• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Custom aliases using domain name

Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
32 Posts 5 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N
    NogBadTheBad
    last edited by NogBadTheBad Nov 28, 2018, 2:24 PM Nov 28, 2018, 2:21 PM

    It's deny outbound.

    Get it working with ASN numbers they play with the social networking source after.

    Andy

    1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

    1 Reply Last reply Reply Quote 0
    • N
      NogBadTheBad
      last edited by NogBadTheBad Nov 28, 2018, 2:51 PM Nov 28, 2018, 2:40 PM

      I've just tried it and its an issue with your block list as it doesn't contain valid IP addresses just 0.0.0.0 FQDN.

      PfB_Test_v4 Table
      IP Address
      123.41.54.45
      130.211.230.53
      160.41.54.45
      163.41.54.45
      194.41.54.45

      Rather than using IP try using the DBNS

      0_1543416681468_Screenshot 2018-11-28 at 14.50.13.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 1
      • S
        Su30MKI
        last edited by Nov 28, 2018, 3:00 PM

        Can you please suggest any list?

        N 1 Reply Last reply Nov 28, 2018, 3:06 PM Reply Quote 0
        • N
          NogBadTheBad @Su30MKI
          last edited by Nov 28, 2018, 3:06 PM

          @su30mki

          Have you tried blocking facebook by ASN numbers or like I suggested try the using the list your using in the DBNSL section as per my screenshot.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          S 1 Reply Last reply Nov 28, 2018, 3:13 PM Reply Quote 0
          • S
            Su30MKI @NogBadTheBad
            last edited by Nov 28, 2018, 3:13 PM

            @nogbadthebad Thank you very much.. It is working. Saved my reputation.

            N 1 Reply Last reply Nov 28, 2018, 3:14 PM Reply Quote 0
            • N
              NogBadTheBad @Su30MKI
              last edited by Nov 28, 2018, 3:14 PM

              @su30mki said in Custom aliases using domain name:

              @nogbadthebad Thank you very much.. It is working. Saved my reputation.

              via IP and ASN number or DNSBL ?

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              S 1 Reply Last reply Nov 28, 2018, 3:21 PM Reply Quote 1
              • S
                Su30MKI @NogBadTheBad
                last edited by Nov 28, 2018, 3:21 PM

                @nogbadthebad Now how do I segregate different rules for different vlans?

                N 1 Reply Last reply Nov 28, 2018, 3:29 PM Reply Quote 0
                • N
                  NogBadTheBad @Su30MKI
                  last edited by Nov 28, 2018, 3:29 PM

                  @su30mki

                  Use alias permit, alias deny, alias match & alias native.

                  That will just create an alias you can use in firewall rules.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  S 1 Reply Last reply Nov 28, 2018, 3:30 PM Reply Quote 1
                  • S
                    Su30MKI @NogBadTheBad
                    last edited by Nov 28, 2018, 3:30 PM

                    @nogbadthebad Can you please help me with a screenshot?

                    1 Reply Last reply Reply Quote 0
                    • N
                      NogBadTheBad
                      last edited by NogBadTheBad Nov 28, 2018, 3:36 PM Nov 28, 2018, 3:35 PM

                      0_1543419206004_Screenshot 2018-11-28 at 15.32.37.png

                      Only allow GB access to my SFTP server:-

                      0_1543419347807_Screenshot 2018-11-28 at 15.33.03.png

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      S 1 Reply Last reply Nov 28, 2018, 3:41 PM Reply Quote 1
                      • S
                        Su30MKI @NogBadTheBad
                        last edited by Nov 28, 2018, 3:41 PM

                        @nogbadthebad Thank you for your effort. But that is Geoip. Imagine I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? How can I do different rules for different vlan via DNSBL?

                        A 1 Reply Last reply Dec 20, 2018, 5:28 AM Reply Quote 0
                        • N
                          NogBadTheBad
                          last edited by Nov 28, 2018, 3:47 PM

                          Use ASN if you want to block a specific company.

                          DBNSL alters DNS so x.y.z.abc.com resolves to an internal ip address on your router.

                          IP creates tables that can be used in firewall rules.

                          The example I gave you was a GeoIP one I use but ASN based ones are no different, rather than containing a countries IP range it contains a companies IP range.

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          1 Reply Last reply Reply Quote 0
                          • A
                            Alexismurphy @Su30MKI
                            last edited by Dec 20, 2018, 5:28 AM

                            @su30mki said in Custom aliases using domain name:

                            I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it?

                            First at all, you have to configure your vlan.
                            After that, you have to create an ACL in order to provide internet access to one vlan and block it in the other vlans.
                            Remember set your device as a “Layer 3” device.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                              [[user:consent.lead]]
                              [[user:consent.not_received]]