Howto to block all traffic to the internet except 5 web address

  • Can I block all traffic except for 5 web address.  I need to block all internet access.

  • Yes.

    You'd want to block all outbound access from the LAN (to the WAN) by default. Then you'll need to install a proxy server (such as Squid - see the Packages section of the forum) and configure it to allow only those 5 domains. Your firewall rules will need to allow access from the LAN to the pfSense LAN interface (you can optionally lock this down to just the required services).

    The simplest way of doing that will be to create a new rule allowing traffic with the source of the LAN subnet and a destination of the LAN interface, then disable the default allow all rule. At that point no host on the LAN will be able to directly reach the Internet. You'll need to create additional rules to allow any other required services.