From owner-freebsd-pf@FreeBSD.ORG Fri Aug 3 08:06:19 2007 Return-Path: Delivered-To: freebsd-pf@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 0666416A419 for ; Fri, 3 Aug 2007 08:06:19 +0000 (UTC) (envelope-from patpro@patpro.net) Received: from smtp1-g19.free.fr (smtp1-g19.free.fr [212.27.42.27]) by mx1.freebsd.org (Postfix) with ESMTP id ACFD513C4CA for ; Fri, 3 Aug 2007 08:06:18 +0000 (UTC) (envelope-from patpro@patpro.net) Received: from smtp1-g19.free.fr (localhost.localdomain [127.0.0.1]) by smtp1-g19.free.fr (Postfix) with ESMTP id 756B91AB2F0; Fri, 3 Aug 2007 10:06:17 +0200 (CEST) Received: from boleskine.patpro.net (boleskine.patpro.net [82.235.12.223]) by smtp1-g19.free.fr (Postfix) with ESMTP id 59F211AB2E8; Fri, 3 Aug 2007 10:06:16 +0200 (CEST) Received: from [192.168.0.2] (unknown [192.168.0.2]) by boleskine.patpro.net (Postfix) with ESMTP id 48ECB1CC40; Fri, 3 Aug 2007 10:06:16 +0200 (CEST) In-Reply-To: <20070803073610.GA39968@quartzo.cirp.usp.br> References: <20070803073610.GA39968@quartzo.cirp.usp.br> Mime-Version: 1.0 (Apple Message framework v752.2) Content-Type: text/plain; charset=ISO-8859-1; delsp=yes; format=flowed Message-Id: Content-Transfer-Encoding: quoted-printable From: Patrick Proniewski Date: Fri, 3 Aug 2007 10:06:15 +0200 To: Ali Faiez Taha X-Mailer: Apple Mail (2.752.2) Cc: freebsd-pf@freebsd.org Subject: Re: Block WWW.ORKUT.COM X-BeenThere: freebsd-pf@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Technical discussion and general questions about packet filter \(pf\)" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 03 Aug 2007 08:06:19 -0000 Hi, On 03 ao=FBt 2007, at 09:36, Ali Faiez Taha wrote: > What I need to do to block the access to www.orkut.com, via =20 > webproxy, anonymizer sites and direct access ? > I am using FreeBSD with PF, without Proxy server, 2 NICs (one for =20 > Iternet and one for Intranet). > Actually I use a table with a lot of IP address blocked. This is just impossible, unless may be you have as much money and =20 power as the chinese government. What you want to do is layer 7 firewalling: ie. looking into the HTTP =20= transmitted, determine if it comes from orkut (directly or via a =20 proxy), and block accordingly. You might want to known: even this =20 won't work if the client uses HTTPS to connect to the proxy/=20 anonymizer (in that case, HTTP transfer is encrypted, and you can't =20 eavesdrop the http content.) patpro=