OPNsense Forum

English Forums => Zenarmor (Sensei) => Topic started by: eponymous on February 20, 2022, 07:22:41 PM

Title: Blocking iCloud private relay?
Post by: eponymous on February 20, 2022, 07:22:41 PM
Hi,

I've noticed that turning on iCloud private relay allows you to bypass pretty much any blocking that Zenarmor is doing.

Is there any way to block private relay using Zenarmor?

Thanks.
Title: Re: Blocking iCloud private relay?
Post by: athurdent on February 20, 2022, 07:26:40 PM
Here is what I did:
https://docs.opnsense.org/manual/unbound.html#advanced-configurations
Using this:

server:
local-zone: "mask.icloud.com" static
local-zone: "mask-h2.icloud.com" static

Apple document:
https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay
Title: Re: Blocking iCloud private relay?
Post by: Mundan101 on February 21, 2022, 02:48:37 AM
if you look under policy, app control, proxy....you will see icloud private rely.

block that you should be good.



Quote from: athurdent on February 20, 2022, 07:26:40 PM
Here is what I did:
https://docs.opnsense.org/manual/unbound.html#advanced-configurations
Using this:

server:
local-zone: "mask.icloud.com" static
local-zone: "mask-h2.icloud.com" static

Apple document:
https://developer.apple.com/support/prepare-your-network-for-icloud-private-relay
Title: Re: Blocking iCloud private relay?
Post by: sy on June 22, 2023, 05:39:39 AM
Hi,

It is also possible with Zenarmor by blocking iCloud Private Relay in App Controls - Proxy.