Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    pfSense pfBlocker and mobile phones apps

    Scheduled Pinned Locked Moved pfBlockerNG
    9 Posts 4 Posters 2.2k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      William Barni
      last edited by William Barni

      I can't seem to find a way to block any app activity in my mobile phones.
      I can block youtube in the workstations via TLD, but all the mobilephones have normal access to videos, facebook and whatever they want.

      I added a rule in pfSense to block all traffic on port 53 from LAN, so everyone needs to use pfSense as DNS server... but youtube and other apps keep working normally.

      Source any, Destination Lan net, allow port 53
      Source Lan net, Destination any, block port 53

      I've also added youtube (youtube.com and many other hosts) into a custom list, did not work.

      DNS Resolver is enabled.
      I'm on pfSense 2.4.4-RELEASE-p3 and pfBlockerNG 2.1.4_17.

      provelsP 1 Reply Last reply Reply Quote 0
      • provelsP
        provels @William Barni
        last edited by

        @William-Barni Try this:
        https://docs.netgate.com/pfsense/en/latest/dns/redirecting-all-dns-requests-to-pfsense.html
        But if your phones are using their data plan instead of your WiFi, you're SOL.

        Peder

        MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
        BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

        1 Reply Last reply Reply Quote 0
        • W
          William Barni
          last edited by

          They are connected via the WiFi, without any data enabled but the WiFi and the WiFi routers are on bridge mode.

          1 Reply Last reply Reply Quote 0
          • pfSenseTestP
            pfSenseTest
            last edited by

            You didn't say, but depending on the mobile phone it could be this...
            https://forum.netgate.com/topic/135832/quad9-dns-over-tls-setup-with-unbound-forwarding-in-2-4-4-rc/2
            Phones could be using TLS via port 853 for DNS

            2x SG-5100 | MBT-4220 (retired) | SG-1000 (retired)

            W 1 Reply Last reply Reply Quote 1
            • W
              William Barni @pfSenseTest
              last edited by

              @pfSenseTest Added the firewall rules mentioned in the link (I already had added the DNS, and now I added the TLSDNS ones) and in the mobile the youtube is blocked when accesing via browser but the app still works perfectly fine.

              Several mobile phones, all the same behavior. iOS 10, 11 and 12. Android 6, 7 and 8.

              pfSenseTestP 1 Reply Last reply Reply Quote 0
              • provelsP
                provels
                last edited by

                Probably need to pick one of these phone's IPs and create a rule to log everything for that IP.

                Peder

                MAIN - pfSense+ 24.11-RELEASE - Adlink MXE-5401, i7, 16 GB RAM, 64 GB SSD. 500 GB HDD for SyslogNG
                BACKUP - pfSense+ 23.01-RELEASE - Hyper-V Virtual Machine, Gen 1, 2 v-CPUs, 3 GB RAM, 8GB VHDX (Dynamic)

                1 Reply Last reply Reply Quote 0
                • pfSenseTestP
                  pfSenseTest @William Barni
                  last edited by

                  @William-Barni said in pfSense pfBlocker and mobile phones apps:

                  blocked when accesing via browser but the app still works perfectly fine.

                  web browser vs dedicated app are 2 different things.

                  https://www.netgate.com/blog/application-detection-on-pfsense-software.html

                  https://docs.netgate.com/pfsense/en/latest/ids-ips/setup-snort-package.html

                  2x SG-5100 | MBT-4220 (retired) | SG-1000 (retired)

                  W 1 Reply Last reply Reply Quote 1
                  • W
                    William Barni @pfSenseTest
                    last edited by

                    @pfSenseTest Hum... ok. Thanks for the answer.

                    I need to learn a ton of new tools and to develop rules for them, understand their behavior, just to block youtube.

                    bmeeksB 1 Reply Last reply Reply Quote 0
                    • bmeeksB
                      bmeeks @William Barni
                      last edited by bmeeks

                      @William-Barni said in pfSense pfBlocker and mobile phones apps:

                      @pfSenseTest Hum... ok. Thanks for the answer.

                      I need to learn a ton of new tools and to develop rules for them, understand their behavior, just to block youtube.

                      YouTube does not want to be blocked ... 😉 . So they make sure it is somewhere between difficult and impossible to block their traffic. Google has gotta have that ad revenue you know ... 😀 .

                      1 Reply Last reply Reply Quote 0
                      • First post
                        Last post
                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.