Jump to content

Blocking the facebook app on ipads


Recommended Posts

Posted

Has anyone tried this?

 

we have a Bloxx box, quite happily blocking facebook through safari, I.E etc. Princiaplly as those programmes access facebook through URL.

The ipad app however uses a whole range of destination I.Ps to access, rather than URL.

 

I have set up static routes, which work in part by preventing the login part of the facebook app from working.

 

However, sometimes it will allow you to log in. and once logged in, that's it, full facebook access.

 

we are not using MDM, as the students all own their ipads, and we are unable to implement MDM for this reason

 

 

 

any ideas?

Posted
If I was doing it on any desktops or laptops I would just adjusting /etc/hosts so that facebook.com would go 10 localhost/172.0.0.1 which would just have the page not load. easier and faster than an application doing this on a computer. If there is a similar file on iOS I would adjust this.
Posted
If I was doing it on any desktops or laptops I would just adjusting /etc/hosts so that facebook.com would go 10 localhost/172.0.0.1 which would just have the page not load. easier and faster than an application doing this on a computer. If there is a similar file on iOS I would adjust this.

 

Only doable if you jailbreak the device. Not a usable solution I'm afraid. The IPs should just tie down to facebook's CDN (s-platform.ak.fbcdn.net), the akamai CDN (fbcdn-photos-a.akamaihd.net), and pct.channel.facebook.com / m.c10r.facebook.com (or similar). Bloxx should be able to reverseDNS the IPs so that if you blacklist the domains *.facebook.com & *.fbcdn.net that'll stop it. If it's not doing, I'd be tempted to contact Bloxx for a solution.

  • 3 weeks later...
Posted

We have a web content filter that blocks anything at facebook.com(which includes the app). The only way they would be able to get around it would be to not use our network or to use a VPN service.

 

-

Patrick

Posted
It will be nice when content filters are doing layer 7 app management :) I know it's on the road map for bloxx, Smoothwall and light speed :)
Posted
Meraki has some nice solutions for layer-7.

 

We are going to be trialling a sonicwall UTM which also has layer 7 on it. Will be interesting to see how it goes :)

Posted
We are going to be trialling a sonicwall UTM which also has layer 7 on it. Will be interesting to see how it goes :)

With Meraki is all cloud managed to the annual fees are kinda high. Are there any with the sonicwall UTM? If so about how much would you say?

Posted
With Meraki is all cloud managed to the annual fees are kinda high. Are there any with the sonicwall UTM? If so about how much would you say?

 

There are annual / license fee's with all the options I believe.

 

Don't have the sonic wall price in front of me will dig them out though tomorrow :)

Posted

Not really an option as these are ipads, so group policy doesn't apply.

 

 

@ittech:

 

Can you not setup a group policy for student users which blocks access using IP's?, you can on Smoothwall!

 

This would do the trick :)

Posted
Has anyone tried this?

 

we have a Bloxx box, quite happily blocking facebook through safari, I.E etc. Princiaplly as those programmes access facebook through URL.

The ipad app however uses a whole range of destination I.Ps to access, rather than URL.

 

I have set up static routes, which work in part by preventing the login part of the facebook app from working.

 

However, sometimes it will allow you to log in. and once logged in, that's it, full facebook access.

 

we are not using MDM, as the students all own their ipads, and we are unable to implement MDM for this reason

 

 

 

any ideas?

Do you have the range of IP's and if you did you could put a proxy in squid with dansguardian for example and block the addresses, ive been after the IP's or other host-names of Facebook for a while for the same reason i managed to stop some bits but not the majority, but if i had the other addresses i could block it out.

  • 1 month later...
Posted

I managed to find a complete list of addresses in the end, but the only way we've found so far to block apps effectively is to make our DNS servers authoritative for the domains that the apps are trying to reach. but it's a nigh on impossible task trying to keep up with the apps that are popping up. the number of proxy bypass applicatuions available on the itunes store is ridiculous and clearly it's unfeasible to find destination addresses for every app, block and then whitelist accordingly.

MDM isn't an option either as cost is too high, around £30 per user per annum for an MDM solution that allows us to control app access whilst students are on site. The meraki solution looks OK, but still does not allow control over what apps can be used and which cannot. The ideal solution would be app whitelisiting and blacklisting on say a bloxx box or smoothy. (or equivalent piece of hardware) is anyone aware of anything? Our Bloxx renewal is due this summer and we could really do with something that allows greater control over in app, internet access.

Posted
I managed to find a complete list of addresses in the end, but the only way we've found so far to block apps effectively is to make our DNS servers authoritative for the domains that the apps are trying to reach. but it's a nigh on impossible task trying to keep up with the apps that are popping up. the number of proxy bypass applicatuions available on the itunes store is ridiculous and clearly it's unfeasible to find destination addresses for every app, block and then whitelist accordingly.

MDM isn't an option either as cost is too high, around £30 per user per annum for an MDM solution that allows us to control app access whilst students are on site. The meraki solution looks OK, but still does not allow control over what apps can be used and which cannot. The ideal solution would be app whitelisiting and blacklisting on say a bloxx box or smoothy. (or equivalent piece of hardware) is anyone aware of anything? Our Bloxx renewal is due this summer and we could really do with something that allows greater control over in app, internet access.

 

If you have something fully inline between your firewall / router and switches then the traffic will pass through it and will be filtered (the app is still accessing a URL or ten, which you can then see through logs and recategorise / block / allow if necessary). If you forward proxy you'll miss stuff.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...