Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to block facebook in 4 ways

    Scheduled Pinned Locked Moved Firewalling
    20 Posts 11 Posters 24.6k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • J Offline
      jigpe
      last edited by

      Hi pFSerians! Good afternoon! :)

      How-to block facebook in 4 ways:

      1st: Get the CIDR of facebook using the domain_whois_tool
                     - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

      2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

      3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

      4th : Install SQUID and block facebook.com there.

      I hope im posting it in a right folder discussion..

      Hope it help all pFSerians!

      Thanks to codemarauder for the additional CIDR :) More beers later man :)

      jigp

      1 Reply Last reply Reply Quote 0
      • J Offline
        jigpe
        last edited by

        Of course you can add some exemption to certain ips. :)

        Do this: Proto:TCP > Source: Lan IP > Destination: fbips > Port: fbports

        jigp

        1 Reply Last reply Reply Quote 0
        • N Offline
          Nachtfalke
          last edited by

          If you are blocking all IPs by firewall rules why do you use squid in addition ?

          1 Reply Last reply Reply Quote 0
          • J Offline
            jigpe
            last edited by

            If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.

            1 Reply Last reply Reply Quote 0
            • J Offline
              jigpe
              last edited by

              @jigpe:

              If you have no squid you cant block facebook.com. Ive tried it. Unless there's another way around? But all work for me here.
              In my case, i have exemptions so i really need squid.

              1 Reply Last reply Reply Quote 0
              • S Offline
                syedadi
                last edited by

                @jigpe:

                Hi pFSerians! Good afternoon! :)

                How-to block facebook in 4 ways:

                1st: Get the CIDR of facebook using the domain_whois_tool
                               - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

                2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

                4th : Install SQUID and block facebook.com there.

                I hope im posting it in a right folder discussion..

                Hope it help all pFSerians!

                Thanks to codemarauder for the additional CIDR :) More beers later man :)

                jigp

                Can you give me the link for the CIDR info?

                1 Reply Last reply Reply Quote 0
                • M Offline
                  Metu69salemi
                  last edited by

                  @syedadi:

                  @jigpe:

                  Hi pFSerians! Good afternoon! :)

                  How-to block facebook in 4 ways:

                  1st: Get the CIDR of facebook using the domain_whois_tool
                                 - OR use my Aliases CIDR http://imageshack.us/f/193/cidr.png

                  2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                  3rd:  Create a firewall rule in LAN > Action is Reject > TCP as proto > DESTINATION is my fbips - PORT is my fbports..

                  4th : Install SQUID and block facebook.com there.

                  I hope im posting it in a right folder discussion..

                  Hope it help all pFSerians!

                  Thanks to codemarauder for the additional CIDR :) More beers later man :)

                  jigp

                  Can you give me the link for the CIDR info?

                  First post image?!?

                  1 Reply Last reply Reply Quote 0
                  • J Offline
                    jigpe
                    last edited by

                    Sure. http://imageshack.us/f/193/cidr.png :)

                    1 Reply Last reply Reply Quote 0
                    • T Offline
                      tommyboy180
                      last edited by

                      That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                      -Tom Schaefer
                      SuperMicro 1U 2X Intel pro/1000 Dual Core Intel 2.2 Ghz - 2 Gig RAM

                      Please support pfBlocker | File Browser | Strikeback

                      1 Reply Last reply Reply Quote 0
                      • J Offline
                        johnnybe
                        last edited by

                        @tommyboy180:

                        That's a lot of steps. Just install ipblocklist and use a custom list or http://list.iblocklist.com/?list=ecqbsykllnadihkdirsh&fileformat=p2p&archiveformat=gz

                        Thanks!

                        you would not believe the view up here

                        1 Reply Last reply Reply Quote 0
                        • J Offline
                          jigpe
                          last edited by

                          @tommyboy180

                          Thanks! But in my case i have some exemptions. All users are blocked from accessing fb except me. So im creating a rule to allow it to my IP. And if someone would like to access fb, i will just create a rule to allow the user's IP.

                          jigp

                          1 Reply Last reply Reply Quote 0
                          • P Offline
                            pcbosrders
                            last edited by

                            2nd: Create Aliases, put all CIDR of facebook (i named it fbips as description) and create ports 80/4443 (i named it fbports as description)

                            if you do this and have a webserver are you going to prevent it to access the net?
                            is the port 80 / 443 instead of 80 / 4443
                            want to try this and see if it interferes

                            don't fix it, if ain't broken !!!

