Set up a block rule on the LAN on the firewall. Source IP 192.168.1.100 sorce port any destination IP 72.30.38.140 and destination port 80. (and again 443. Also, you IP will probably be different than the one for me.)
For number two, you can put nytimes.com in the DNS forwarder resolving to 74.125.227.99. However, no one will get to nytimes then.
If you need more than this, you may want Untangle, not m0n0wall.
|