Jump to content

list of necessary url?

Required

Hey

Is there some list of necessary url who I must white List in my Router to allow the User to use the "good" Sites?
Thanks

From AT. :x

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Required said:

Hey

Is there some list of necessary url who I must white List in my Router to allow the User to use the "good" Sites?
Thanks

No, not really. What exactly are you trying to do?

 

The way this is usually done is using something like pihole which effectively blocks websites. It can be rather easily circumvented tho, if the user knows anything about DNS.  

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks to the developer my Router can Block them to. Sadly some Block List contain false positive. Since my Router Download there File every Day I cant edit them or do something. So I need a Whitelist with all of the neccecary URL so that everyone can use the Web. Like Font Awesome,...

From AT. :x

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, Required said:

Thanks to the developer my Router can Block them to. Sadly some Block List contain false positive. Since my Router Download there File every Day I cant edit them or do something. So I need a Whitelist with all of the neccecary URL so that everyone can use the Web. Like Font Awesome,...

  1. Which router?
  2. Which blocklist?
  3. Do you have a "query log" of the blocked/allowed items?
Link to comment
Share on other sites

Link to post
Share on other sites

23 minutes ago, Required said:

Thanks to the developer my Router can Block them to. Sadly some Block List contain false positive. Since my Router Download there File every Day I cant edit them or do something. So I need a Whitelist with all of the neccecary URL so that everyone can use the Web. Like Font Awesome,...

You probably don’t want to do it with an allow list… things are to dynamic for this. Using a block list will have less “blocks in error” then an allow list will have “failed to allow”.
 

If your router supports block lists, then use the default pihole block lists for instance; they work very well.

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

31 minutes ago, Falcon1986 said:

Which router?

An Zyxel ATP

 

32 minutes ago, Falcon1986 said:

Which blocklist?

Maintained by Macafee

 

32 minutes ago, Falcon1986 said:

Do you have a "query log" of the blocked/allowed items?

Sorry I dont know the Therm. I see in an local Log when someone try to connect to an "bad"/ blocked URL. Well since many People surf without an Ad Blocker that Log get DAMN fast "full" (well "full" is not the right terme since the Router save the Log on an USB 512GB Flash Drive as "Backup")

 

19 minutes ago, LIGISTX said:

If your router supports block lists, then use the default pihole block lists for instance; they work very well.

Do you have an URL to an "Plain Text" List?

 

Here for example what Microsoft need: https://docs.microsoft.com/en-us/azure/virtual-desktop/safe-url-list?tabs=azure

 

I use this List: https://pgl.yoyo.org/adservers/serverlist.php?hostformat=nohtml&showintro=0&mimetype=plaintext

 

From AT. :x

Link to comment
Share on other sites

Link to post
Share on other sites

40 minutes ago, Required said:

Maintained by Macafee

 The Zyxel ATP line is intended for small to medium sized businesses, so it makes sense for the security to be high. Are you allowed to use other blocklists or is the McAfee list tied to the ATP?

 

Spoiler

BTW, I didn’t realize McAfee was still doing stuff… 😒

 

44 minutes ago, Required said:

Do you have an URL to an "Plain Text" List?

As I’ve found out recently, not all blocklists can be used for all firewalls. The syntax varies based on the platform the list is intended for.

 

This is the one by StevenBlack that is usually included by default on PiHole setup. Firebog also has their collection. You can compare them to the McAfee blocklist to see if they’re similar and replace the McAfee one. One of these is less likely to cause false detections.

 

1 hour ago, Required said:

So you use this and the McAfee one?

Link to comment
Share on other sites

Link to post
Share on other sites

12 minutes ago, Falcon1986 said:

Are you allowed to use other blocklists or is the McAfee list tied to the ATP?

Ity my Router I can do what I want to. 😉 There are 2 methods the first one is the Contend Filter who I can select a "bad" Categorie like Ads and the get blocked. In addition I can use external Lists to. When I remember right for Black and With List.

Here is the official Demo: https://atp500demo.zyxel.com/

https://sitelookup.mcafee.com/?p=mcafee&product=01-ts

 

I also found this German Site: https://www.technoy.de/lists/blocklists-fuer-pihole/

 

But sadly I need a "White List" since the bad get blocked by the Contend Filter.

From AT. :x

Link to comment
Share on other sites

Link to post
Share on other sites

11 minutes ago, Required said:

 

But sadly I need a "White List" since the bad get blocked by the Contend Filter.

If your block list is blocking too many “good” sites, you need to use a less aggressive list. 
 

The pihole list mentioned above is not overly aggressive and has only broken 1 or 2 links for me over the years, but it does a great job of stopping adds. 

Rig: i7 13700k - - Asus Z790-P Wifi - - RTX 4080 - - 4x16GB 6000MHz - - Samsung 990 Pro 2TB NVMe Boot + Main Programs - - Assorted SATA SSD's for Photo Work - - Corsair RM850x - - Sound BlasterX EA-5 - - Corsair XC8 JTC Edition - - Corsair GPU Full Cover GPU Block - - XT45 X-Flow 420 + UT60 280 rads - - EK XRES RGB PWM - - Fractal Define S2 - - Acer Predator X34 -- Logitech G502 - - Logitech G710+ - - Logitech Z5500 - - LTT Deskpad

 

Headphones/amp/dac: Schiit Lyr 3 - - Fostex TR-X00 - - Sennheiser HD 6xx

 

Homelab/ Media Server: Proxmox VE host - - 512 NVMe Samsung 980 RAID Z1 for VM's/Proxmox boot - - Xeon e5 2660 V4- - Supermicro X10SRF-i - - 128 GB ECC 2133 - - 10x4 TB WD Red RAID Z2 - - Corsair 750D - - Corsair RM650i - - Dell H310 6Gbps SAS HBA - - Intel RES2SC240 SAS Expander - - TreuNAS + many other VM’s

 

iPhone 14 Pro - 2018 MacBook Air

Link to comment
Share on other sites

Link to post
Share on other sites

On 9/1/2022 at 6:59 AM, Required said:

 

 

But sadly I need a "White List" since the bad get blocked by the Contend Filter.

Which is basically what I do at work. We are one of those "why so serious" compaines and somehow used mcafee as network filter.

I just allow the site and its CDN urls whenever any user requests because it's blocked by stupid mcafee. Games, shows, ideas, entertainment, I allow them all.

Link to comment
Share on other sites

Link to post
Share on other sites

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×