Youtube Blocking in pfblocker via IP
-
Hi everyone,
Im using pfBlockerNG/IP/IPv4 to block websites and add the website IP to IPv4 Custom_List to block website.
But when im blocking youtube, the rule I created. The pfsense automatically include our ISP(please see attach img), so if the rule is active we can't use our internet.
Any suggestion? appreciate your help.
-
The file used, 'pfB_Blocked_YT_v4', can be found (afaik) here /var/db/aliastables/
Does that file include your WAN IP ?Not a real solution, more a workaround : what about a pass rule you create and place just above this pfB block rule so that it your WAN IP ?
Btw : Youtube uses 2000+ IPv4's. So, this week, the set you've listed is activate, it will change (all the time) in a couple of days/weeks/months. Blocking the big players is (Microsoft, facebook, apple, google, etc) is close to mission impossible as they have hired all the greatest network administrators to make your live harder. Worse, block those sites and your network guests will just leave your network (and start dealing with SIM cards ^^).
What will work is blocking all IPs that alphabet owns = block their ASN and then nothing will work anymore. Including www.google.com etc. -
@antgalla We tried blocking YouTube for my son via ASN but could not get it to consistently block. We ended up using a View in unbound. To block for everyone you could set a domain override to nowhere. Remember to block DoH/DoT to force devices to use pfSense for DNS.
-
@Gertjan
The file used, 'pfB_Blocked_YT_v4', can be found (afaik) here /var/db/aliastables/ - its working after I edit the file via vi!
But when I reload the pfblockerNG/IP the problem returns -
@SteveITS
I need to block website with specific device only. I can't used domain overrides because its blocking all devices. -
@antgalla I have excellent news for you. :) In DNS Resolver settings try:
-
@SteveITS
Niceee, I will try it later! Can I put alias instead of IP? -
@antgalla said in Youtube Blocking in pfblocker via IP:
@SteveITS
Niceee, I will try it later! Can I put alias instead of IP?Itβs raw unbound config so I doubt it knows about pfSense aliases.