Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Blocking WeChat and TikTok

    pfBlockerNG
    9
    15
    899
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • G
      goldkeeper last edited by

      Hi, total pfSense noob here; posted this on the Firewall forum and was suggested to post here. Can anyone tell me how to block WeChat and TikTok?

      NogBadTheBad 1 Reply Last reply Reply Quote 0
      • NogBadTheBad
        NogBadTheBad @goldkeeper last edited by

        @goldkeeper Use pfBlocker and create a geoip alias and use it on a block outbound rule.

        You could use their ASN numbers if they host everything in their address space.

        Loads of posts here regarding pfBlocker.

        Andy

        1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

        NogBadTheBad 1 Reply Last reply Reply Quote 1
        • NogBadTheBad
          NogBadTheBad @NogBadTheBad last edited by NogBadTheBad

          WeChat AS131628
          TikTok AS138699

          Andy

          1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

          C 1 Reply Last reply Reply Quote 2
          • G
            Gblenn last edited by Gblenn

            I have been running PiHole for a long time even though I still use pfBlocker. Mainly because I like the interface and the reporting. But I recently decided to switch over to AdGuard Home (on separate server - not as plugin).
            It does pretty much the same thing as PiHole but has a simple function for this specific purpose.
            In the "Blocked Services" menu, there's a list of some 45 well known predefined applications, including WeChat and TikTok. You simply "throw a switch" for each of the applications you want to block...

            1 Reply Last reply Reply Quote 1
            • G
              goldkeeper last edited by

              Thank you for the advice! Is it possible to block only for a specific user/device?

              1 Reply Last reply Reply Quote 0
              • Cool_Corona
                Cool_Corona last edited by

                Doesnt work...

                I have facebook blocked via ASN and it works like a charm for everybody.

                1 Reply Last reply Reply Quote 0
                • M
                  michmoor last edited by

                  someone mentioned adguard which is what i use at home for a particular vlan. everyone else uses pfblocker. But in theory i could just use pfblocker and do dns blocking, no? same purpose here? why cant we just do that?

                  Firewall: NetGate 6100/7100U, Palo Alto
                  Routing: Juniper MX204 , Arista 7050X3
                  Switching: Juniper EX/QFX. Arista 7050SX
                  Wireless: Unifi, Aruba IAP

                  G 1 Reply Last reply Reply Quote 0
                  • G
                    Gblenn @michmoor last edited by Gblenn

                    @michmoor Off course you can do it with pfBlocker. Same purpose and same method of doing dns blocking.
                    It's just that AdGuard have already taken the ASN's for the most popular Apps and converted them into a nice human friendly interface with icons, app name and a toggle switch for each.
                    Extremely quick and intuitive, vs doing it yourself...

                    @goldkeeper said in Blocking WeChat and TikTok:

                    Thank you for the advice! Is it possible to block only for a specific user/device?

                    No you can't at least not at the moment.

                    johnpoz 1 Reply Last reply Reply Quote 0
                    • johnpoz
                      johnpoz LAYER 8 Global Moderator @Gblenn last edited by

                      @gblenn said in Blocking WeChat and TikTok:

                      No you can't at least not at the moment.

                      Not sure where you got that info, I am not a user of adguard - but clearly the docs show you can do per device configuration.

                      setup.jpg

                      https://github.com/AdguardTeam/AdGuardHome#getting-started

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 23.01 | Lab VMs CE 2.6, 2.7

                      G 1 Reply Last reply Reply Quote 0
                      • G
                        Gblenn @johnpoz last edited by Gblenn

                        @johnpoz I wouldn't necessarily take that listing as proof, as it basically means that you can configure many of the listed items on a per client basis. Which upstream DNS servers to use, whether or not to use AdGuards parental control, the their Safe search or browsing security features.

                        BUT, having said that, I'm glad you made me check again, because they have actually implemented this specific function as well!! There is in fact a tab where you get the same nice UI to select from the list of apps to block, or simply use the global blocking list...

                        So yes it is possible!!

                        1 Reply Last reply Reply Quote 0
                        • Referenced by  Alejo 0 Alejo 0 
                        • V
                          viviantmccormick Banned last edited by

                          This post is deleted!
                          1 Reply Last reply Reply Quote 0
                          • C
                            ciroque @NogBadTheBad last edited by

                            @nogbadthebad

                            I have attempted to get this working, but going to tiktok.com still loads. I am missing something basic I know...

                            Appreciate any guidance!

                            pfBlockerNG Alias definition:
                            65c8f6bb-79a3-4819-b712-ebd6e471482d-image.png

                            LAN Ruleset (redacted):
                            f2b77a8d-9b8f-498f-a4f6-537bc94865bf-image.png

                            Thanks,
                            Steve

                            M NogBadTheBad V 3 Replies Last reply Reply Quote 0
                            • M
                              michmoor @ciroque last edited by

                              @ciroque Wouldnt it be easier to either

                              1. spin up adguarddns and block tiktop app
                              2. spin up pi-hole and block tiktop app
                              3. forward traffic to opendns or nextdns and block tiktop app

                              just a suggerstion.

                              Firewall: NetGate 6100/7100U, Palo Alto
                              Routing: Juniper MX204 , Arista 7050X3
                              Switching: Juniper EX/QFX. Arista 7050SX
                              Wireless: Unifi, Aruba IAP

                              1 Reply Last reply Reply Quote 0
                              • NogBadTheBad
                                NogBadTheBad @ciroque last edited by

                                @ciroque Maybe your web browser is doing DNS over HTTP.

                                Tried killing the firewall states ?

                                Andy

                                1 x Netgate SG-4860 - 3 x Linksys LGS308P - 1 x Aruba InstantOn AP22

                                1 Reply Last reply Reply Quote 0
                                • V
                                  Vollans @ciroque last edited by

                                  @ciroque said in Blocking WeChat and TikTok:

                                  I have attempted to get this working, but going to tiktok.com still loads.

                                  Don't suppose your ISP gives you a dual stack IPv4 and IPv6 address range? The shots you show block IPv4, but wouldn't block any IPv6 TikTok addresses.

                                  1 Reply Last reply Reply Quote 0
                                  • First post
                                    Last post