Bulk import

Another way of creating an alias for a site with a number of different IP addresses is to use pfSense's bulk import function. The bulk import function can be invoked by navigating to the main Aliases page (via Firewall | Aliases) and clicking on the blue Import button.

There are three fields on the Bulk Import page: Alias Name, Description, and Aliases to import.  The first two fields are identical to the same-named fields on the Aliases page that appears when the Add button is pressed. In the Aliases to import edit box, enter a carriage return-delimited list of IP addresses, with or without a CIDR and a description. When done, press the Save button.

Using Bulk Import is easy; what is hard is finding a valid list of IP addresses for popular sites that is up to date. As with the DNS lookup method of creating aliases, the challenge is that many of these sites regularly add new IP addresses and ranges to the pool of IP addresses they utilize and retire other addresses/ranges. One (as of this writing) up-to-date list is a list of Facebook (http://facebook.com/) IP addresses at https://gist.github.com/Whitexp/9591384. Copying and pasting this list into your alias should enable you to block Facebook. Using this method to block popular social media sites, however, is generally not recommended, due to the administrative overhead associated with making sure that aliases maintain up to date lists of IP addresses. Rather, it is recommended that you use proxies, which will be discussed more fully in Chapter 11, Extending pfSense with Packages.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset