How to control internet with Layer7 protocol

Hello Guys

I need help. I’m using Routerboard 1100AHx2 in Head office and connecting with IPsec tunnel to our 21 branches. Our branches have Routerboard450G. So i have to control our internet using and must deny some pages like youtube , facebook and other. Now i’m using Webproxy but that’s not good enough. So that i want to use layer7 protocol but i can’t configure it.

i hope someone help me and thank you so much

Even if you setup layer 7 rules to block these websites how will you stop users going to https://www.google.com or https://www.facebook.com ? Will you block all port 443 traffic?

i don’t know. But in Webproxy, i redirect port 443 to port 8080 and i can block these sites. So do you have a any idea for blocking HTTPS protocol with Layer7 rule?

That was my point, you can’t block websites using https/443 as it’s encrypted, so you would have to block the IP addresses and keep the list up to date. Using web proxy should be good enough for blocking port 80 sites http://wiki.mikrotik.com/wiki/How_to_Block_Websites_%26_Stop_Downloading_Using_Proxy

(usa tu traductor)

hola…

la respuesta la puedes encontrar en:

http://mikrotik-learning.blogspot.com/2011/11/mikrotik-how-to-block-facebook-youtube.html#.UU0dh1dn1fR

y Funciona muy bien.

lo que no he logrado es hacerlo funcionar solo para algunas IPs de la red.

This actually works, takes a bit to kick in though, only tested in chrome.