09-23-2010 07:00 AM - edited 03-06-2019 01:08 PM
I currently administer a network. I use a Cisco 2821 as my gateway.Please i will need a configuration to block some users on my Network from accessing the following sites: www.facebook.com, www.youtube.com, Yahoo Chat.
My LAN IP: 172.16.0.0/24
WAN: 10.1.1.0/28
09-23-2010 07:29 AM
Hi Obafemiboye,
The best way to accomplish this is using a proper proxy with content filter - there are options ranging from very expensive to free.
(Try IPCOP with squidguard addon for example)
A very quick and dirty way to block facebook using only your router is to route all traffic to facebook Ip addresses to null
ip route 69.63.184.142 255.255.255.255 null0
ip route 69.63.187.17 255.255.255.255 null0
ip route 69.63.187.19 255.255.255.255 null0
ip route 69.63.181.11 255.255.255.255 null0
ip route 69.63.181.12 255.255.255.255 null0
If you want to only block access for certain users, then this is possible using Policy Based Routing
ip access-list extended ACL_BLOCK_FACEBOOK
permit ip 192.168.1.0 0.0.0.255 host 69.63.184.142
permit ip 192.168.1.0 0.0.0.255 host 69.63.187.17
permit ip 192.168.1.0 0.0.0.255 host 69.63.187.19
permit ip 192.168.1.0 0.0.0.255 host 69.63.181.11
permit ip 192.168.1.0 0.0.0.255 host 69.63.181.12
deny ip any any
route-map RM_BLOCK_FACEBOOK permit 10
match ip address ACL_BLOCK_FACEBOOK
set ip next-hop null0
!
route-map RM_BLOCK_FACEBOOK permit 20
!
Interface f0/1
description Inside Interface
ip policy route-map RM_BLOCK_FACEBOOK
This assumes the users you want to block are in the range 192.168.1.0/24
However this is easily circumvented by people using open proxies.
Hope this helps ;-)
Nick
09-23-2010 07:33 AM
Thanks. I will implement it and get back to you.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide