If you really want to block all traffic from/to facebook, lookup the IP prefixes associated with their AS number(AS32934), and setup your firewall to block those. If you are using PF, tables are your friend. With netfilter, consider using ipset.
If you really want to block all traffic from/to facebook, lookup the IP prefixes associated with their AS number(AS32934), and setup your firewall to block those. If you are using PF, tables are your friend. With netfilter, consider using ipset.
[1] http://www.tcpiputils.com/browse/as/32934 * note there are more than average ads on this site and it's a bit plain but this was the only one I could find that, with my brief searching, showed ip prefixes associated to the AS number.
If anyone has a better lookup tool that'd be great!
edit: Should also note that since other users are mentioning they might be under multiple AS number's maybe the ticket would be to setup a GitHub that collected these AS numbers for FB.
edit 2: found a less ad filled site! http://ipduh.com Search AS32934 click "prefixes" at top
You can also confirm this is the only ASN for Facebook by searching for Facebook at https://ipinfo.io/countries/us
[1] http://www.commandlinefu.com/commands/view/16096/block-all-f...
And if you're already doing outbound whitelisting (which is generally much more trouble than it's worth) then unless you put Facebook on the whitelist you don't need to do anything anyway.
AS information isn't trivially available, though you can do a pretty good job through tools like the CIDR Report and ASN Routeviews.
There are quite substantial portions of the Internet to which I'd generally provide very little or very limited access if I had my druthers.
Most of what you'd want is out there, but you might have to obtain it all and doing a bit of work to combine/correlate i all.
definitely not ideal, not even complete, and requires work - BUT, nearly any Internet user can implement the solution done this way.
It would be really interesting to autogenerate the domain lists by running background scripts on AS numbers, polling DNS for every IP in the range, and cataloging the domains by script - say, daily, and then printing the list into a 0.0.0.0 prefixed hosts list. Thank you!
disclaimer: github user maintaining linked resource
https://en.m.wikipedia.org/wiki/Autonomous_system_(Internet)
An AS (identified by an ASN) is an autonomous system. It's comprised of multiple CIDR blocks, contiguous regions of IP addresses. The network definition (by CIDR block) is fairly dynamic, as blocks can be added, deleted, or consolidated.
An autonomous system is a single administrative domain over public IP space. Essentially, autonomous systems are what the Internet is inter-networking between, through BGP (border gateway protocol). BGP and AS are what Cisco (and other router) gear are ultimately all about.
So yes: organisations typically have one AS. Exceptions are typically the result of corporate mergers (not uncommon) or government space (where the domains are large).
(Disclaimer: I'm not a networking bithead, don't muck with routers much, and have a rough knowledge of much of this, though it should be vaguely accurate.)
fdda274d380ki4frcgi-rumjfjai1460158783-sonar.xx.fbcdn.net
there are probably many more like that. $ curl ipinfo.io/`dig +short facebook.com | head -n1`
{
"ip": "69.171.230.68",
"hostname": "edge-star-mini-shv-17-prn1.facebook.com",
"city": "Menlo Park",
"region": "California",
"country": "US",
"loc": "37.4590,-122.1781",
"org": "AS32934 Facebook, Inc.",
"postal": "94025"
}
See https://ipinfo.io/developers for more detailscan I and how obtain this information myself, from the very source, for a given domain name or company or whatever it is?
I thought I was unreconcilably blocked for the duration of the hackathon, as DNS propagation disclaimers give itself 72 hours, and SSL certificates require who knows what.
I was able to get a completely new domain with Amazon Route 53 and Amazon's free SSL certificates in 20 minutes.
So yeah, I would say these blocklists are futile now, in OP's format.