<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>Mikrotik.moscow [тема: Заблокировать диапазон IP-адресов (facebook)]</title>
		<link>http://mikrotik.moscow</link>
		<description>Новое в теме Заблокировать диапазон IP-адресов (facebook) форума RouterOS на сайте Mikrotik.moscow [mikrotik.moscow]</description>
		<language>ru</language>
		<docs>http://backend.userland.com/rss2</docs>
		<pubDate>Thu, 20 Aug 2026 02:28:04 -0400</pubDate>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375827">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Спасибо! Я пробовал, но всё равно получаю сообщение «сервер не найден», когда пытаюсь подключиться. <br />
			<i>09.01.2013 19:22:00, Xanadu.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375827</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375827</guid>
			<pubDate>Wed, 09 Jan 2013 19:22:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375826">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Не видел этот IP в твоём списке IP-адресов Facebook. В любом случае, хочу здесь поделиться, как я настроил свой фильтр, и возьму Facebook для примера, так как разговор идёт именно о нём.<br /><br />Моё правило фильтрации 1 &nbsp;<br />;;; блокировать fb &nbsp;<br />chain=forward src-address-list=!fwall-x dst-address-list=fb action=reject reject-with=icmp-network-unreachable<br /><br />Мой список адресов – IP-адреса Facebook, которые я сейчас блокирую: &nbsp;<br />LIST &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ADDRESS &nbsp;<br />0 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.224.37 &nbsp;<br />1 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.242.11 &nbsp;<br />2 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;66.220.149.11 &nbsp;<br />3 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;66.220.158.11 &nbsp;<br />4 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.229.11 &nbsp;<br />5 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.224.53 &nbsp;<br />6 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.234.64 &nbsp;<br />7 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;66.220.146.94 &nbsp;<br />8 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;69.171.229.70 &nbsp;<br />9 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;66.220.149.88 &nbsp;<br />10 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.234.37 &nbsp;<br />11 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.234.21 &nbsp;<br />12 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.70 &nbsp;<br />13 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.229.74 &nbsp;<br />14 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 66.220.149.94 &nbsp;<br />15 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.74 &nbsp;<br />16 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.234.69 &nbsp;<br />17 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 66.220.146.101 &nbsp;<br />18 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.40 &nbsp;<br />19 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.224.64 &nbsp;<br />20 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.14 &nbsp;<br />21 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 66.220.147.88 &nbsp;<br />22 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.237.16 &nbsp;<br />23 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.237.32 &nbsp;<br />24 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 66.220.152.16 &nbsp;<br />25 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 66.220.158.70 &nbsp;<br />26 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.247.21 &nbsp;<br />27 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.224.36 &nbsp;<br />28 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.234.39 &nbsp;<br />29 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.72 &nbsp;<br />30 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.234.23 &nbsp;<br />31 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.237.20 &nbsp;<br />32 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.237.36 &nbsp;<br />33 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.229.18 &nbsp;<br />34 &nbsp; fb &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 69.171.228.76 &nbsp;<br /><br />IP-адреса пользователей, которым я разрешаю доступ к Facebook: &nbsp;<br />LIST &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;ADDRESS &nbsp;<br />0 &nbsp; ;;; user1 fwall-x &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 192.168.1.11 &nbsp;<br />1 &nbsp; ;;; user2 fwall-x &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 192.168.1.28 &nbsp;<br />2 &nbsp; ;;; rdc &nbsp; fwall-x &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; 192.168.1.25 &nbsp;<br /><br />Как видишь, я создал две группы в списках адресов: одну для IP Facebook, которые блокирую, и одну для пользователей, которым разрешён доступ к Facebook. Затем добавил правило фильтра, которое говорит: всем, кто пытается зайти на Facebook, блокировать доступ, кроме тех, кто есть в списке адресов fwall-x.<br /><br />Делать так удобно, потому что у меня всего одно правило в списке фильтров, и им проще управлять и поддерживать. Если хочу убрать или разрешить доступ отдельному пользователю — просто добавляю его IP в разрешённый список. А если хочу заблокировать новые IP Facebook — просто добавляю их в группу fb.<br /><br />Ах да, не забудь про комментарии — они помогают понять, кто и к чему имеет доступ.<br /><br />Кстати, если хочешь заблокировать Facebook полностью, это может пригодиться. Обрати внимание на раздел Network Resources, там указаны необходимые сетевые блоки. &nbsp;<br /><noindex><a href="http://whois.arin.net/rest/customer/C02001848" target="_blank" rel="nofollow" >http://whois.arin.net/rest/customer/C02001848</a></noindex> &nbsp;<br /><noindex><a href="http://whois.arin.net/rest/customer/C02107106" target="_blank" rel="nofollow" >http://whois.arin.net/rest/customer/C02107106</a></noindex> &nbsp;<br /><noindex><a href="http://whois.arin.net/rest/customer/C02107153" target="_blank" rel="nofollow" >http://whois.arin.net/rest/customer/C02107153</a></noindex> &nbsp;<br /><noindex><a href="http://whois.arin.net/rest/customer/C02156967" target="_blank" rel="nofollow" >http://whois.arin.net/rest/customer/C02156967</a></noindex> &nbsp;<br /><noindex><a href="http://whois.arin.net/rest/customer/C02738182" target="_blank" rel="nofollow" >http://whois.arin.net/rest/customer/C02738182</a></noindex> &nbsp;<br /><br />Удачи! <br />
