Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 10,984
» Latest member: Jamesoneve
» Forum threads: 67
» Forum posts: 179

Full Statistics

Latest Threads
speedyindex google schola...
Forum: Admin interface
Last Post: Williamtz
03-18-2024, 11:43 PM
» Replies: 0
» Views: 640
WIZARD
Forum: Installation
Last Post: emmsch
09-18-2023, 02:48 PM
» Replies: 0
» Views: 1,496
Proxmox
Forum: Installation
Last Post: benoit
08-30-2023, 04:54 AM
» Replies: 1
» Views: 1,165
Getting started
Forum: Users and devices connection management
Last Post: byronbulb
07-03-2023, 02:30 PM
» Replies: 0
» Views: 3,543
Dual network interfaces n...
Forum: Network
Last Post: whopz
06-20-2023, 11:07 PM
» Replies: 0
» Views: 2,223
Hardware
Forum: Users and devices connection management
Last Post: emmsch
06-19-2023, 08:12 AM
» Replies: 2
» Views: 4,550
iptables issue with times...
Forum: Profiles
Last Post: rdavila
02-05-2023, 02:20 PM
» Replies: 1
» Views: 3,043
Custom iptables rules
Forum: Network
Last Post: rdavila
02-05-2023, 02:08 PM
» Replies: 1
» Views: 2,143
Schedule does not seem to...
Forum: Profiles
Last Post: rdavila
01-11-2023, 07:52 PM
» Replies: 1
» Views: 1,165
[RESOLVED] Install script...
Forum: Installation
Last Post: m_keexybox_user
01-03-2023, 02:22 PM
» Replies: 0
» Views: 1,310

Lightbulb Time allocation
Posted by: mrwhite2020 - 01-10-2021, 11:22 PM - Forum: Users and devices connection management - Replies (1)

Hi everyone,

I'm not sure if this is a feature request or whether other users have found a solution.  Keexybox does most of what I am looking for and I'm a new raspberry pi user, so this may be a really easy request.

In addition to users/profiles/devices we can allocate time schedules from Monday to Sunday 00:00 to 23:59 each day, which is awesome.

What I'd like to also do is to be able to allocate to a user:
 - time alocation;
in addition to the time schedule above.

So I can allocated to:
 - a user;
 - a maximum of 4hrs internet / time allocation (day/week)

So I would allocate to a user:
 - a profile;
 - a time schedule;
 - a time allocation (4hrs/day total)

Looking forward to what people have to suggest.

Cheers,

Karl Angel.

Print this item

  Network Topology Question
Posted by: ramkhal - 12-24-2020, 06:50 PM - Forum: Users and devices connection management - Replies (1)

Hi
I have a network which I have attached a pdf file with its topology inside.

There is an outdoor modem, an indoor router (with dhcp disabled) connected to it with cable and all the devices are connected to this router wirelessly.

My Question is what topology should I use for this configuration? Should I change the ip addresses or other things on the router and Keexybox?

I am installing KeexyBox on a raspberry pi 2, with only ethernet cable and no wifi module. Can I set things up in a way that wifi connected devices connect to the router, then checked by keexybox and after that they access internet?

Thanks in advance



Attached Files
.pdf   Dec 24 17h19.pdf (Size: 182.1 KB / Downloads: 10)
Print this item

  social media apps
Posted by: zeyad - 12-21-2020, 02:00 PM - Forum: Profiles - Replies (1)

Hi guys

Very impressive work, one question please :

Is it possible to block social media apps in profiles (Facebook, Instagram, ….etc.)?

Print this item

  Problem with Mobile Amazon App and Keexybox self-signed certificate
Posted by: ricardodiaz - 12-18-2020, 05:44 PM - Forum: SSL Certificate - Replies (1)

Hi!,

I already have the application configured for each of the devices we have at home, and the following happens to me:

From my mobile phone, I have problems to use the Amazon app, every time I try to access any option of the application, it shows an error page and prevents me from using it (this happens when the device is connected and making the dns queries to via KeexyBox).

After reviewing the phone's logcat, I see that the requests made by the application against the Amazon servers try to establish the SSL connection and it fails (handshake failed) and this, I imagine, must be due to the self-signed certificate generated from the KeexyBox application.

Is it possible in some way to configure a trusted certificate such as LetsEncrypt in the application to solve this problem?

(As long as this is the cause ... which is not clear to me either).

I paste an excerpt from my android's logcat:



Code:
12-12 21:11:54.574 13267 13287 W System  : A resource failed to call end.
12-12 21:11:54.575 13267 13287 W System  : A resource failed to call close.
12-12 21:11:54.577 13267 14148 E chromium: [ERROR:ssl_client_socket_impl.cc(960)] handshake failed; returned -1, SSL error code 1, net_error -202
12-12 21:11:54.602 13267 13267 E MShopWebViewClient: onReceivedSslError: primary error: 3 certificate: Issued to: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.602 13267 13267 E MShopWebViewClient: Issued by: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.602 13267 13267 E MShopWebViewClient:  on URL: https://fls-eu.amazon.es/1/batch/1/OP/A0........
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler: {appVersion: 20.22.2.100}{errorDescription: primary error: 3 certificate: Issued to: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler: Issued by: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler:  on URL: https://fls-eu.amazon.es/1/batch/1/OP/Aal%.........


