Welcome, Guest
You have to register before you can post on our site.

Username
  

Password
  





Search Forums

(Advanced Search)

Forum Statistics
» Members: 8,786
» Latest member: sarimshaikh
» Forum threads: 66
» Forum posts: 181

Full Statistics

Latest Threads
[RESOLVED] Install script...
Forum: Installation
Last Post: sarimshaikh
11-06-2024, 07:10 PM
» Replies: 1
» Views: 3,420
Network Topology Question
Forum: Users and devices connection management
Last Post: sarimshaikh
11-06-2024, 12:28 PM
» Replies: 2
» Views: 22,433
purely device based
Forum: Users and devices connection management
Last Post: sarimshaikh
11-06-2024, 12:25 PM
» Replies: 2
» Views: 21,537
WIZARD
Forum: Installation
Last Post: emmsch
09-18-2023, 02:48 PM
» Replies: 0
» Views: 3,450
Proxmox
Forum: Installation
Last Post: benoit
08-30-2023, 04:54 AM
» Replies: 1
» Views: 2,571
Getting started
Forum: Users and devices connection management
Last Post: byronbulb
07-03-2023, 02:30 PM
» Replies: 0
» Views: 7,401
Dual network interfaces n...
Forum: Network
Last Post: whopz
06-20-2023, 11:07 PM
» Replies: 0
» Views: 4,501
Hardware
Forum: Users and devices connection management
Last Post: emmsch
06-19-2023, 08:12 AM
» Replies: 2
» Views: 6,553
iptables issue with times...
Forum: Profiles
Last Post: rdavila
02-05-2023, 02:20 PM
» Replies: 1
» Views: 4,682
Custom iptables rules
Forum: Network
Last Post: rdavila
02-05-2023, 02:08 PM
» Replies: 1
» Views: 3,250

  Network Topology Question
Posted by: ramkhal - 12-24-2020, 06:50 PM - Forum: Users and devices connection management - Replies (2)

Hi
I have a network which I have attached a pdf file with its topology inside.

There is an outdoor modem, an indoor router (with dhcp disabled) connected to it with cable and all the devices are connected to this router wirelessly.

My Question is what topology should I use for this configuration? Should I change the ip addresses or other things on the router and Keexybox?

I am installing KeexyBox on a raspberry pi 2, with only ethernet cable and no wifi module. Can I set things up in a way that wifi connected devices connect to the router, then checked by keexybox and after that they access internet?

Thanks in advance



Attached Files
.pdf   Dec 24 17h19.pdf (Size: 182.1 KB / Downloads: 10)
Print this item

  social media apps
Posted by: zeyad - 12-21-2020, 02:00 PM - Forum: Profiles - Replies (1)

Hi guys

Very impressive work, one question please :

Is it possible to block social media apps in profiles (Facebook, Instagram, ….etc.)?

Print this item

  Problem with Mobile Amazon App and Keexybox self-signed certificate
Posted by: ricardodiaz - 12-18-2020, 05:44 PM - Forum: SSL Certificate - Replies (1)

Hi!,

I already have the application configured for each of the devices we have at home, and the following happens to me:

From my mobile phone, I have problems to use the Amazon app, every time I try to access any option of the application, it shows an error page and prevents me from using it (this happens when the device is connected and making the dns queries to via KeexyBox).

After reviewing the phone's logcat, I see that the requests made by the application against the Amazon servers try to establish the SSL connection and it fails (handshake failed) and this, I imagine, must be due to the self-signed certificate generated from the KeexyBox application.

Is it possible in some way to configure a trusted certificate such as LetsEncrypt in the application to solve this problem?

(As long as this is the cause ... which is not clear to me either).

I paste an excerpt from my android's logcat:



Code:
12-12 21:11:54.574 13267 13287 W System  : A resource failed to call end.
12-12 21:11:54.575 13267 13287 W System  : A resource failed to call close.
12-12 21:11:54.577 13267 14148 E chromium: [ERROR:ssl_client_socket_impl.cc(960)] handshake failed; returned -1, SSL error code 1, net_error -202
12-12 21:11:54.602 13267 13267 E MShopWebViewClient: onReceivedSslError: primary error: 3 certificate: Issued to: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.602 13267 13267 E MShopWebViewClient: Issued by: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.602 13267 13267 E MShopWebViewClient:  on URL: https://fls-eu.amazon.es/1/batch/1/OP/A0........
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler: {appVersion: 20.22.2.100}{errorDescription: primary error: 3 certificate: Issued to: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler: Issued by: CN=keexybox.keexybox,OU=Home,O=Keexybox,L=Somewhere,ST=Some-State,C=FR;
12-12 21:11:54.621 13267 13267 D com.amazon.mobile.error.log.AppErrorLogHandler:  on URL: https://fls-eu.amazon.es/1/batch/1/OP/Aal%.........


Thanks in advance.

Print this item

  Suggested topology only support wifi connection?
Posted by: pmdroz - 12-13-2020, 07:58 PM - Forum: Users and devices connection management - Replies (1)

Hi

If i use the "Suggested topology",  does it only support wifi connection?  A rasbperry only have 1 rj45 connection so i suppose that device need to be connected as wifi.  Is that right?

