Community discussions

MikroTik App
 
ansari
newbie
Topic Author
Posts: 27
Joined: Mon Jan 23, 2017 8:04 am

https, 443 proxy configuration

Wed Mar 01, 2017 1:15 pm

Hi, i am beginner on mikrotik, i want to use mikrotik web proxy https 443. please help me to know how can i configure and redirect all internet protocol via mikrotik web proxy.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26954
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: https, 443 proxy configuration

Wed Mar 01, 2017 1:27 pm

proxy does not support encrypted https traffic
 
ansari
newbie
Topic Author
Posts: 27
Joined: Mon Jan 23, 2017 8:04 am

Re: https, 443 proxy configuration

Wed Mar 01, 2017 1:32 pm

proxy does not support encrypted https traffic
Then what should i do for restrict 443 protocol? i want to block facebook on my network and also block vpn and proxy extension from pc and web browsers.
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26954
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia
Contact:

Re: https, 443 proxy configuration

Wed Mar 01, 2017 1:39 pm

you can block by IP address in the firewall, or by DNS name in the DNS server
 
msatter
Forum Guru
Forum Guru
Posts: 2942
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: https, 443 proxy configuration

Wed Mar 01, 2017 1:42 pm

Not much. Have a look SNI which states what server is approached. If you want yo block the other protocols you better look at which protocols you want to let trough out instead of blocking each unwanted one separately.
 
ansari
newbie
Topic Author
Posts: 27
Joined: Mon Jan 23, 2017 8:04 am

Re: https, 443 proxy configuration

Wed Mar 01, 2017 1:46 pm

OK, thank you
 
msatter
Forum Guru
Forum Guru
Posts: 2942
Joined: Tue Feb 18, 2014 12:56 am
Location: Netherlands / Nīderlande

Re: https, 443 proxy configuration

Wed Mar 01, 2017 3:42 pm

OK, thank you


You're welcome however Facebook is a dragon with multiple heads and I block it 'effectively' with three lines for my local DNS sever (DNSMasq):
# No access to Facebook
server=/facebook.com/fbcdn.net/facbook.com/fb.com/fbsbx.com/facebook.com.edgesuite.net/instagram.com/
server=/facebook.net/instagramstatic-a.akamaihd.net/instagramstatic-a.akamaihd.net.edgesuite.net/
server=/cdninstagram.com/tfbnw.net/whatsapp.com/fb.me/
This works if you can control the machines connection not to have their own host files in which workarounds are defined to bypass the DNS server on these specific Facebook lines.
Blocking that would mean that you block each IP that Facebook uses and that are a LOT.

Facebook has their own AS Number and I am still looking for a script (internal/external) to make an address-list from that AS Number (AS32934). Just like we are now able to state a domain name and that in the internal DNS generating the IP numbers. This list can then be called in the filtering rules by the AS Number as name.
 
User avatar
blajah
Member Candidate
Member Candidate
Posts: 222
Joined: Fri Jun 12, 2015 8:58 pm
Location: Belgrade, Serbia
Contact:

Re: https, 443 proxy configuration

Thu Mar 02, 2017 11:31 am

Actually it's not so big issue. I have blocked ranges announced by FB ASN and from my side there is no way to open FB:
0 fb 204.15.20.0/22 feb/27/2017 12:18:41
1 fb 69.63.176.0/20 feb/27/2017 12:18:41
2 fb 173.252.64.0/18 feb/27/2017 12:18:41
3 fb 31.13.64.0/19 feb/27/2017 12:18:41
4 fb 31.13.96.0/24 feb/27/2017 12:18:41
 
kivimart
Frequent Visitor
Frequent Visitor
Posts: 54
Joined: Thu Oct 10, 2013 3:06 pm

Re: https, 443 proxy configuration

Thu Mar 09, 2017 10:43 pm

How did you find the ip addresses.?