Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Block google chat

    Scheduled Pinned Locked Moved Firewalling
    14 Posts 4 Posters 2.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • C
      catey03
      last edited by

      Hello again,

      Is it possible to disable google chat in pfSense but still have a google search enable? I tried to block talkgadget.google.com, chatenabled.mail.google.com, talk.google.com,  and talkx.l.google.com using DNS forwarder but still no luck and also tried to block port 5222. Please advice.

      Thank you!

      1 Reply Last reply Reply Quote 0
      • KOMK
        KOM
        last edited by

        If you have those domains properly overridden then they should resolve to localhost.  Are you sure your clients aren't using their own DNS?  Proxy?  VPN?

        1 Reply Last reply Reply Quote 0
        • C
          catey03
          last edited by

          This is currently what's in my DNS forwarder and block port 5222 from LAN. Is this correct or am I missing something?

          DNS.jpg
          DNS.jpg_thumb

          1 Reply Last reply Reply Quote 0
          • KOMK
            KOM
            last edited by

            You have a host of www for all entries.  Do you know for sure that your clients are resolving www.talk.google.com, for example, and not just talk.google.com?

            Best practice is to put all your block rules at the top, btw.

            1 Reply Last reply Reply Quote 0
            • C
              catey03
              last edited by

              Should I put http and https on the host? Mine is using https://talkgadget.google.com. Thanks

              1 Reply Last reply Reply Quote 0
              • DerelictD
                Derelict LAYER 8 Netgate
                last edited by

                No.  That happens after DNS is resolved.

                In that example just put talkgadget as the host and google.com as the domain.

                Chattanooga, Tennessee, USA
                A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                Do Not Chat For Help! NO_WAN_EGRESS(TM)

                1 Reply Last reply Reply Quote 0
                • C
                  catey03
                  last edited by

                  I got it working I think. Chat in gmail is showing this error "We're having trouble connecting to Google. We'll keep trying…"  :D Thank you so much..

                  Can I also allow selected users to have access to gtalk?

                  1 Reply Last reply Reply Quote 0
                  • KOMK
                    KOM
                    last edited by

                    If you let select users use alternate DNS, then they could access the service.

                    1 Reply Last reply Reply Quote 0
                    • C
                      catey03
                      last edited by

                      Can you walk me through on how to do that?  :)

                      1 Reply Last reply Reply Quote 0
                      • KOMK
                        KOM
                        last edited by

                        Create an alias that holds your special users.  Add a firewall rule just above your DNS block rule that allows that alias to pass port 53 traffic.  Then configure their network DNS clients to also use Google or OpenDNS.  I've never had to do this before so I'm guessing my way through.

                        1 Reply Last reply Reply Quote 0
                        • C
                          catey03
                          last edited by

                          @KOM You're a genius! It works perfectly. Thank you!

                          1 Reply Last reply Reply Quote 0
                          • KOMK
                            KOM
                            last edited by

                            @KOM You're a genius!

                            More like a stopped clock is right twice per day  ;D

                            1 Reply Last reply Reply Quote 0
                            • S
                              souciss
                              last edited by

                              I think couldn't. At least I have never succeeded. . .. :(

                              1 Reply Last reply Reply Quote 0
                              • S
                                souciss
                                last edited by

                                Maybe I was wrong, one of my friends have done it.


                                coquebox
                                etui Samsung Galaxy A5

                                1 Reply Last reply Reply Quote 0
                                • First post
                                  Last post
                                Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.