OPNsense
  • Home
  • Help
  • Search
  • Login
  • Register

  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • default block all; allow whitelist
« previous next »
  • Print
Pages: [1]

Author Topic: default block all; allow whitelist  (Read 14629 times)

godfather007

  • Newbie
  • *
  • Posts: 28
  • Karma: 1
    • View Profile
default block all; allow whitelist
« on: March 11, 2018, 11:20:55 am »
Hi,

looking into webproxy to whitelist access to windowsupdate.com etc. for certain IP's.

Tried to allocate "*.*, 0.0.0.0/0.0.0.0"  to the blacklist but it only accepts single entries thus far: "meuk.com".

Is it possible through the GUI or should i create squid ACL lists at shell level?


Thanks
Logged

godfather007

  • Newbie
  • *
  • Posts: 28
  • Karma: 1
    • View Profile
Re: default block all; allow whitelist
« Reply #1 on: March 12, 2018, 08:52:47 am »
For the record,

i would like to block all and allow *.windowsupdates.com etc.

Thanks
Logged

jrmagots

  • Newbie
  • *
  • Posts: 2
  • Karma: 0
    • View Profile
Re: default block all; allow whitelist
« Reply #2 on: August 14, 2018, 02:20:40 pm »
I'm looking for an option like these too
Logged

nospam

  • Newbie
  • *
  • Posts: 29
  • Karma: 0
    • View Profile
Re: default block all; allow whitelist
« Reply #3 on: September 13, 2018, 02:28:58 pm »
Why not just create a firewall rule allowing only LAN net to LAN net and LAN net to your desired WAN IP ranges?
Logged

tomclewes

  • Newbie
  • *
  • Posts: 12
  • Karma: 0
    • View Profile
Re: default block all; allow whitelist
« Reply #4 on: November 14, 2020, 06:28:53 pm »
I'm also looking for an answer to this and can't find one.
Logged

Amr

  • Jr. Member
  • **
  • Posts: 71
  • Karma: 2
    • View Profile
Re: default block all; allow whitelist
« Reply #5 on: November 16, 2020, 01:30:24 pm »
For the "block all" of the question you have three approaches:

1-From the GUI, Go to access control list and add all the TLD you can think of in the blacklist  EX: .com, .net ...etc
you can also add The following Regex expression to block all TLDs :  .[a-zA-Z]+
2-Add "http_access deny all" line in "/usr/local/etc/squid/squid.conf" file after "http_access deny blacklist" (Changes in squid.conf gets overwritten after updates)
3-Write a custom squid acl and put it in pre-auth.


You can reference these posts to see how to use custom ACL :
https://forum.opnsense.org/index.php?topic=16171.msg73968#msg73968
https://forum.opnsense.org/index.php?topic=6516.0

Quote
Why not just create a firewall rule allowing only LAN net to LAN net and LAN net to your desired WAN IP ranges?
nospam got a point, fetching windows updates through the proxy is problametic , Creating firewall rules would be easier , and if possible consider a WSUS if you want to save bandwidth.
« Last Edit: January 11, 2021, 07:28:26 am by Amr »
Logged
Disclaimer: I'm not a professional, just trying to help.

juliocbc

  • Sr. Member
  • ****
  • Posts: 264
  • Karma: 11
    • View Profile
    • Cloudfence
Re: default block all; allow whitelist
« Reply #6 on: November 21, 2020, 02:52:22 pm »
Hello!

Not official plugin (based on squidguard) that can help you with that:

https://wiki.cloudfence.com.br/english/managing-rules (Take a look in the Rule Action).

Hope it helps!

Logged
Cloudfence Open Source Team

  • Print
Pages: [1]
« previous next »
  • OPNsense Forum »
  • English Forums »
  • Web Proxy Filtering and Caching (Moderator: fabian) »
  • default block all; allow whitelist
 

OPNsense is an OSS project © Deciso B.V. 2015 - 2023 All rights reserved
  • SMF 2.0.19 | SMF © 2021, Simple Machines
    Privacy Policy
    | XHTML | RSS | WAP2