Is blocking youtube really this hard?!



  • I am going mad trying to come up with a solution that blocks youtube and youtube only.  ??? ??? ???

    Running 2.01 + Squid + Squidguard.

    I have tried getting squidguard to block it with no luck, although I have a blacklist working for other sites no problem. 
    I have tried using an FQDN alias and blocking it by rule, but that causes maps.google.com, news.google.com and others to be blocked also.

    What else can I try?



  • @ckuecker:

    What else can I try?

    Try Untangle in bridge mode.

    That is what I did.  It has nicely packaged solutions for everything you want to block and gives you unreal amount of info of what is running through your firewall.

    I used both pfs and Ut  over the last two plus years and recently decided I needed both.

    I love the firewall functionality of pfs but the packages were too unpolished or not available for the current version.

    And that is the void that UT filled in but sure, with added complexity and another device sitting in your network.



  • In the ACL of Squid (I don't know about squidguard as I don't currently use it), in the blacklist, put .*youtube.com. This should be able to block any host that uses youtube.com in the domain. I don't think you will be able to block if using direct IP with any firewall unless you already know the IPs associated with youtube.



  • @podilarius:

    In the ACL of Squid (I don't know about squidguard as I don't currently use it), in the blacklist, put .*youtube.com. This should be able to block any host that uses youtube.com in the domain. I don't think you will be able to block if using direct IP with any firewall unless you already know the IPs associated with youtube.

    Thanks for this.  I will try this if SG stops working again.

    The other day SG started blocking it again and has been ever since.



  • There's another one to  block, something like ytimg.com



  • I would think snort gives you the flexibility of blocking youtube both IP and domain name. Your biggest problem is the unbelievable amount of CDNs there are for youtube. Pepole could get around you with embeded youtube videos.


Locked