Outpost Users Support Forum  
Outpost User Operated Support Forum
Agnitum Outpost Pro Release (OP, OSS, AV): 7.0.2.3377 [23-JUL-2010]
www.agnitum.com

Go Back   Outpost Users Support Forum > Agnitum Outpost Security Suite / Outpost Firewall/Outpost Antivirus > Outpost Security Suite General Discussions, Support, and Troubleshooting

Reply
 
Thread Tools
  #1  
Old 01-29-2010, 05:52 PM
tekbahadur1's Avatar
tekbahadur1 tekbahadur1 is offline
Junior Member
 
Join Date: Jan 2010
Posts: 5
Post not able to block facebook.com using ipblock list

when i add the domain name in ipblock list.
it should automatically detect all the ip addresses assigned for same domain name but it is failing to do this.
plz help me to block social networking sites.
I am using firewall ver3.0

Last edited by tekbahadur1; 01-29-2010 at 05:58 PM.
Reply With Quote
  #2  
Old 01-29-2010, 07:49 PM
kronckew's Avatar
kronckew kronckew is offline
Moderator
 
Join Date: May 2003
Location: CSA Consulate,Rm.101,Glos. UK
Posts: 4,462
Re: not able to block facebook.com using ipblock list

the ip blocklist looks up the current IP of facebook at the time you click the button. facebook uses a fair number of IP's, so the next time your pc goes there it will likely be a different IP.

anyhow, have a look at this thread where we discuss the facebook howto. there are a number of options...
__________________
Regards,

CAVE CANEM ET SEMPER PARATUS
Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB,
and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650,
Firefox 3.6.8pre, Thunderbird 3.1, IE8
, 802.11g adapters,
Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2
,
in-house IT Support Dept. consisting of two retired greyhounds.

Reply With Quote
  #3  
Old 01-29-2010, 10:57 PM
tekbahadur1's Avatar
tekbahadur1 tekbahadur1 is offline
Junior Member
 
Join Date: Jan 2010
Posts: 5
Re: not able to block facebook.com using ipblock list

can't we have the keyword web blocking back in firewall?
as it was available and quite reliable in firewall version 2.0...
Reply With Quote
  #4  
Old 01-29-2010, 11:38 PM
kronckew's Avatar
kronckew kronckew is offline
Moderator
 
Join Date: May 2003
Location: CSA Consulate,Rm.101,Glos. UK
Posts: 4,462
Re: not able to block facebook.com using ipblock list

keyword blocking for ads is still available as in earlier versions, it will prevent anything from displaying, ie. *.facebook.* should stop anything from facebook from showing, but it will not stop the site connection like the blocklist.


it also will not stop ads or frames that have a non-facebook url. see the list in the improvenet tab as per attached for examples. for facebook you'd also need to block their other domains like fbcdn.net, it also may not block gzipped or secure encrypted sites.

for facebook, the simplest solution is to add the following three lines to the file called HOSTS (note that there is no extension) in windows\system32\drivers\etc:

127.0.0.1 www.facebook.com
127.0.0.1 facebook.com
127.0.0.1 fbcdn.net
Attached Images
File Type: jpg 2010-01-30 12 31 34.jpg (91.5 KB, 37 views)
__________________
Regards,

CAVE CANEM ET SEMPER PARATUS
Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB,
and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650,
Firefox 3.6.8pre, Thunderbird 3.1, IE8
, 802.11g adapters,
Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2
,
in-house IT Support Dept. consisting of two retired greyhounds.


Last edited by kronckew; 01-30-2010 at 12:27 AM.
Reply With Quote
  #5  
Old 01-30-2010, 04:47 AM
tekbahadur1's Avatar
tekbahadur1 tekbahadur1 is offline
Junior Member
 
Join Date: Jan 2010
Posts: 5
Question Re: not able to block facebook.com using ipblock list

great!!!
but everyone knows about hosts file and anyone can revert the hosts file to access the blocked url.
ok if we modify the hosts file but what to do with the bypass proxy sites like www.bypassthat.com which makes our effort useless??????????