Thanks

Print this item

  Hard coded dns / IPs
Posted by: PronoLeaks - 12-13-2020, 01:47 PM - Forum: Blacklist - Replies (1)

Hi, just 20 mins ago, I found about this project and it looks super interesting! I think I am going to try it now on a 3b+ laying around. I had a question tho. How does this box handle hard coded queries ? Like IPs and dns ?

This is a problem I had trouble getting my head around when using similar installations / setups such as keexybox.

Is this allowing for having access to full monitoring report? (filtered maybe). I mean not only graphs but lists of outgoing queries made by my devices and their protocols ? (sorry if I am not that clear, I am not an expert). I am hoping that this project helps me reveal potential suspicious traffic made by devices.

I guess an example or two would be best. So let's say the Unifi dream machine, it has been suspected to "phone home" without user knowledge before and, so far, I haven't seen someone showing test results about that.

One more example, android devices using hard coded DNS to send data even if a user is trying to prevent this (which apparently bypasses user's attempts to block those). Again all speculations, at least to me. And I like to test stuff so, would this be a proper project / box for me to do that kind of investigation ?

I know some tools that might already do this but I am not that great when it comes to networking yet. Still learning some basics...

Anyways, I figured I'd ask and worst case, it'll be a suggestion for you guys / gals Smile

Edit:

Hmm funny that I had to make this post right before finally finding good info about this topic. Usually I wasn't able to get much out of my searches hehe. Here, this is what I mean. (idk how trustworthy this info is but it does describe well what I was trying to say)

https://labzilla.io/blog/force-dns-pihole

Print this item

  Weird behaviour on Profiles/Devices
Posted by: ricardodiaz - 12-11-2020, 06:35 PM - Forum: Profiles - Replies (7)

Hi,

The last week I installed the software on my Raspberry Pi3 and have been doing some testing.

I am running into the following problem:

I have a device to which I have assigned a certain profile:

[Image: Image1.png]

In connections, the device appears connected and with the correct profile assigned.

[Image: Image2.png]

But when consulting the statistics, the records generated by this device appear in a different profile ... in fact, if I go to view the associated connection, the profiles do not match.

I think the rules of the wrong profile are being applied...

[Image: Image3.png]

[Image: Image4.png]

I have tried restarting the connections, and even restarting the service ... but it remains the same ..

Am I doing something wrong?
Any ideas?

Thanks in advance...

EDIT:

I'm checking log files and on devices.log I can see that the device has assigned the profile ID 4


Code:
2020-12-11 19:48:45 - Enabling access for device Movil_Xiaomi_MiA3_Richi with profile ID 4, IP 192.168.0.128 and MAC 60:AB:67:86:45:E6

But on bind_queries.log, it seems that the rules applied for the device are those of profile ID 2...


Code:
11-Dec-2020 19:38:53.263 client @0x2502b58 192.168.0.128#7195 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.1$
11-Dec-2020 19:38:53.362 client @0x2502b58 192.168.0.128#18999 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.$
11-Dec-2020 19:38:53.395 client @0x2502b58 192.168.0.128#18081 (fr.app.chat.global.xiaomi.net): view view_profile_2: query: fr.app.chat.global.xiaomi.net IN A + (192.$

Print this item

  Network topology
Posted by: SadE54 - 12-08-2020, 07:59 AM - Forum: Installation - Replies (3)

Hi ,


I would you Keexy for parental control for my children( web filtering + time planning). They're using PS4 (over wifi) , one of my kids has it's own computer (over wifi) and there's the common computer for the family.
I have a 1Gb fiber access (with freebox revolution).
I guess I have to use it has wifi access point ? Because I would avoid to route all data , at least from the main computer , through Keexy, except if it's possible to get max bandwitdh with it (currently ~400Mb from main computer). Or using only dns is enough ? What do you think is the best topology for my case ?

And because this computer is shared , is it possible to use windows accounts to log in keexy ?

Regards,

Yann

Print this item

  Hardware configuration
Posted by: gshinde - 12-06-2020, 09:05 PM - Forum: Installation - Replies (1)

Hello,

Thank you very much for this cool idea. 
What is the recommended hardware configuration for this? I've never used a Pi and I'm starting from scratch. Do you recommend Raspberry pi 4, 4GB RAM, Fan cooling? 

Will an old Raspberry pi 1 (512MB RAM) work? 

If I want Keexybox to sit before my router (Google Nest), it should be sufficiently powerful to handle the traffic. It would be helpful to list some example hardware configurations on your installation page. 

Thanks,
gs

Print this item

  Statistics Stopped Displaying
Posted by: hunty1980 - 11-17-2020, 01:21 PM - Forum: Statistics and logs - Replies (1)

Firstly - wanted to say what a great project this is - keep up the good work!!  Big Grin

I seem to have an slight issue - I've noticed that as of 20:00 on the 16th Nov my stats have stopped displaying. Any ideas what would cause them to stop showing? It's for all devices and all profiles with statistics enabled.

Thanks,

Print this item

  Adding Blacklist takes "forever" on rpi3
Posted by: momothecat - 10-06-2020, 01:48 AM - Forum: Blacklist - Replies (4)

Hi all,

I'm using RPI 3B+ as h/w for keexybox. When I tried to add the blacklist from shallalist it takes more than 3 hours until my box responding again and adding blocklist from v.firebog.net takes more then 1 hour. Is that normal operation?

Anybody have experience with RPI 4?

Thanks

Print this item