Community discussions

MikroTik App
 
cylent
Member
Member
Topic Author
Posts: 383
Joined: Sun May 28, 2006 10:30 am

block traffic from specific sites.

Fri Apr 06, 2012 6:08 pm

this may sound too easy for some but its not something i can figure out.

lets say i want to block

windowsupdate.com
or download.windowsupdate.com
or phobos.apple.com

the problem is these sites dont have one ip address. most have 10 or even more and theres no way to figure them all out to drop traffic from one or two ips.

please advise.
 
User avatar
cybercoder
Member Candidate
Member Candidate
Posts: 175
Joined: Tue Dec 07, 2010 11:20 pm
Location: Guilan, Iran
Contact:

Re: block traffic from specific sites.

Fri Apr 06, 2012 6:35 pm

if there's specific ip address for a subdomain, then you can block the IP address from layer 3 filter rules. but if not you could use regular expressions and layer 7 protocols to mark that specific packets and then drop theme from firewall rules.
 
cylent
Member
Member
Topic Author
Posts: 383
Joined: Sun May 28, 2006 10:30 am

Re: block traffic from specific sites.

Fri Apr 06, 2012 6:47 pm

i tried to mark packets and apply a queue using mangle and content on "au.download.windowsupdate.com" and the mangle rule had hits but it didnt work.

example sites:

ardownload.adobe.com
a1410.phobos.apple.com
au.download.windowsupdate.com
swcdn.apple.com
a474.phobos.apple.com
wl.dlservice.microsoft.com

as you can see from above phobos.apple.com has two links above. and more and more.


my users are literally ignorant. they dont know even basic computer knowledge. and because i set speed limits for their internet access they will complain their connection is slow. little do they know that their computer is running an update in the background sucking the speed thats allowed to them.
 
User avatar
czolo
Member
Member
Posts: 423
Joined: Fri Mar 04, 2005 9:49 am
Location: Poland (Warsaw)
Contact:

Re: block traffic from specific sites.

Sun Apr 08, 2012 1:45 am

i tried to mark packets and apply a queue using mangle and content on "au.download.windowsupdate.com" and the mangle rule had hits but it didnt work.

example sites:

ardownload.adobe.com
a1410.phobos.apple.com
au.download.windowsupdate.com
swcdn.apple.com
a474.phobos.apple.com
wl.dlservice.microsoft.com

as you can see from above phobos.apple.com has two links above. and more and more.


my users are literally ignorant. they dont know even basic computer knowledge. and because i set speed limits for their internet access they will complain their connection is slow. little do they know that their computer is running an update in the background sucking the speed thats allowed to them.
Maybe try to use proxy. I'm doing that, and it works
 
User avatar
acim
Member
Member
Posts: 415
Joined: Mon Sep 12, 2005 12:26 am
Location: Serbia
Contact:

Re: block traffic from specific sites.

Sun Apr 08, 2012 3:08 am

You can do it with DNS also if you have your own (or Mikrotik).

Who is online

Users browsing this forum: No registered users and 63 guests