how I can block for specific internal addresses, specific websites?
sorry for my english ...
This thread was automatically locked due to age.
Internal (Network) -> Any -> {Facebook group} : Drop
Internal (Network) -> Any -> {Facebook group} : Drop
I understand your response now - the yes was a response to the following. Ahhhhh...
I would recommend that you remove HTTP and HTTP-ALT from the Websurfing services group, and that you use the proxy in transparent mode as the easiest way to control browsung.
If you don't want to use the proxy, you'll need to find out all of the facebook IPs, puthem into a network group and add a packet filter rule at the "Top" of your list:Internal (Network) -> Any -> {Facebook group} : Drop
Cheers - Bob