• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 619
  • Last Modified:

Blocking Facebook

hi there
i need help please.
i have to install a firewall for a company with about 50 users.
the director requires me to block certain sites like facebook, twitter etc, but just for certain users....not everyone.
now this is easy when you use pfsense with squid.
my problem is that facebook uses https now so the squid proxy doesnt pick it up.
how can i get this solved as i have tried various things all weekend.
i cant seem to get my head around this or find relevant info on the web that can assist me.

your help will be greatly appreciated

thank you

2 Solutions
Jon SnydermanCommented:
Most of the newer UTM appliance type firewalls will do exactly what you are asking.  For your size, I would personally recommend  a Watchguard XTM33 or XTM330 depending on growth needs.  They will do exactly what you are asking, have a great management tool and also great logging and reporting.  Sonicwall, palo alto and fortinet are also good choices that will do what you need.   In any case, let someone with that produvt experience help you with the install so that you look like the hero to your boss.  

Jon SnydermanCommented:
Looks like you might be an it consultant.  I would suggest sub'ing the initial install, just to be sure its right.  They all have their own idiosyncrasies.

stevenvanheerdenAuthor Commented:
hi Jon

thanks for the advice, but i'm the one doing the install.
so i need to know how to do this...i just though pfsense could handle it as i use it for various other applications.
i'm just not getting the https blocked for certain sites and certain users...

if you were in my position and you could not sub the job, what would you use?

Evaluating UTMs? Here's what you need to know!

Evaluating a UTM appliance and vendor can prove to be an overwhelming exercise.  How can you make sure that you're getting the security that your organization needs without breaking the bank? Check out our UTM Buyer's Guide for more information on what you should be looking for!

stevenvanheerdenAuthor Commented:
oh, and i need opensource please...i have to convert a server that we replaced recently to act as the firewall proxy...
Jon SnydermanCommented:
Watchguard.   One thing that most people will say about Watchguard is that the user interface (not the web based one) is the best.  It is the most intuitive and well organized.   Thats one of the things that I like best.   I can generally train a (competent) customer in a matter of a couple hours.   Understanding some of the terminology and how they all interact in the other brands can be a bit confusing.  They are good but take some getting used to.  Watchguard has a good clean top down approach that is pretty easy to understand and get used to.      

Oh, and I know that it will do what you need in a number of different ways.   You do need to make sure (with any of them) that you get the full UTM bundle.   You need webblocker and application control to do what you need to do.

.....  I was typing this as you put your last entry in.   If you are strictly looking for opensource, none of these suggestions will help.   Sorry.
Facebook is pissing a lot of IT people off lately with this crap.  They knew it would make it difficult and went out of their way to do so.

You may be able to create a port rule, but you'd need the IP addresses for the ssl sites.
Jon SnydermanCommented:
Yep, that's the problem, but the next problem is those IPS change and move based on load balancers, etc.

Do you want opensource to have opensource? Or do you want opensource because you have new hardware and you need to utilize it?  If sp, throw ESXi on the server and then load the watchguard virtual appliance version of their firewall.   I think that they are the only one in my list that has that option.
you can use DNS redirection for those users, and hope your users are not tech savvy
Paul 1Commented:
"Zabo1 : you can use DNS redirection for those users, and hope your users are not tech savvy"

When I was requested to block certain users on a budget of zero I created a share to the windows\system32\drivers\etc folder and could then have a shortcut on my PC to all those users folders where I could copy and paste a host file that contained 'whatever.com'

The best thing though would be to have a local webserver setup that the host file pointed to and have a "site blocked notice", even better would be to have the attempts to access logged.
stevenvanheerdenAuthor Commented:
Thanks for all the input guys.
Paul/Zabo - thanks for the nifty trick, but it wont be practical in my situation.
so far the watchguard sound like the only sound solution or perhaps the commercial version of sonicwall.
is there anyone out there that has achieved this with PFSense?

its such a versatile product that i cant believe this cant be done...

any further ideas?
Are they on a Windows domain? Make a hosts.txt file with entries to facebook.com pointing to Use a GPO to push the hosts.txt to all desired groups in the domain into the windows\system32\drivers\etc\hosts.txt

Watchguard, Sonicwall, Fortinet all have afordable UTM's, but is simple traffic blocking is the goal, my suggestion will keep you on budget.

Hope this helps.

stevenvanheerdenAuthor Commented:
Thanks a lot for the input guys - its greatly appreciated!

Featured Post

KuppingerCole Reviews AlgoSec in Executive Report

Leading analyst firm, KuppingerCole reviews AlgoSec's Security Policy Management Solution, and the security challenges faced by companies today in their Executive View report.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now