Last edited by minoka; 01-30-2010 at 05:25 AM.
Reply With Quote
  #6  
Old 01-30-2010, 05:19 AM
kronckew's Avatar
kronckew kronckew is offline
Moderator
 
Join Date: May 2003
Location: CSA Consulate,Rm.101,Glos. UK
Posts: 4,462
Re: not able to block facebook.com using ipblock list

sigh

i gather we're trying to keep a persistant juvenile from facebook, etc. if they're that smart, it gets difficult. if the pc's user is smart and tries hard enough, it's difficult to keep them away from their addiction. per your last, you also need to block any known proxys.

you could tie down the pc from access to the system folders with the policy editor, so only the admin account has access, and ensure they can't get in the admin account. while you are at it, set it so they do not see any of the networking related settings, so they can't change dns settings.

then you could set up an account at opendns, password protect the account with a strong password sequence, then set the opendns server addresses in the router, set networking to point to the router as the dns server. use the opendns account to block porn, instant messaging, proxys and social networks, etc. and let them worry about the IP's. make sure you again use a strong password on the router so they can't change it. if they can get thru that, you are in deep doo-doo.

some routers (like my netgear) allow you to block domains at the hardware level, and have keyword blocking. if router access is secure that can help, again you'd also need to block any proxy sites, etc. they could alsways set the router back to factory defaults, reconnect and thus bypass it, if y'all connect via wifi instead of cabling, they'd need to set up the wap security with the same passwords/keys as before or you'd know when you couldn't connect yourself. you also need to make sure they can't connect to a neighbours insecure wap.

all in all a never ending battle. OP is just one layer in the defence onion.

dropping the pc from the top of a tall building , hitting it repeatedly with a 10 lb. sledge hammer, or a few hits from a 12 ga. will also keep them from facebooking i do not recommend a similar strategy with the offending user as the police tend to frown on that.

one major advantage of having two dogs that live with me in lieu of children is that their fingers do not fit the keyboard and they have no thumbs. and if they disobey, get loose, and get pregnant you can sell the offspring. they also need me, i'm the only one that can work the can opener.
__________________
Regards,

CAVE CANEM ET SEMPER PARATUS
Win7x86, P4E, 3 GB ram, nVidia fx5200, Asrock p4v88 MB,
and win7 x64, pentium D, 2GB ram, nvidia 8400gs, acer aspire t650,
Firefox 3.6.8pre, Thunderbird 3.1, IE8
, 802.11g adapters,
Netgear DG834G adsl modem/FW/router, Outpost Security Suite v7.0.2
,
in-house IT Support Dept. consisting of two retired greyhounds.


Last edited by kronckew; 01-30-2010 at 05:31 AM.
Reply With Quote
  #7  
Old 02-01-2010, 01:41 AM
Escalader's Avatar
Escalader Escalader is offline
Senior Member
 
Join Date: Mar 2009
Posts: 319
Re: not able to block facebook.com using ipblock list

Quote:
Originally Posted by tekbahadur1 View Post
can't we have the keyword web blocking back in firewall?
as it was available and quite reliable in firewall version 2.0...

Just a thought for you, you can put keyword web blocking in Nod32 V4 using their address management feature. Here is an example I use for China.

*.cn.
__________________
Best Regards!

.... there is always time to do it over, but never enough to do it right the first time....
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Agnis block list for Outpost J4ZNJC Outpost Firewall General Discussions, Support, and Troubleshooting 11 04-03-2009 03:36 AM
Anyway to edit IP block list from outside Outpost? spiril Outpost Firewall General Discussions, Support, and Troubleshooting 12 10-27-2005 08:27 AM
AD block exceptions list Sh8an Retired Threads 6 12-19-2001 08:22 PM
Make the initial ads block list empty vrapp Retired Threads 8 12-06-2001 12:18 AM


All times are GMT -12. The time now is 09:04 PM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.