Parental control nad AD blocking, will it ever happen ?

Started by mucflyer, May 31, 2018, 06:27:55 PM

Previous topic - Next topic
Hi All
OPNSense looks cool, very promising. Only two things I'm really missing. AD Blocking realized easy way, implementing black list, without playing with proxy, rules etc.
And second, even more important - parental control. I would like to limit Internet usage for example 4 hours per day. And disable network between let's say 8PM and 6AM.

Will it even be possible ?

you can use firewall schedules to make a rule only available at certain time ranges - no problem. But what's the problem with the proxy? It's working pretty well.

Not sure right now, I think I was struggling with transparent proxy and https. Due to, no option to install replacement certificate on local machines. And mobile phones. But maybe I will come back to opnsense trying this again. pfblockerng is easier and works for both http and https without additional work on local machines.


This looks indeed good.
Any chance, to have Internet budget in the future (to allow, lets say, only 4 hours / PC / day).

Quote from: franco on June 01, 2018, 08:14:20 AM
> Parental control nad AD blocking, will it ever happen ?

It happened.

https://docs.opnsense.org/manual/how-tos/proxywebfilter.html


Cheers,
Franco

Correct me if I'm wrong, but this will restrict access for all devices. This is definitely not parental control. Parental control means implementing access restrictions based on MAC address and, ideally, different rules for each MAC. I have two kids, 7 yro and 14 yro. I definitely can't apply the same restrictions to both. And I don't want any restrictions for me and my wife. And that's only part one of parental control is. The second part is internet budget.

you probably want to use a user based acl which the proxy is capable to handle. I am just not sure if that works via the GUI.

I'm using a simple add blocker as described here. I edited the list slightly as my wife finds the google add links are sometimes useful, especially when shopping. :)


https://devinstechblog.com/



OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member

Quick note on my message above, if you do edit the list, remember to restart Unbound and you may also need to do a flushdns on your devices.
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member

Quote from: marjohn56 on June 07, 2018, 07:02:59 PM
I'm using a simple add blocker as described here. I edited the list slightly as my wife finds the google add links are sometimes useful, especially when shopping. :)


https://devinstechblog.com/

How is this linked to a specific MAC?

Quote from: fabian on June 07, 2018, 06:03:11 PM
you probably want to use a user based acl which the proxy is capable to handle. I am just not sure if that works via the GUI.

Yeah, good luck with that on Android. I can enter a proxy and a port, but that's as far as it goes. No user/pass there. But that would be the wrong approach anyway. The norm is transparent proxy with MAC based restrictions.

Quote from: mdcclxv on June 07, 2018, 08:02:54 PM
Quote from: marjohn56 on June 07, 2018, 07:02:59 PM
I'm using a simple add blocker as described here. I edited the list slightly as my wife finds the google add links are sometimes useful, especially when shopping. :)


https://devinstechblog.com/

How is this linked to a specific MAC?


It's not, I missed your bit about the mac address.
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member

Imho it must be a mix of captive portal with currently Missing limit per user and something like opendns family shield.

June 08, 2018, 02:43:06 PM #13 Last Edit: June 08, 2018, 03:02:15 PM by marjohn56
Or MAC filtering on a schedule or a VLAN on a schedule. Fixed IP and no dhcp on the VLAN.


Forgot to add the MAC address filtering is pretty easy to bypass.
OPNsense 24.7 - Qotom Q355G4 - ISP - Squirrel 1Gbps.

Team Rebellion Member

I guess that for your kids an approach based on "hotel" setup, using vouchers, would be a better fit, at least for internet time budgeting.

For the web filtering, I would set a static lease for each PC so that I'd be sure the PCs would always have the same IP, and set appropriate filtering in proxy for each IP, accordingly and respectively. Of course, your kids should not have admin rights on their PC logon users (to not be able to manually change the IP on PCs).