• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Blocking everything except...

General pfSense Questions
block all whitelist
4
9
1.1k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O
    Oceanwatcher
    last edited by Nov 22, 2019, 9:14 PM

    I have a customer that needs to block everything except a few domains.

    So they basically would like to have some whitelisted domains, and the problem of course is that some of these are using a CDN or otherwise use multiple IP addresses.

    I am assuming this is a job for squid? Or do you have any better suggestions? What is the best way of getting this done?

    This block has to happen for all traffic from a specific VLAN. Other VLAN's should not be affected.

    Regards,

    Oceanwatcher
    2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

    1 Reply Last reply Reply Quote 0
    • M
      mare
      last edited by Nov 22, 2019, 9:41 PM

      Perhapse more pfBlockerNG than Squid. It blocks using DNS Resolver service.

      O 1 Reply Last reply Nov 25, 2019, 7:24 PM Reply Quote 0
      • S
        stephenw10 Netgate Administrator
        last edited by Nov 23, 2019, 3:08 PM

        Usually when people ask this they don't really understand what they're asking for. Any site that has a large CDN probably pulls data fro numerous domains to work correctly. Allowing, for example, only *.gmail.com to resolve is not going to end well. 😉

        Steve

        O 1 Reply Last reply Nov 25, 2019, 7:20 PM Reply Quote 0
        • O
          Oceanwatcher @stephenw10
          last edited by Oceanwatcher Nov 25, 2019, 7:21 PM Nov 25, 2019, 7:20 PM

          @stephenw10
          Thank you for taking the time to answer. Although, I do not fully understand your answer.

          Was it a hint that I do not understand what I am asking for? Or is it something you wanted me to pass on to my customer? 😉

          Please help me understand how your answer will help me come up with a solution 😉 😉

          Regards,

          Oceanwatcher
          2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

          1 Reply Last reply Reply Quote 0
          • O
            Oceanwatcher @mare
            last edited by Nov 25, 2019, 7:24 PM

            @mare Great. Thank you. Will take my question over to the sub forum for pfBlockerNG.

            Regards,

            Oceanwatcher
            2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

            1 Reply Last reply Reply Quote 0
            • S
              stephenw10 Netgate Administrator
              last edited by Nov 25, 2019, 9:02 PM

              I'm saying what the customer is asking for is probably more complex than they think.
              "Just a few domains" is probably just a few sites which could be a large number of domains and also a moving target.
              It might not be...

              Steve

              O 1 Reply Last reply Nov 28, 2019, 2:34 PM Reply Quote 0
              • N
                NollipfSense
                last edited by Nov 27, 2019, 1:46 AM

                The same person asked the same question here: https://forum.netgate.com/topic/148392/blocking-everything-except

                They got a response yet never followed up...that leads me to conclude that OP isn't sure what the alleged customer wants.

                pfSense+ 23.09 Lenovo Thinkcentre M93P SFF Quadcore i7 dual Raid-ZFS 128GB-SSD 32GB-RAM PCI-Intel i350-t4 NIC, -Intel QAT 8950.
                pfSense+ 23.09 VM-Proxmox, Dell Precision Xeon-W2155 Nvme 500GB-ZFS 128GB-RAM PCIe-Intel i350-t4, Intel QAT-8950, P-cloud.

                O 1 Reply Last reply Nov 27, 2019, 9:52 PM Reply Quote 0
                • O
                  Oceanwatcher @NollipfSense
                  last edited by Nov 27, 2019, 9:52 PM

                  @NollipfSense Please read this whole thread before making any judgement 😉

                  Regards,

                  Oceanwatcher
                  2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

                  1 Reply Last reply Reply Quote 0
                  • O
                    Oceanwatcher @stephenw10
                    last edited by Nov 28, 2019, 2:34 PM

                    @stephenw10 said in Blocking everything except...:

                    It might not be...

                    That is correct 😉

                    Regards,

                    Oceanwatcher
                    2x SuperMicro 8core w/ 8 GB RAM running v. 2.3.1 - will eventually set them up with failover

                    1 Reply Last reply Reply Quote 0
                    8 out of 9
                    • First post
                      8/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.