Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Custom aliases using domain name

    Scheduled Pinned Locked Moved Off-Topic & Non-Support Discussion
    32 Posts 5 Posters 4.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • NogBadTheBadN
      NogBadTheBad
      last edited by NogBadTheBad

      I've just tried it and its an issue with your block list as it doesn't contain valid IP addresses just 0.0.0.0 FQDN.

      PfB_Test_v4 Table
      IP Address
      123.41.54.45
      130.211.230.53
      160.41.54.45
      163.41.54.45
      194.41.54.45

      Rather than using IP try using the DBNS

      0_1543416681468_Screenshot 2018-11-28 at 14.50.13.png

      Andy

      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

      1 Reply Last reply Reply Quote 1
      • S
        Su30MKI
        last edited by

        Can you please suggest any list?

        NogBadTheBadN 1 Reply Last reply Reply Quote 0
        • NogBadTheBadN
          NogBadTheBad @Su30MKI
          last edited by

          @su30mki

          Have you tried blocking facebook by ASN numbers or like I suggested try the using the list your using in the DBNSL section as per my screenshot.

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          S 1 Reply Last reply Reply Quote 0
          • S
            Su30MKI @NogBadTheBad
            last edited by

            @nogbadthebad Thank you very much.. It is working. Saved my reputation.

            NogBadTheBadN 1 Reply Last reply Reply Quote 0
            • NogBadTheBadN
              NogBadTheBad @Su30MKI
              last edited by

              @su30mki said in Custom aliases using domain name:

              @nogbadthebad Thank you very much.. It is working. Saved my reputation.

              via IP and ASN number or DNSBL ?

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              S 1 Reply Last reply Reply Quote 1
              • S
                Su30MKI @NogBadTheBad
                last edited by

                @nogbadthebad Now how do I segregate different rules for different vlans?

                NogBadTheBadN 1 Reply Last reply Reply Quote 0
                • NogBadTheBadN
                  NogBadTheBad @Su30MKI
                  last edited by

                  @su30mki

                  Use alias permit, alias deny, alias match & alias native.

                  That will just create an alias you can use in firewall rules.

                  Andy

                  1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                  S 1 Reply Last reply Reply Quote 1
                  • S
                    Su30MKI @NogBadTheBad
                    last edited by

                    @nogbadthebad Can you please help me with a screenshot?

                    1 Reply Last reply Reply Quote 0
                    • NogBadTheBadN
                      NogBadTheBad
                      last edited by NogBadTheBad

                      0_1543419206004_Screenshot 2018-11-28 at 15.32.37.png

                      Only allow GB access to my SFTP server:-

                      0_1543419347807_Screenshot 2018-11-28 at 15.33.03.png

                      Andy

                      1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                      S 1 Reply Last reply Reply Quote 1
                      • S
                        Su30MKI @NogBadTheBad
                        last edited by

                        @nogbadthebad Thank you for your effort. But that is Geoip. Imagine I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it? How can I do different rules for different vlan via DNSBL?

                        A 1 Reply Last reply Reply Quote 0
                        • NogBadTheBadN
                          NogBadTheBad
                          last edited by

                          Use ASN if you want to block a specific company.

                          DBNSL alters DNS so x.y.z.abc.com resolves to an internal ip address on your router.

                          IP creates tables that can be used in firewall rules.

                          The example I gave you was a GeoIP one I use but ASN based ones are no different, rather than containing a countries IP range it contains a companies IP range.

                          Andy

                          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                          1 Reply Last reply Reply Quote 0
                          • A
                            Alexismurphy @Su30MKI
                            last edited by

                            @su30mki said in Custom aliases using domain name:

                            I want to block facebook to one vlan and another vlan requires facebook access.. How do I do it?

                            First at all, you have to configure your vlan.
                            After that, you have to create an ACL in order to provide internet access to one vlan and block it in the other vlans.
                            Remember set your device as a “Layer 3” device.

                            1 Reply Last reply Reply Quote 0
                            • First post
                              Last post
                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.