From owner-freebsd-ipfw@freebsd.org Mon Nov 30 11:18:50 2015 Return-Path: Delivered-To: freebsd-ipfw@mailman.ysv.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) by mailman.ysv.freebsd.org (Postfix) with ESMTP id 17170A249A1 for ; Mon, 30 Nov 2015 11:18:50 +0000 (UTC) (envelope-from kulamani.sethi@gmail.com) Received: from mail-io0-x229.google.com (mail-io0-x229.google.com [IPv6:2607:f8b0:4001:c06::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (Client CN "smtp.gmail.com", Issuer "Google Internet Authority G2" (verified OK)) by mx1.freebsd.org (Postfix) with ESMTPS id D9C521AC1 for ; Mon, 30 Nov 2015 11:18:49 +0000 (UTC) (envelope-from kulamani.sethi@gmail.com) Received: by ioc74 with SMTP id 74so168178007ioc.2 for ; Mon, 30 Nov 2015 03:18:49 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:date:message-id:subject:from:to:content-type; bh=cNCnn8zIvv3b0n9Vt2EpMPx7JmVUA1Y0RgJUB+F4d1o=; b=dFCVK1x0ShqbdoYNyii5b46OjjNVjrrbf/OwS2JNMEUEehtLX+sO+PyNCRLsHZh+Xu i+pvF/NMvFGKVxPvWLz25nhqHrZBZJoQItspapVl4lbeVVBsaYJ0EbhoW5qBI1A9l57o ZL3L0ZxtoYIk0msCaOH2Xr2tQ4f6noQMRXTx43EnpfnLsA9pHqjfeN6i/lKoA31F9jWK xC60KLmqmXiIbfdLT7Puib3DZhPk9U7YhFOCT0lNZ+nhd+cJuYMSSmLNyhSF2fkl/Qau KSnozhUt915GY/tnEKIYzq8d+y536mYnjVYDG0HlBzyWzVl1VPZhuu3oL+fpxSLAxWLa yXPQ== MIME-Version: 1.0 X-Received: by 10.107.133.227 with SMTP id p96mr59686985ioi.1.1448882329270; Mon, 30 Nov 2015 03:18:49 -0800 (PST) Received: by 10.36.211.146 with HTTP; Mon, 30 Nov 2015 03:18:49 -0800 (PST) Date: Mon, 30 Nov 2015 16:48:49 +0530 Message-ID: Subject: Set a deny rule for a URL in IPFW by its domain name From: Kulamani Sethi To: freebsd-ipfw@freebsd.org Content-Type: text/plain; charset=UTF-8 X-Content-Filtered-By: Mailman/MimeDel 2.1.20 X-BeenThere: freebsd-ipfw@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: IPFW Technical Discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 30 Nov 2015 11:18:50 -0000 Hi all, I am using ipfw3, can i block a URL by its domain name? When i am setting rules in IPFW by its domain name, it simple set rule by its corresponding IP. Here example how i set C:>ipfw add 1002 deny log ip from www.google.com to any As i know most of the websites uses dynamic IP, it simple changes there IP periodically. This rule i set for google is worked for few moment, then it allow the packets to my terminal.