Path: csiph.com!v102.xanadu-bbs.net!xanadu-bbs.net!feeder.erje.net!eu.feeder.erje.net!news.albasani.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail From: "john james" Newsgroups: uk.d-i-y,uk.comp.os.linux,comp.os.linux.misc Subject: Re: Parental guardian - internet (WEB) filtering Date: Wed, 1 Apr 2015 06:59:37 +1100 Lines: 75 Message-ID: References: Mime-Version: 1.0 Content-Type: text/plain; format=flowed; charset="UTF-8"; reply-type=response Content-Transfer-Encoding: 8bit X-Trace: individual.net NKj+h5PjeVfQtLJylYf8gw/tXeWMAbwJeQtPQHR9RvKFmIF/A= Cancel-Lock: sha1:e1xMSoUmS5BF5pOpcZZcP2/5U8U= In-Reply-To: X-Priority: 3 X-MSMail-Priority: Normal Importance: Normal X-Newsreader: Microsoft Windows Live Mail 14.0.8117.416 X-MimeOLE: Produced By Microsoft MimeOLE V14.0.8117.416 Xref: csiph.com comp.os.linux.misc:14290 "Tim Watts" wrote in message news:vh2rub-54e.ln1@squidward.dionic.net... > Please, no debates about the merits of this - > > I'm having trouble trying to find anything that might work. > > > DNS based: > ========== > OpenDNS https://www.opendns.com/home-internet-security/ > is going to be tricky trying to make that work alongside Unblock-US which > is also DNS based. I might be able to track down the relevant Netflix > zones and declared them in my local DNS server and refer those to > UnblockUS whilst the default is to OpenDNS. In many ways though this is > the easiest solution, except that it has to work along side UnblockUS. > > No worries about the kids setting their own DNS servers, I'll deal with > that in the firewall :) > > > > Proxy > ===== > eg Squidguard - It will not work with SSL traffic. Well, it might, but > then all my browsers will throw up man-in-the-middle warnings. Seems like > a non starter. > > Bloody big blacklist of IPs > =========================== > Assuming I can load several million into iptables without blowing up the > router (see below), this could work. > > > Any approaches I've missed? Does not need to be perfect - just good enough > to mostly keep them off rotten.com, jihadist beheading vids and hard core > porn. And if they hack their way around it, good for them - at least they > are working for it - no illusions that they will be defeated for ever. > > > Cheers > > Tim > > > > Equipment I have: > > Nice linux router running Debian 7 (this is are full blown nano system > with lots of RAM, not embedded). It is my PPPoE endpoint, firewall, > router, DNS, DHCP NAT and kerberos box. > > > So I'd like to put 2 of my VLANs onto a filtered feed whilst leaving the > main VLANs unfiltered. My VLANs are like this: > > 1) Public IP /27 block > 2) Private "Golden" 10.0.0.0/24 block > 3) Media 10.0.1.0/24 block for Netflix etc - Chromecast, Roku and > phones/pads will use this > 4) Guest net 10.0.2.0/24 > > Each maps to a separate WIFI ESSID. > > 1+2 unfiltered > 3+4 filtered all the time. > > Only difference between 3 and 4 is 4 can get a new password every few > weeks, without having to change Chromecast, Roku and other stuff. > > Assume the kids do not ever get to access 1+2. Don’t forget who will be picking your nursing home.