× Attn: Nighthawk Pro Gaming members, we have recently released firmware to address a critical security vulnerability. For more information click here. .
× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Orbi WiFi 7 RBE973
Reply

Blocking Sites

gfeldman
Aspirant

Blocking Sites

In the "Security" / "Blocked Sites" tab in the router administration portal, I listed a domain name that I wanted to block for out-going / in-coming access. ("Allow trusted IP addresses" is NOT checked.) It doesn't seem to work.  (My previous Asus Router had a similar option, and it worked fine -- prior to buying this router, the Netgear sales support contact concurred that this was a standard capability.)  I'm hoping that I don't need to subscribe to any premium service to use this basic feature.  Are there any other settings that I need to invoke? What is the most effective way to block such traffic from a single domain?  THANKS. - GARY

Message 1 of 3
CrimpOn
Guru

Re: Blocking Sites

The router function to "Block Sites" is a hold-over from "days of yore" and is no longer of much practical use.  My experiment with the original Orbi router (RBR50) was that it will block http access as advertised, but does not block any other access (such as ICMP [ping] or secure web [https])

 

Please give this experiment a try:

  • Go into Security, Block Sites and add these two entries:
    • sexykitten
    • ford
  • Then, open a command window and attempt to ping them.
    • ping sexykitten.com will return "Ping request could not find host sexykitten.com. Please check the name and try again."
      (This is because there appears to be no such URL. - although there certainly should be one!)
  • Open a web browser and attempt to browse to the unencrypted (http) version of these sites:
    • http://sexykitten.com will return an error that the web site does not exist.
    • http://ford.com will return an error that  "Web Site Blocked by NETGEAR Firewall", complete with bold RED banners across the entire page.
  • In the web browser, attempt to browser to the secure web sites:

In other words, the feature is basically worthless in today's world where 99% of all web sites are https.

 


@gfeldman wrote:

What is the most effective way to block such traffic from a single domain?  THANKS. - GARY


There are two generally accepted methods to accomplish this:

  • Place some device upstream from the Orbi router which will block connections, such as another router.
  • Change the Orbi router to resolve DNS with something that will reject the URL's that you want it to, such as:
    • OpenDNS using a "free" account, or
    • Your own DNS server, such as Pi-Hole.

 

Message 2 of 3
gfeldman
Aspirant

Re: Blocking Sites

Thank you both - appreciate your responsiveness. What a shame that Netgear is focused on premium services and allow their existing adm module sw to degrade into garbage. Leaves a bitter taste.

Now on (the FREE) openDNS.
Message 3 of 3
Top Contributors
Discussion stats
  • 2 replies
  • 1044 views
  • 0 kudos
  • 2 in conversation
Announcements

Orbi 770 Series