Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Custom block list for specific subnet ?

    Scheduled Pinned Locked Moved pfBlockerNG
    2 Posts 2 Posters 305 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mzeid
      last edited by

      Hello everyone,

      So in case of school where all devices have the default block lists to block porn and ads, but in the computer lab we need to block games websites like poki.com and such

      So i think this breaks down to three points:

      • block list of gaming websites
      • pfblockerng block different lists for specific subnet
      • bypassing one of the IP addresses. This is the teacher's computer, not bypass them to gaming websites but in case I add other block lists to the students but still allow the teacher.

      For the first one I'm still looking for lists, if anybody does know such a list please mention it

      For the 2nd and 3rd I really need help, any help is appreciated.

      Thanks in advance

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG
        Gertjan @mzeid
        last edited by

        @mzeid said in Custom block list for specific subnet ?:

        pfblockerng block different lists for specific subnet

        While adding a new DNSBL feed here Firewal > lpfBlockerNG > DNSBL > DNSBL you can not select "use feeds only on interface LAN & LAN2" or "use feed only on interface LAN2 only", DNSBL feeds (filtering) apply to all interfaces.
        That is, this is valid when the "Python mode" is used.
        A feature request ?

        Btw : the above is 'very AFAIK, of course.
        For a school I would probably consider using a Pi-hole also

        As the DNSB Python filtering script is (I guess) aware of the requester IP, thus the network, thus the interface, it could be capable of 'per interface' filtering.

        In the past, before we were using pfBlockerng, and used handcrafted 'unbound' config rules, here :

        d451e5e1-6886-42ee-b577-9ea9f9d427c8-image.png

        we were able to set up DNSBL files 'per interface' (per network).
        This meant that this one was our guide line.

        @mzeid said in Custom block list for specific subnet ?:

        bypassing one of the IP addresses

        That's the policy group setting :

        e41d7108-7cd8-424e-acd9-d3b82e996bd6-image.png

        and from now on, this devices will bypass DNSBL filtering

        Btw :

        @mzeid said in Custom block list for specific subnet ?:

        teacher's computer

        I'm pretty sure the teacher doesn't mind he can't visit these sites neither ^^

        No "help me" PM's please. Use the forum, the community will thank you.
        Edit : and where are the logs ??

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.