Difference between revisions of "Facebook Block Https"

From MS Computech
Jump to: navigation, search
 
Line 1: Line 1:
 
nano /etc/rc.d/rc.firewall.local
 
nano /etc/rc.d/rc.firewall.local
 
<pre>
 
<pre>
iptables -t nat -I PREROUTING -m tcp -p tcp -m iprange --dst-range 69.63.176.0-69.63.191.255 --dport 80 -j DROP
+
iptables -t nat -I PREROUTING -p tcp -d 69.171.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -m tcp -p tcp -d 66.220.147.22 --dport 80 -j DROP
+
iptables -t nat -I PREROUTING -p tcp -d 66.220.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -m tcp -p tcp -d 66.220.147.22 --dport 443 -j DROP
+
iptables -t nat -I PREROUTING -p tcp -d 64.208.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -m tcp -p tcp -m iprange --dst-range 69.63.176.0-69.63.191.255 --dport 443 -j DROP
+
iptables -t nat -I PREROUTING -p tcp -d 61.213.0.0/16 --dport 443 -j DROP
</pre>
+
iptables -t nat -I PREROUTING -p tcp -d 96.16.0.0/16 --dport 443 -j DROP
[http://www.clearfoundation.com/component/option,com_kunena/Itemid,232/catid,7/func,view/id,16002/ Source]
+
iptables -t nat -I PREROUTING -p tcp -d 125.56.0.0/16 --dport 443 -j DROP
 +
iptables -t nat -I PREROUTING -p tcp -d 125.252.0.0/16 --dport 443 -j DROP
 +
iptables -t nat -I PREROUTING -p tcp -d 210.161.0.0/16 --dport 443 -j DROP
  
Another method ( Tested Work )
+
#iptables -t nat -I PREROUTING -p tcp --dport 443 -j DROP
 
 
<pre>
 
FACEBOOK_ALLOW="192.168.1.12 192.168.1.14 192.168.1.111"
 
iptables -N FACEBOOK
 
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 66.220.144.0-66.220.159.255 --dport 443 -j FACEBOOK
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 69.63.176.0-69.63.191.255 --dport 443 -j FACEBOOK
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 204.15.20.0-204.15.23.255 --dport 443 -j FACEBOOK
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 66.220.144.0-66.220.159.255 --dport 80 -j FACEBOOK
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 69.63.176.0-69.63.191.255 --dport 80 -j FACEBOOK
 
iptables -I FORWARD -m tcp -p tcp -m iprange --dst-range 204.15.20.0-204.15.23.255 --dport 80 -j FACEBOOK
 
 
## FACEBOOK ALLOW
 
for face in $FACEBOOK_ALLOW; do
 
    iptables -A FACEBOOK -s $face -j ACCEPT
 
done
 
iptables -A FACEBOOK -j REJECT
 
 
</pre>
 
</pre>
 
[http://blog.kdn2.info/2010/11/block-facebook-com-with-iptables/ Source]
 

Latest revision as of 13:19, 24 November 2011

nano /etc/rc.d/rc.firewall.local

iptables -t nat -I PREROUTING -p tcp -d 69.171.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 66.220.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 64.208.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 61.213.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 96.16.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 125.56.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 125.252.0.0/16 --dport 443 -j DROP
iptables -t nat -I PREROUTING -p tcp -d 210.161.0.0/16 --dport 443 -j DROP

#iptables -t nat -I PREROUTING -p tcp --dport 443 -j DROP