<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Sites still available even with dnsbl]]></title><description><![CDATA[<p dir="auto">I'm trying to block social media and video sites for the kiddos.</p>
<p dir="auto">I've tried using pfblockerng categories, and explicitly defining DNS entries for specific sites ( with the categories disabled ) pointing to 10.10.10.1.</p>
<p dir="auto">For some reason I don't understand a handful of specific sites still make it though with the DNS filtering enabled.</p>
<p dir="auto">Nslookup shows my blocking address on any sites I'm trying to block, but certain large sites (tiktok, Facebook and reddit especially) still load. What am I doing wrong here?</p>
]]></description><link>https://forum.netgate.com/topic/163347/sites-still-available-even-with-dnsbl</link><generator>RSS for Node</generator><lastBuildDate>Thu, 12 Mar 2026 19:23:13 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/163347.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 28 Apr 2021 03:10:44 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Sites still available even with dnsbl on Sun, 02 May 2021 00:57:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/nollipfsense">@<bdi>nollipfsense</bdi></a> I saved and reloaded the changes. Im getting the correct 10.10.10.1 address when I attempt dns lookups. Thanks though.</p>
]]></description><link>https://forum.netgate.com/post/980902</link><guid isPermaLink="true">https://forum.netgate.com/post/980902</guid><dc:creator><![CDATA[timbrigham]]></dc:creator><pubDate>Sun, 02 May 2021 00:57:06 GMT</pubDate></item><item><title><![CDATA[Reply to Sites still available even with dnsbl on Sat, 01 May 2021 21:40:56 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/timbrigham">@<bdi>timbrigham</bdi></a> Not sure whether you're still checking your thread; however, you never mentioned saving the changes you had made, then updating and reload pfBlockerNG (data base).</p>
]]></description><link>https://forum.netgate.com/post/980893</link><guid isPermaLink="true">https://forum.netgate.com/post/980893</guid><dc:creator><![CDATA[NollipfSense]]></dc:creator><pubDate>Sat, 01 May 2021 21:40:56 GMT</pubDate></item><item><title><![CDATA[Reply to Sites still available even with dnsbl on Wed, 28 Apr 2021 05:24:16 GMT]]></title><description><![CDATA[<p dir="auto">I'm certainly no expert on pfblockerng, as I haven't had to work a content filter or anything for a good 10 years or so...but if I go to tiktok and press F12 I see all kinds of junk like the following:<br />
sf16-scmcdn-va.ibytedos.com/goofy/tiktok/blahblahblah<br />
mcs-va.tiktokv.com<br />
mon-va.byteoversea.com</p>
<p dir="auto">It might say tiktok in the url; but everything inside is coming out of a giant content delivery network. If all the blocker redirects is the 'name brand' webpage; 99.9% of the content might load just fine, especially with side loading bullcrap that isn't using the normal web front end.  Applications on phones and stuff will frequently bypass the front end entirely and rely on the CDN.</p>
<p dir="auto">When I pull up the simple facebook login page I get a million of these:<br />
static.xx.fbcdn.net<br />
scontent.fapa1-1.fna.fbcdn.net</p>
<p dir="auto">Similar story with reddit being full of:<br />
www.redditstatic.com<br />
v.redd.it<br />
preview.redd.it<br />
i.redd.it</p>
<p dir="auto">You owe me two bits for making me load tiktok.  I watched 4 videos...I am dumber.</p>
]]></description><link>https://forum.netgate.com/post/980252</link><guid isPermaLink="true">https://forum.netgate.com/post/980252</guid><dc:creator><![CDATA[skogs]]></dc:creator><pubDate>Wed, 28 Apr 2021 05:24:16 GMT</pubDate></item></channel></rss>