sábado, 13 de marzo de 2021

Mikrotik: Bloquear Netflix con Layer7

 Mikrotik: Bloqueo de Netflix con Layer7

MikroTik RouterOS 6.48.1
 
1ro:  
Mediante el terminal: En ip / firewall / layer7protocols

/ip firewall layer7-protocol
add name=Block_Netflix regexp="^(.*|\.)(Nflxso|Nflxvideo|Netflix)\.(net|com)"

o

/ip firewall layer7-protocol
add name=Block_Netflix regexp="^.+(netflix.com|netflix.net|nflxext.com|nflximg.com|nflximg.net|nflxso.net|nflxvideo.net|.netflix.).*$"

En Winbox esta imagen:




2do:
En el Terminal: En ip / firewall / filter rules


/ip firewall filter
add action=drop chain=forward comment=Drop_NETFLIX layer7-protocol=\
    Block_Netflix

En Winbox esta otra imagen:



Fuente: https://buananetpbun.github.io/mikrotik/block-netflix-layer7-content-tls.html
----------------------------------------------------------------------------------------------------------------
Block Netflix with "Layer 7" or "Content" or "TLS
----------------------------------------------------------------------------------------------------------------

Block Netflix With "Layer-7"

/ip firewall layer7-protocol
add name=Netflix regexp="^.+(netflix.com).*\$"
/ip firewall filter
add action=drop chain=forward layer7-protocol=Netflix


Block Netflix With "Content"

/ip firewall filter
add action=drop chain=forward content="netflix.com" 
add action=drop chain=forward content=".netflix."


Block Netflix With "TLS"

/ip firewall filter
add action=drop chain=forward protocol=tcp tls-host="netflix.com"
add action=drop chain=forward protocol=tcp tls-host="*.netflix.*"

Credit: www.o-om.com

----------------------------------------------------------------------------------- por content video block

https://github.com/misterkrittin/Scripts-MikroTik/blob/main/%5BScript-MikroTik%5D%20Blocking%20Netflix%20traffic%20using%20RouterOS.txt

/ip firewall filter
add action=drop chain=forward dst-address-list=Netflix src-address=192.168.50.0/24 comment="Blocking Netflix traffic using RouterOS"

/ip firewall mangle
add action=add-dst-to-address-list address-list=Netflix address-list-timeout=4w2d chain=prerouting content=nflxvideo.net src-address=192.168.50.0/24 comment="Detecting IP Addresses Netflix"