• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Custom aliases using domain name

Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
32 Posts 5 Posters 4.1k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • S
    Su30MKI
    last edited by Nov 21, 2018, 4:54 PM

    Is it possible to create custom aliases using domain name and not ip address or use a blacklist in the aliases with dns name and not ip address?

    1 Reply Last reply Reply Quote 0
    • K
      KOM
      last edited by Nov 21, 2018, 6:39 PM

      This post is deleted!
      1 Reply Last reply Reply Quote 0
      • S
        Su30MKI
        last edited by Nov 22, 2018, 12:31 PM

        I want to create the aliases using domain name to block the access to particular website or to use a URL which contains the website of a particular category like shallade black list. I don't want to use the DNS IP I want to use the DNS name.

        K 1 Reply Last reply Nov 22, 2018, 2:52 PM Reply Quote 0
        • B
          bepo
          last edited by Nov 22, 2018, 12:49 PM

          Yes it is possible. Just create an alias containing the FQDN and use this as a destination object in a firewall rule.

          Please use the thumbs up button if you received a helpful advice. Thank you!

          1 Reply Last reply Reply Quote 1
          • N
            NogBadTheBad
            last edited by NogBadTheBad Nov 22, 2018, 1:32 PM Nov 22, 2018, 1:31 PM

            pfBlockerNG

            Block by the ASN number or I think you can use a TLD.

            An example using Facebook.

            0_1542893420091_Screenshot 2018-11-22 at 13.30.02.png

            Use deny outbound or use it to create an alias.

            Andy

            1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

            1 Reply Last reply Reply Quote 0
            • K
              KOM @Su30MKI
              last edited by Nov 22, 2018, 2:52 PM

              This post is deleted!
              S 1 Reply Last reply Nov 22, 2018, 6:55 PM Reply Quote 0
              • S
                Su30MKI @KOM
                last edited by Nov 22, 2018, 6:55 PM

                @kom Thank you.. But I am not going to block it with the DNS IP address but with the DNS name.

                1 Reply Last reply Reply Quote 0
                • S
                  Su30MKI
                  last edited by Nov 22, 2018, 6:57 PM

                  @nogbadthebad Thank you for the wonderful representation. I am so happy for your effort. Can I assign host based blocking in the network with this method?

                  N 1 Reply Last reply Nov 22, 2018, 7:08 PM Reply Quote 0
                  • S
                    Su30MKI
                    last edited by Nov 22, 2018, 7:03 PM

                    @youngsand1 Hi.. Thank you for showing your support. I created an alias with the url. But it is not blocking.0_1542913389436_Facebook-Alias.PNG

                    1 Reply Last reply Reply Quote 0
                    • K
                      KOM
                      last edited by Nov 22, 2018, 7:06 PM

                      This post is deleted!
                      1 Reply Last reply Reply Quote 0
                      • N
                        NogBadTheBad @Su30MKI
                        last edited by Nov 22, 2018, 7:08 PM

                        @su30mki said in Custom aliases using domain name:

                        @nogbadthebad Thank you for the wonderful representation. I am so happy for your effort. Can I assign host based blocking in the network with this method?

                        Never used it but there's a bit at the bottom:-

                        0_1542913706306_Screenshot 2018-11-22 at 19.07.04.png

                        I still think you'd be better blocking by AS number.

                        Andy

                        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                        S 1 Reply Last reply Nov 22, 2018, 7:19 PM Reply Quote 1
                        • S
                          Su30MKI
                          last edited by Nov 22, 2018, 7:11 PM

                          This post is deleted!
                          1 Reply Last reply Reply Quote 0
                          • S
                            Su30MKI @NogBadTheBad
                            last edited by Su30MKI Nov 22, 2018, 7:20 PM Nov 22, 2018, 7:19 PM

                            @nogbadthebad I understand that part. How to create an alias for blocking pfsense by pfblockerng? I am very new to pf blockerng. I also have paid blacklist service. Can I load that to pfblockerng?

                            1 Reply Last reply Reply Quote 0
                            • N
                              NogBadTheBad
                              last edited by NogBadTheBad Nov 22, 2018, 7:41 PM Nov 22, 2018, 7:29 PM

                              • Instal lpfBlockerNG-devel

                              • Run the setup wizard , define your inbound and outbound interface.

                              • Create a rule Firewall -> pfBlockerNG -> IP -> IPv4 as per my screenshot but set it as deny outbound

                              • Run update via Firewall -> pfBlockerNG -> Update, the firewall rules will automatically be created

                              The rules will automatically be created on the inbound and outbound interfaces, give it a go, its quite easy.

                              0_1542914881999_Screenshot 2018-11-22 at 19.25.49.png

                              Re the paid block list you can, depending on the format, it basically creates tables that are used in firewall rules, check the tables out via Diagnostics -> Tables

                              0_1542915086235_Screenshot 2018-11-22 at 19.31.13.png

                              Andy

                              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                              S 1 Reply Last reply Nov 28, 2018, 6:08 AM Reply Quote 1
                              • S
                                Su30MKI @NogBadTheBad
                                last edited by Nov 28, 2018, 6:08 AM

                                @nogbadthebad Hello.. Thank you for your support. I am sorry for the delay in the reply. I was doing a whole new set up. I have multi wan failover setup done. So in PfblockerNG, The Inbound interface --> WAN1 & WAN2 and The outbound interface --> LAN. Is it the right method?

                                N 1 Reply Last reply Nov 28, 2018, 8:47 AM Reply Quote 0
                                • N
                                  NogBadTheBad @Su30MKI
                                  last edited by Nov 28, 2018, 8:47 AM

                                  @su30mki

                                  Yup sounds right.

                                  Andy

                                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                  S 1 Reply Last reply Nov 28, 2018, 8:56 AM Reply Quote 1
                                  • S
                                    Su30MKI @NogBadTheBad
                                    last edited by Nov 28, 2018, 8:56 AM

                                    @nogbadthebad I am having multiple vlans created in pfsense. Then I think the outbound interface should be all the vlans.

                                    N 1 Reply Last reply Nov 28, 2018, 10:48 AM Reply Quote 0
                                    • N
                                      NogBadTheBad @Su30MKI
                                      last edited by Nov 28, 2018, 10:48 AM

                                      @su30mki

                                      Yes.

                                      Andy

                                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                      S 1 Reply Last reply Nov 28, 2018, 2:19 PM Reply Quote 1
                                      • S
                                        Su30MKI @NogBadTheBad
                                        last edited by Su30MKI Nov 28, 2018, 2:19 PM Nov 28, 2018, 2:19 PM

                                        @nogbadthebad Hi, I tried doing it, But it is not blocking facebook. Please find the screenshots.1_1543414765834_IPv4-list-2.PNG 0_1543414765815_IPv4-list1.PNG

                                        1 Reply Last reply Reply Quote 0
                                        • N
                                          NogBadTheBad
                                          last edited by NogBadTheBad Nov 28, 2018, 2:24 PM Nov 28, 2018, 2:21 PM

                                          It's deny outbound.

                                          Get it working with ASN numbers they play with the social networking source after.

                                          Andy

                                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                          1 Reply Last reply Reply Quote 0
                                          3 out of 32
                                          • First post
                                            3/32
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received