OPNsense Forum

English Forums => Tutorials and FAQs => Topic started by: Pranjal on October 03, 2019, 11:21:59 AM

Title: Domain blocking
Post by: Pranjal on October 03, 2019, 11:21:59 AM
Can any one tell me how to block domain in opnsesne
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 12:13:14 PM
There is any one who can help me out please.

I want to block Twitter and other social sites also..please guide me how I can do it
Title: Re: Domain blocking
Post by: mimugmail on October 03, 2019, 12:19:57 PM
IPS App detection Rules
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 12:25:14 PM
I m not getting you please tell me method step by step...I want block social sites
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 12:28:07 PM

Firewall -> Aliases -> All

Add new alias

Name: facebook
Description: Social Network 1
Type: Host(s)
Host(s): www.facebook.com

And add other line in the same rule

Name: facebook
Description: Social Network 1
Type: Host(s)
Host(s): es-la.facebook.com

Save

Now add a new firewall rule

Firewall -> Rules -> LAN -> add new rule

Action: Block
Protocol: TCP/UDP
Destination: facebook
Description: Social Network 1

Save


I tried this one for Twitter also....but sometimes firewall block it and sometimes it get opened . What I m missing please tell
Title: Re: Domain blocking
Post by: mimugmail on October 03, 2019, 01:18:43 PM
No, go to Services : Intrusion Detection, enable IPS mode, set LAN interface, Download App detection rules, go to rules tab, search for Twitter and enable and set to drop
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 01:45:50 PM
Thanks it's working
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 01:55:16 PM
Can you please tell me how to block through certificate.
Title: Re: Domain blocking
Post by: Pranjal on October 03, 2019, 02:09:50 PM
There is one problem with IPS mode .

Can you tell me how to block Amazon type websites in IPS mode.

Which rule I have to download for Amazon
Title: Re: Domain blocking
Post by: mimugmail on October 03, 2019, 04:21:29 PM
If you cant find there is none yet