			<i>09.01.2013 10:12:00, rdc.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375826</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375826</guid>
			<pubDate>Wed, 09 Jan 2013 10:12:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375825">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Думаю, в вашем случае HTTP Facebook тоже будет работать, как и HTTPS. Ваши правила смотрят на dst-адреса (серверы Facebook) и блокируют трафик (неважно — http или https, это станет важно, например, если вы используете веб-прокси). Мне кажется, что теперь вы уже не попадаете под эти правила, попробуйте сделать ping &gt; <noindex><a href="http://www.facebook" target="_blank" rel="nofollow" >http://www.facebook</a></noindex> &gt; с MKT или локального компьютера и посмотрите, какой IP-адрес разрешается. Я предполагаю, что разрешённый IP не из указанных выше диапазонов? На самом деле разрешился IP 173.252.100.16, я только что проверил http — и мне показывает то же сообщение. <br />
			<i>08.01.2013 21:27:00, Xanadu.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375825</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375825</guid>
			<pubDate>Tue, 08 Jan 2013 21:27:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375824">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Думаю, в вашем случае HTTP-фейсбук будет работать так же, как и HTTPS. Ваши правила смотрят на dst-адреса (серверы Facebook) и блокируют трафик (не важно, http это или https, это станет важно, например, если вы используете веб-прокси). Похоже, вы больше не попадаете под эти правила. Попробуйте пропинговать <noindex><a href="http://www.facebook" target="_blank" rel="nofollow" >http://www.facebook</a></noindex> с MKT или локального компьютера и посмотрите, какой IP-адрес разрешается, я подозреваю, что разрешённый IP не из указанных выше диапазонов? <br />
			<i>08.01.2013 20:17:00, mixig.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375824</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375824</guid>
			<pubDate>Tue, 08 Jan 2013 20:17:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375823">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, ребята, до вчерашнего дня эти правила у меня работали: &nbsp;<br />&gt; add action = accept chain = forward src-address-List = Facebook_allow dst-address = 66.220.1.0/20 &nbsp;<br />&gt; add action = accept chain = forward src-address = Facebook_allow dst-address = 69.63.176.0/20 &nbsp;<br />&gt; add action = accept chain = forward src-address = Facebook_allow dst-address = 204.15.20.0/22 &nbsp;<br />&gt; add action = accept chain = forward src-address = Facebook_allow dst-address = 69.171.224.0/19 &nbsp;<br /><br />&gt; ip firewall filter add action = drop chain = forward comment = "Block Facebook" dst-address = 66.220.144.0/20 &nbsp;<br />&gt; ip firewall filter add action = drop chain = forward dst-address = 69.63.176.0/20 &nbsp;<br />&gt; ip firewall filter add action = drop chain = forward dst-address = 204.15.20.0/22 &nbsp;<br />&gt; ip firewall filter add action = drop chain = forward dst-address = 69.171.224.0/19 &nbsp;<br /><br />Как видите, я сделал эти правила, чтобы позволить некоторым привилегированным пользователям заходить на Facebook, а обычным — запрещать. Но теперь любой может зайти на https:\facebool.com. Помогите! <br />
			<i>08.01.2013 19:54:00, Xanadu.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375823</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375823</guid>
			<pubDate>Tue, 08 Jan 2013 19:54:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
		<item>
			<title>Заблокировать диапазон IP-адресов (facebook)</title>
			<description><![CDATA[<b><a href="http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375822">Заблокировать диапазон IP-адресов (facebook)</a></b> <i>RouterOS</i> в форуме <a href="http://mikrotik.moscow/forum/forum57/">RouterOS</a>. <br />
			Привет, ребята. У меня вопрос по поводу блокировки Facebook, YouTube и подобных сайтов. Я администрирую сеть в одной VOIP-компании (колл-центр). Я заблокировал диапазоны IP-адресов Facebook, YouTube и т.д. (гайд нашёл где-то в Гугле), и всё работает отлично. Единственная проблема — я хочу, чтобы директор компании всё-таки мог пользоваться этими сервисами на своём компьютере. Есть ли способ разрешить одному ПК (по MAC-адресу или IP) обходить эти ограничения? Что-то вроде статического IP и правила, которое позволяет обходить список заблокированных адресов и диапазонов IP? По сути, я хочу, чтобы эти правила применялись ко всей сети, кроме его компьютера. Заранее спасибо, Александр, aka hyp3R <br />
			<i>08.01.2012 19:46:00, hyp3R.</i>]]></description>
			<link>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375822</link>
			<guid>http://mikrotik.moscow/forum/forum57/83363-zablokirovat-diapazon-ip_adresov-_facebook/message375822</guid>
			<pubDate>Sun, 08 Jan 2012 19:46:00 -0500</pubDate>
			<category>RouterOS</category>
		</item>
	</channel>
</rss>
