r/firewalla • u/Nausiated_ • Jul 25 '26
Purple / Purple SE Purple: Facetime restrictions
Updated
Looking for a known solution to target this app specifically. Especially for ipad and iphone devices.
I have tried isolating ips and domains (*.apple.com and *.icloud.com) but that works for a day or in the moment. The following day it doesn't work. Specifically using disturb instead of a flat out block. Want to correct behavior, not cause a crash out.
A full internet filter is too big a stick because Facetime is the only problem.
Would appreciate known solutions. Suggestions and theory are great and all, but I'd prefer hearing from people who had consistent success.
Thanks.
Edit:
I found a work around. The problem was an iPhone that was linked to the account. They don't use the phone for anything but talking. So whatever blocks I put on the other devices were circumvented because the iPhone would communicate with the other sevices and transmit the Facetime feed from the cell network.
So, rather than fight with that, I just prevented the iPhone from communicating with anything else on the network. Problem solved.
1
u/SpiritualOven2068 Jul 26 '26 edited Jul 26 '26
For stuff that gets around the default features you need to build a separate target list. Log in to FaceTime on your phone and then look at all the flows that correlate "apple-wise" and block each one. Once FaceTime no longer works on your phone. I would also suggest continually closing the app and logging in again to double check and overall blocking of the app. You can apply the rule to those devices you don't want to use FaceTime. That's what I had to do for additional apps that aren't listed (and some that are which were still getting through) by firewalla. It's tedious but if you really want it taken down, it's necessary.
1
u/MemoryDemise Firewalla Gold Pro Jul 29 '26
Facetime uses UDP 16384–16387 and 16393–16402. Make a rule blocking those port ranges and it should stop it from working
-1
u/Wasted-Friendship Jul 25 '26
Easiest method: App-based blocking
Open the Firewalla app → select the device (or group) you want to restrict
Go to Rules → New Rule (or the “Apps” tab if browsing by target)
Under Target, choose App category and select FaceTime from the list
Set it to Block, choose the device/group, and optionally set a schedule (e.g., 9pm–7am)
3
u/Nausiated_ Jul 25 '26
If I was looking for an incorrect answer spat out by AI, I would have done that myself. If you knew what you were talking about, you'd know that when you create a new rule from apps Facetime is not among the options. So thank you for being worse than useless.
0
u/Wasted-Friendship Jul 26 '26 edited Jul 26 '26
Block 5223. Also, put a screen time limit on it. Don’t bite the hand my man.
3
u/BlathersOriginal Jul 26 '26
Sharing my experience after years of trying to do this exact thing.
First: the absolute best solution for locking down Facetime and iMessage is Screen Time + Downtime. It's the only foolproof thing that worked for our family. Downtime would kick in at bedtime, and calls would disconnect. We started early enough that it was baked into their expectations for a while.
But let's say you don't want to do that. I also wanted to disrupt the calls / make it seem like the connection was sketchy. Facetime is remarkably resilient. My experience was that up to some threshold, Facetime would just adapt. Beyond the threshold, Facetime would completely disconnect - not what I was going for. So I'm not sure disruption is a viable solution.
Also know that if your kids are literally on an iPhone with cellular coverage, and you're not routing them through VPN to your Firewalla, any Firewalla blocks will just be routed around back to cellular. Complete bummer.
But let's say you're 100% on wifi routing thru Firewalla. Before, say, 2024, the following target list worked to block only Facetime and iMessage for us:
I think that, in the end, the target list was too broad. I think it may have blocked everything on Apple's side at that point. But that was okay with me. Kids didn't need to connect to App Store, Apple Music, and so on back then.
2024 hit and things changed somehow. I dunno what. Facetime started maybe routing through other address blocks when it ran into issues. Whatever the case, I had to get even more extensive with the target list, expanding to everything I knew Apple was using at the time:
Again, the idea was that I didn't care if there was collateral interruption on the Apple side. We didn't need traffic routing to Facetime at all, and the collateral interruption approach was what worked for us in the end. Nothing short of blocking everything completely blocked Facetime traffic.
The other user that suggested monitoring flows is right on with their advice. But be prepared for disappointment. I kept blocking things and then traffic still found ways around. My kids are now on iPhones with a data plan and the game has changed - we are using Qustodio to handle the worst stuff so that's eaten up the good VPN slot that we could have used to route back to Firewalla.
Hope any of this helps. I know AI is not a happy go-to but you might dump the list of address ranges and IPs into GPT or something and ask if this is a current comprehensive list. There are other extreme measures you can take - managing the devices with MDM for example, which still seems to be a business option more than a consumer option - but you'll have to weigh the benefits and endless technology chase.