Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 22 Aug 2017 23:58:07 +0100
From:      Frank Shute <frank@woodcruft.co.uk>
To:        Ernie Luzar <luzar722@gmail.com>
Cc:        "freebsd-questions@freebsd.org" <freebsd-questions@freebsd.org>
Subject:   Re: How to block facebook access
Message-ID:  <20170822225807.GA97221@woodcruft.co.uk>
In-Reply-To: <59988180.7020301@gmail.com>
References:  <59988180.7020301@gmail.com>

next in thread | previous in thread | raw e-mail | index | archive | help

--Qxx1br4bt0+wmkIi
Content-Type: text/plain; charset=utf-8
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

On Sat, Aug 19, 2017 at 02:20:48PM -0400, Ernie Luzar wrote:
>
> Hello list;
>=20
> Running 11.1 & ipfilter with LAN behind the gateway server. LAN users=20
> are using their work PC's to access facebook during work.
>=20
> What method would recommend to block all facebook access?
>=20
=20
Hi Ernie,


My recommendation would be to set up unbound(8) on your 11.1 machine (or
setup another) and configure everything on the LAN to use it for name
service.

You can then shove some local records in unbound.conf(5), such as:

local-zone: "facebook.com" refuse
local-zone: "doubleclick.net" refuse
=2E..
etc.

If you then do a lookup from the LAN:

$ host facebook.com
Host facebook.com not found: 5(REFUSED)

Firefox and Chrome seem to handle that gracefully.

To stop any muppets who decide to use alternative name service ie. Google,
OpenDNS etc. Configure ipfilter to drop any outgoing to 53 except from
your unbound machine.

Of course, other benefits are:=20

1). You can cutdown on all sorts of additional superfluous traffic which
improves all sorts of things: contention, less bandwidth & quota needed
etc.

2). Lookups are a lot quicker if they're cached on the LAN; which your
users will appreciate.

This all somewhat depends on how computer savvy your users are and how
locked down their PCs are.

If they know what they're doing then they will find away around it and
nothing short of nuking all of Facebook's DCs will stop it. Now there's
an idea....


Regards,

--=20

Frank



--Qxx1br4bt0+wmkIi
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEXRpQZWMUMC1nxphkORvOAPtvi1oFAlmctvsACgkQORvOAPtv
i1rRaw/7BEEmBeGqbEEJ0BvrSkctnffD2lJ6ZIBaHBp/owGDFvnj9+FO077rUDl5
oodODgyHETVMkVS/Zu1dpkZip8rDQNsd8Idl77WKjqwqa7bJTWfZv9A67rEkaMyL
FYBIVk/FJjvOQVbK5eTlWQkLI4DmDWuXVPPCvDWWle8Gp7+J+RZj2bfn6J16sH6t
Z80uInCQCDIWlFWPcAR/XwSaPkyrd+LinJMEu+Acx/qBtIFtQu72tSnBv+KXOyMn
ZsWu0vLYKwQIoIcCjx0YA6Z6njRB0LvH7ZjwRUO7/qVfWKYg7cE0xsjRWV/HW1Zb
AyQl9w8cVYDaGR5xKSKtNGFIABAVa2Wxslobbau6jVTmvsT9EutkaAnB2SSI0YmC
SO4DEM5wns3YXXvuJyBe2EpEqZrdLHO3sPedw1nnXOMxZI5cu0zYNrFpFZZm7Zz/
kLpRDWxqPsW0qOuSwQDr/mwYHvCqa7cu7VA8EQlZG7ZMi9V8WaL5+Ao18f9d+0cV
JWWkweB0+BSEfHjXdIhOlZ7LtF9p35EORj/xJYXqZLVIWxwgaId2+CCi1jC4onwU
6wO0MZ1S3NaeULPCcJGUwHUlr0joTEqta7ufgCEkxiK2SOr6wzW8Y3+0ESpEbzXf
js/vvsVjodxL5s0/3JYOFhQzLd/1G8utOGqwPZH2QAcz8lDbJq8=
=b/Uf
-----END PGP SIGNATURE-----

--Qxx1br4bt0+wmkIi--



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20170822225807.GA97221>