Enviado em 08/01/2014 - 11:06h
Bem galera tenho testados algumas formas de sites https tipo "facebook/youtube/orkut(vai que usam ainda)"
SQUID
####
http_port 3130 transparent cert=/etc/squid/openssl.crt key=/etc/squid/openssl.key
####
#iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 443 -j REDIRECT --to-port 3130
######################
IPs_BLOCK="ip's que quero bloquear"
/sbin/iptables -N SITEBLOCK
/sbin/iptables -I FORWARD -m tcp -p tcp -m string --algo bm --string "facebook.com" -j SITEBLOCK
#/sbin/iptables -I FORWARD -m tcp -p tcp -m string --algo bm --string "youtube.com" -j SITEBLOCK
## BLOCK ##
for block in $IPs_BLOCK; do
/sbin/iptables -A SITEBLOCK -s $block -j REJECT
/sbin/iptables -A SITEBLOCK -d $block -j REJECT
done
######################