Block Youtube on computers and smartphone apps

Yes, using tls-host is in my experience the best result with least effort

add action=reject chain=forward in-interface-list=LAN protocol=tcp reject-with=tcp-reset tls-host=*.googlevideo.com

Plus a rule to block quic. It is resistant to DoHS, but not against VPN. It requires only one simple and easy to maintain filter rule.
Until you realize there are thousands of other video sites and streaming portals still working and requiring rules.
At the end it is a hare and hedgehog race with your users you hardly ever win.

So you’re all responsible for all those complaints about youtube / facebook beeing slow or non functional, because you put crap limits on things.

I’m not :wink:

I only apply such filters for stupid paying customers wanting it. Because they only know YouTube for video and Facebook for social media. So they think trying to block those two sites helps anything.
What I sometimes do on sites with low bandwidth uplink is using tls-host rules to apply youtube/netflix etc. (whatever their favorite video/streaming sites are) to low priority queues. So they can watch videos without having to fear disrupting ongoing Zoom/Teams/SIP calls.
But even for such use cases, I started to prefer Cake queues. Cake does priorisation automatically with mostly good results without requiring to maintain a set of tls-host rules for individual DNS hosts.

Hi

blocking youtube will cos issues in some google services such as app/gmail/etc. they use same IPs and domains for google global cache and if you block it it will move your ip into next GGC node.
but you can burst queue for video like 2kbps for 5-10sec which make video in downloads loop.

google/Meta/Amazon CDNs they not one IP or range you can block it some videos stored in local GGC and other in another country.

if you need it urgently better talk with your ISP to block your Public IP from getting videos only but I don’t know if google accept to do it.

also Working on L7 filtering its but you on CPU load for mikrotik.

Regards.

Yay! The point here (especially for ipv6 (Always) OR ipv4 on cake located on the nat router) is that it manages flows to hosts better. A host doing voip and one doing netflix and one doing torrent get balanced automatically, each getting 1/3 the bandwidth, and what you dont use gets shared equally, so voip experiences zero queuing delay, because it is lightweight.

I am not big on the word prioritization, what lies underneath is per host/per flow fq. https://arxiv.org/abs/1804.07617

You turn it off in the clients.

I accompished the goal by having some control on the clients and Pi-Hole..

Disabled DoH (DNS over HTTPS) and set Pi-Hole to block YouTube.

I also have 8.8.8.8 and 8.8.4.4 blocked so that the Application can’t try it’s own lookups.

And this is what I say, to do that you need to have control of the clients, just as I did write above.
In a company network with company rules ok. As an IPS not.


\

Use Splunk> to log/monitor your MikroTik Router(s).--> MikroTik->Splunk :mrgreen:
Backup config to Gmail -->Backup
Block users that tries too use non open ports -->Block

All this posts, but still valid what is written on post #2
All is useless after that post, no matter what users writes…
http://forum.mikrotik.com/t/block-youtube-on-computers-and-smartphone-apps/160031/1

Please stop adding fake signatures, on the forum they are disabled on purpose, and adding this is spam, because users can’t block your text from being seen.

I will do.

Thank you for your courtesy. Really… thanks…

from my experience , if u want to block https traffic defiantly MT can do perfectly, but if u want on application level, i found useful by using OpenDNS

If it was exquisite Italian Art, it may pass the rextended litmus test. :slight_smile:
So perhaps next time a naked David with half a prick :wink:

Please, stop to spread wrong info. You can not assume, that, in case, you did not succeed in blocking, nobody else can do, as well.
I.e. what does any browser, trying to use QUIC, in case UDP port 443 blocked in router ?
There is an old proverb, in Chinese: Those, who do not know, talk. Those, who know, do not talk.

An old North American Proverb, if you open your mouth any further, will be able to fit both feet in it !!

[ caveat: I know sheite about quic, quiddich etc. but I do like proverbs and the occasional reverb ]

What I wrote, does work.

My network, my rules.. Don't like my rules, you'll find your MAC address(es) blocked.

My AP already doesn't allow 'randomized MACs' from connecting.

Did you forget about the topic?
Please point me to the point where you explain exactly how: "Block Youtube on computers and smartphone apps" and we mean, youtube only, of course.

Is not correct, on post #2
supposed: no control on user devices

And if some tries to block some, you can always use an external service.

This is not a commercial, since it free, but you get a free Oracle VPS with:
4 strong ARM CPU (aarc64)
24 GB ram
200GB disk

  • much more
    Free for life

So I can setup a proxy server/vpn +++ for free and bypass the most.

I can set it up so when I do go to youtube.jotne.it than it opens youtube.com in my url. Cloudflare ZeroTrust (free for home users)