Thanks in advance.

Print this item

  Suggested topology only support wifi connection?
Posted by: pmdroz - 12-13-2020, 07:58 PM - Forum: Users and devices connection management - Replies (1)

Hi

If i use the "Suggested topology",  does it only support wifi connection?  A rasbperry only have 1 rj45 connection so i suppose that device need to be connected as wifi.  Is that right?

Thanks

Print this item

  Hard coded dns / IPs
Posted by: PronoLeaks - 12-13-2020, 01:47 PM - Forum: Blacklist - Replies (1)

Hi, just 20 mins ago, I found about this project and it looks super interesting! I think I am going to try it now on a 3b+ laying around. I had a question tho. How does this box handle hard coded queries ? Like IPs and dns ?

This is a problem I had trouble getting my head around when using similar installations / setups such as keexybox.

Is this allowing for having access to full monitoring report? (filtered maybe). I mean not only graphs but lists of outgoing queries made by my devices and their protocols ? (sorry if I am not that clear, I am not an expert). I am hoping that this project helps me reveal potential suspicious traffic made by devices.

I guess an example or two would be best. So let's say the Unifi dream machine, it has been suspected to "phone home" without user knowledge before and, so far, I haven't seen someone showing test results about that.

One more example, android devices using hard coded DNS to send data even if a user is trying to prevent this (which apparently bypasses user's attempts to block those). Again all speculations, at least to me. And I like to test stuff so, would this be a proper project / box for me to do that kind of investigation ?

I know some tools that might already do this but I am not that great when it comes to networking yet. Still learning some basics...

Anyways, I figured I'd ask and worst case, it'll be a suggestion for you guys / gals Smile

Edit:

Hmm funny that I had to make this post right before finally finding good info about this topic. Usually I wasn't able to get much out of my searches hehe. Here, this is what I mean. (idk how trustworthy this info is but it does describe well what I was trying to say)

https://labzilla.io/blog/force-dns-pihole

Print this item

  Weird behaviour on Profiles/Devices
Posted by: ricardodiaz - 12-11-2020, 06:35 PM - Forum: Profiles - Replies (7)

Hi,

The last week I installed the software on my Raspberry Pi3 and have been doing some testing.

I am running into the following problem:

I have a device to which I have assigned a certain profile:

[Image: Image1.png]

In connections, the device appears connected and with the correct profile assigned.

[Image: Image2.png]

But when consulting the statistics, the records generated by this device appear in a different profile ... in fact, if I go to view the associated connection, the profiles do not match.

I think the rules of the wrong profile are being applied...

[Image: Image3.png]

[Image: Image4.png]

I have tried restarting the connections, and even restarting the service ... but it remains the same ..

Am I doing something wrong?
Any ideas?

Thanks in advance...

EDIT:

I'm checking log files and on devices.log I can see that the device has assigned the profile ID 4


Code:
2020-12-11 19:48:45 - Enabling access for device Movil_Xiaomi_MiA3_Richi with profile ID 4, IP 192.168.0.128 and MAC 60:AB:67:86:45:E6

But on bind_queries.log, it seems that the rules applied for the device are those of profile ID 2...


Code:
11-Dec-2020 19:38:53.263 client @0x2502b58 192.168.0.128#7195 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.1$
11-Dec-2020 19:38:53.362 client @0x2502b58 192.168.0.128#18999 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.$
11-Dec-2020 19:38:53.395 client @0x2502b58 192.168.0.128#18081 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.$

Print this item

  Network topology
Posted by: SadE54 - 12-08-2020, 07:59 AM - Forum: Installation - Replies (3)

Hi ,


I would you Keexy for parental control for my children( web filtering + time planning). They're using PS4 (over wifi) , one of my kids has it's own computer (over wifi) and there's the common computer for the family.
I have a 1Gb fiber access (with freebox revolution).
I guess I have to use it has wifi access point ? Because I would avoid to route all data , at least from the main computer , through Keexy, except if it's possible to get max bandwitdh with it (currently ~400Mb from main computer). Or using only dns is enough ? What do you think is the best topology for my case ?

And because this computer is shared , is it possible to use windows accounts to log in keexy ?

Regards,

Yann

Print this item

  Hardware configuration
Posted by: gshinde - 12-06-2020, 09:05 PM - Forum: Installation - Replies (1)

Hello,

Thank you very much for this cool idea. 
What is the recommended hardware configuration for this? I've never used a Pi and I'm starting from scratch. Do you recommend Raspberry pi 4, 4GB RAM, Fan cooling? 

Will an old Raspberry pi 1 (512MB RAM) work? 

If I want Keexybox to sit before my router (Google Nest), it should be sufficiently powerful to handle the traffic. It would be helpful to list some example hardware configurations on your installation page. 

Thanks,
gs

Print this item

  Statistics Stopped Displaying
Posted by: hunty1980 - 11-17-2020, 01:21 PM - Forum: Statistics and logs - Replies (1)

Firstly - wanted to say what a great project this is - keep up the good work!!  Big Grin

I seem to have an slight issue - I've noticed that as of 20:00 on the 16th Nov my stats have stopped displaying. Any ideas what would cause them to stop showing? It's for all devices and all profiles with statistics enabled.

Thanks,

Print this item