                            1 Reply Last reply Reply Quote 0
                            • J Offline
                              jigpe
                              last edited by

                              @pcboarders
                              I have no concern with webserver so i didn't bother to try this.
                              I just want to block facebook and give exemptions to those who want to access facebook,

                              jigp

                              1 Reply Last reply Reply Quote 0
                              • P Offline
                                paoloromano
                                last edited by

                                Masters,

                                What if you have multiwan and failover, will it conflict with squid?
                                I would like to block also other sites and facebook but might encounter unwanted conflict with my multiwan and failover.
                                advise please, thanks!

                                1 Reply Last reply Reply Quote 0
                                • J Offline
                                  jigpe
                                  last edited by

                                  Same rule in MultiWan. Use the firewall rule and select the WAN or whichever is your WAN1 and WAN2.

                                  1 Reply Last reply Reply Quote 0
                                  • K Offline
                                    kornelson
                                    last edited by

                                    Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                    1 Reply Last reply Reply Quote 0
                                    • M Offline
                                      Metu69salemi
                                      last edited by

                                      @kornelson:

                                      Sorry but my english is no good. when i write the url http://www.facebok.com pfsense block the access. but whit secure https://www.facebook.com all people can enter to facebook. i need to block this. Thanks a lot.

                                      How do you block http now? Answer depends greatly your blocking method

                                      1 Reply Last reply Reply Quote 0
                                      • N Offline
                                        NOYB
                                        last edited by

                                        Add Facebook CIDR to bogons data.  :o

                                        1 Reply Last reply Reply Quote 0
                                        • J Offline
                                          jigpe
                                          last edited by

                                          Latest IPs of facebook:

                                          IPV4 IPs:
                                          route:      204.15.20.0/22
                                          route:      69.63.176.0/20
                                          route:      66.220.144.0/20
                                          route:      66.220.144.0/21
                                          route:      69.63.184.0/21
                                          route:      69.63.176.0/21
                                          route:      74.119.76.0/22
                                          route:      69.171.255.0/24
                                          route:      173.252.64.0/18
                                          route:      69.171.224.0/19
                                          route:      69.171.224.0/20
                                          route:      103.4.96.0/22
                                          route:      69.63.176.0/24
                                          route:      173.252.64.0/19
                                          route:      173.252.70.0/24
                                          route:      31.13.64.0/18
                                          route:      31.13.24.0/21
                                          route:      66.220.152.0/21
                                          route:      66.220.159.0/24
                                          route:      69.171.239.0/24
                                          route:      69.171.240.0/20
                                          route:      31.13.64.0/19
                                          route:      31.13.64.0/24
                                          route:      31.13.65.0/24
                                          route:      31.13.67.0/24
                                          route:      31.13.68.0/24
                                          route:      31.13.69.0/24
                                          route:      31.13.70.0/24
                                          route:      31.13.71.0/24
                                          route:      31.13.72.0/24
                                          route:      31.13.73.0/24
                                          route:      31.13.74.0/24
                                          route:      31.13.75.0/24
                                          route:      31.13.76.0/24
                                          route:      31.13.77.0/24
                                          route:      31.13.96.0/19
                                          route:      31.13.66.0/24
                                          route:      173.252.96.0/19
                                          route:      69.63.178.0/24
                                          route:      31.13.78.0/24
                                          route:      31.13.79.0/24
                                          route:      31.13.80.0/24
                                          route:      31.13.82.0/24
                                          route:      31.13.83.0/24
                                          route:      31.13.84.0/24
                                          route:      31.13.85.0/24
                                          route:      31.13.86.0/24
                                          route:      31.13.87.0/24
                                          route:      31.13.88.0/24
                                          route:      31.13.89.0/24
                                          route:      31.13.90.0/24
                                          route:      31.13.91.0/24
                                          route:      31.13.92.0/24
                                          route:      31.13.93.0/24
                                          route:      31.13.94.0/24
                                          route:      31.13.95.0/24
                                          route:      69.171.253.0/24
                                          route:      69.63.186.0/24
                                          route:      204.15.20.0/22
                                          route:      69.63.176.0/20
                                          route:      69.63.176.0/21
                                          route:      69.63.184.0/21
                                          route:      66.220.144.0/20
                                          route:          69.63.176.0/20

                                          IPV6 IPs
                                          route6:    2620:0:1c00::/40
                                          route6:    2a03:2880::/32
                                          route6:    2401:DB00::/32
                                          route6:    2a03:2880:fffe::/48
                                          route6:    2a03:2880:ffff::/48
                                          route6:    2620:0:1cff::/48

                                          Hope this help.
                                          jigp

                                          1 Reply Last reply Reply Quote 0
                                          • C Offline
                                            CrimsonMoon79
                                            last edited by

                                            Yes, this definitely helps a lot, thank you very much.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.