Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    How to block secure websites (like Social, sports ,music etc).

    Cache/Proxy
    5
    6
    168
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • I
      itsupport_debut last edited by

      Hi All,
      i want to block some secure websites (like Social, sports ,music etc). Please guide me how we block these websites. I Want to block secure websites according to configure rules in squidguard.
      Thanks

      1 Reply Last reply Reply Quote 0
      • I
        itsupport_debut last edited by

        Nobody has any idea about this??? @Gertjan

        1 Reply Last reply Reply Quote 0
        • V
          vishantkamboj last edited by

          Hi @itsupport_debut We have face same problem also. I want to block some secure websites like Sports and i have already configure SquidGuard also but unable to block Secure websites.

          1 Reply Last reply Reply Quote 0
          • bmeeks
            bmeeks last edited by bmeeks

            Nobody has replied because this request is somewhere between extrememly hard and nearly impossible to accomplish in today's Internet environment with all the encryption and CDNs (Content Distribution Networks) used by tons of web sites.

            Unless you install a MITM (Man-in-the-Middle) proxy you can't see the cleartext traffic of HTTPS web traffic. That makes is quite hard to block based solely on the content. Furthermore, even attempting to block based only on IP addresses is made very difficult by the fact sites usually serve content from many IP networks via CDNs. And those CDNs carry all kinds of traffic, some of which you may not want to block but it will all be coming from the same IP network blocks.

            Policing Internet usage should begin with clearly defining expected behavior to the humans viewing the content and also providing clear punishments of some type for knowing violations. Trying to police it with technology is likely to be only marginally successful.

            Yes, there are lists of IPs to ban and all kinds of vendors promising a magic elixir, but none is foolproof. And many times you will spend hours chasing down why web sites you want to allow in are getting blocked by something in these magic elixir tools.

            1 Reply Last reply Reply Quote 0
            • NogBadTheBad
              NogBadTheBad last edited by NogBadTheBad

              @bmeeks said in How to block secure websites (like Social, sports ,music etc).:

              Policing Internet usage should begin with clearly defining expected behavior to the humans viewing the content and also providing clear punishments of some type for knowing violations. Trying to police it with technology is likely to be only marginally successful.

              You may be able to do it with Shallalist or UT1 in pfBlockerNG, but you will need loads of memory.

              Firewall -> pfBlockerNG -> DNSBL -> DNSBL Category

              As @bmeeks these lists aren't foolproof.

              Andy

              1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

              1 Reply Last reply Reply Quote 0
              • johnpoz
                johnpoz LAYER 8 Global Moderator last edited by

                Its also possible since your post has only been 1 day. And is in the wrong section... Your asking about how to filter https with squidguard.. Not Firewall..

                Blocking only specific https sites with a firewall that are hosted off CDNs yeah going to be very difficult.. But blocking via proxy is not that difficult, you don't need to do mitm if your using explicit proxy (ie client directed to the proxy). But if doing it via transparent - then yes it becomes more difficult

                I have moved your thread to correct area so you might get an answer on how to do it with squidguard... But then again they prob just going tell you to RTFM ;)

                For example check out the hangout by jimp - he goes over all the different way to filter https traffic
                From the hangout
                https://youtu.be/xm_wEezrWf4
                hangout.png

                Moving to proxy section.

                An intelligent man is sometimes forced to be drunk to spend time with his fools
                If you get confused: Listen to the Music Play
                Please don't Chat/PM me for help, unless mod related
                SG-4860 23.01 | Lab VMs CE 2.6, 2.7

                1 Reply Last reply Reply Quote 1
                • First post
                  Last post