking all webistes but the problem now is that the whiteliste dont work.<br />
I have add a Whitelist at Target Categories and configured as Whitelist at Common ACL and all other categories DENY.<br />
Default access is Allow.<br />
Also at Squid Proxy Server &gt; ACL I have configured some websites as Whitelist.<br />
Can you help how to solve this issue?</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/756103</link><guid isPermaLink="true">https://forum.netgate.com/post/756103</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Mon, 19 Mar 2018 10:40:57 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 10:20:22 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/albtech">@<bdi>albtech</bdi></a>:</p>
<blockquote>
<p dir="auto">….  Can you help how to block all webistes and prevent users from searching from search engines?</p>
</blockquote>
<p dir="auto">All search engins ?<br />
As stated, block all connections who have a destination with port 80 or 443 in it.<br />
If not doing so, maintaining a "black" list will all  "search engines" is close to impossible.</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/albtech">@<bdi>albtech</bdi></a>:</p>
<blockquote>
<p dir="auto">Actually I dont have blocked ports 80/443. But if I do this the LAN side will still have access to internet right ?</p>
</blockquote>
<p dir="auto">Closing 80/443 doesn't shut down you internet connection. Just all connections with a destination using port 80 and 443. These are the two that web servers - and web browsers use .<br />
mail, dns, frp, ssh, vpn, etc etc etc etc will still work.</p>
<p dir="auto">edit : have a look at what OpenDNS can do for you.</p>
]]></description><link>https://forum.netgate.com/post/756099</link><guid isPermaLink="true">https://forum.netgate.com/post/756099</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 19 Mar 2018 10:20:22 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Mon, 19 Mar 2018 09:56:14 GMT]]></title><description><![CDATA[<p dir="auto">I have blocked traffic for ports TCP 80/443 and it all fine with blocking all webistes but the problem now is that the whiteliste dont work.<br />
I have add a Whitelist at Target Categories and configured as Whitelist at Common ACL and all other categories DENY.<br />
Default access is Allow.<br />
Also at Squid Proxy Server &gt; ACL I have configured some websites as Whitelist.<br />
Can you help how to solve this issue?</p>
]]></description><link>https://forum.netgate.com/post/756095</link><guid isPermaLink="true">https://forum.netgate.com/post/756095</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Mon, 19 Mar 2018 09:56:14 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Fri, 16 Mar 2018 14:04:29 GMT]]></title><description><![CDATA[<p dir="auto">Actually I dont have blocked ports 80/443. But if I do this the LAN side will still have access to internet right ?</p>
]]></description><link>https://forum.netgate.com/post/755759</link><guid isPermaLink="true">https://forum.netgate.com/post/755759</guid><dc:creator><![CDATA[albtech]]></dc:creator><pubDate>Fri, 16 Mar 2018 14:04:29 GMT</pubDate></item><item><title><![CDATA[Reply to I want to Block all websites and allow only some on Fri, 16 Mar 2018 13:34:45 GMT]]></title><description><![CDATA[<p dir="auto">What are you doing to force your users to use the proxy?  I assume you're blocking 80/443tcp on LAN?</p>
]]></description><link>https://forum.netgate.com/post/755751</link><guid isPermaLink="true">https://forum.netgate.com/post/755751</guid><dc:creator><![CDATA[KOM]]></dc:creator><pubDate>Fri, 16 Mar 2018 13:34:45 GMT</pubDate></item></channel></rss>