so... how can i block https?Yes, this is why L7 rules are not meant for webpage blocking.
/ip dns static add name=www.facebook.com address=127.0.0.1
OK, I create DNS name, but how to block facebook.com? can I need firewall rule?, if so how to make firewall rules. pl details............Create a DNS name like:Or to an IP with web server and block page.Code: Select all/ip dns static add name=www.facebook.com address=127.0.0.1
It's a solution instead of layer 7, like normis said.
Sent from my XT1225 using Tapatalk
No you can't: can be used one proxy like 2.3.4.5 on brasil for access!The only way to block facebook.com, block on BGP the prefix with AS32934...
No, you can not use one proxy for HTTPS pages! Facebook is near all httpsNo you can't: can be used one proxy like 2.3.4.5 on brasil for access!The only way to block facebook.com, block on BGP the prefix with AS32934...
OK, I create DNS name, but how to block facebook.com? can I need firewall rule?, if so how to make firewall rules. pl details............Create a DNS name like:Or to an IP with web server and block page.Code: Select all/ip dns static add name=www.facebook.com address=127.0.0.1
It's a solution instead of layer 7, like normis said.
Sent from my XT1225 using Tapatalk
/ip firewall nat add chain=dst-nat protocol=udp dst-port=53 in-interface=$YOUR_LAN action=redirect to-ports=53
/ip firewall nat add chain=dst-nat protocol=udp dst-port=53 in-interface=$YOUR_LAN action=redirect to-ports=53 src-address-list=!no-block
/interface list
add name=internet comment="List of WAN"
/interface list member
add interface=ether1 list=internet comment="WAN 1"
add interface=ether2 list=internet comment="WAN 2"
/ip firewall filter
add action=drop chain=input dst-port=53 in-interface-list=internet protocol=tcp connection-state=new comment="TCP DNS Protection"
add action=drop chain=input dst-port=53 in-interface-list=internet protocol=udp connection-state=new comment="UDP DNS Protection"
add action=drop chain=forward dst-address-list=internal_public_IP dst-port=53 protocol=tcp in-interface-list=internet connection-state=new comment="Other Public IP protection used inside LAN"
add action=drop chain=forward dst-address-list=internal_public_IP dst-port=53 protocol=udp in-interface-list=internet connection-state=new
/ip firewall nat
add action=dst-nat chain=dstnat dst-addresses=!192.168.88.1 src-address-list=!do_not_redirect_DNS dst-address-list=!do_not_block_this_DNS dst-port=53 protocol=tcp to-addresses=192.168.88.1 to-ports=53 comment="DNS Redirect"
add action=dst-nat chain=dstnat dst-addresses=!192.168.88.1 src-address-list=!do_not_redirect_DNS dst-address-list=!do_not_block_this_DNS dst-port=53 protocol=udp to-addresses=192.168.88.1 to-ports=53
/ip firewall address-list
add address=192.175.48.1 comment=prisoner.iana.org list=do_not_block_this_DNS
add address=192.175.48.6 comment=blackhole-1.iana.org list=do_not_block_this_DNS
add address=192.175.48.42 comment=blackhole-2.iana.org list=do_not_block_this_DNS
add address=192.168.88.1 comment=Router list=do_not_redirect_DNS
Hi, I did this redirecting facebook requests to my web server 192.168.0.3 (IIS)Create a DNS name like:Or to an IP with web server and block page.Code: Select all/ip dns static add name=www.facebook.com address=127.0.0.1
It's a solution instead of layer 7, like normis said.
Sent from my XT1225 using Tapatalk
/ip dns static add regexp=.facebook.com address=127.0.0.1