how to allow whatsapp or specific websites for example the 192.168.10.5 only accessing netflix and whats apps and the 192.168.10.6 is only whatsapp for social media and the rest of the IP cannot connect to that social media specially the DHCP IPs
I would build this using floating rules with destination port aliases for those services. Layer 7 filtering in pfSense would require a proxy or external package to inspect destination names.
For precise filtering, you’d need to map every WhatsApp and Netflix server range. Instead, consider using a proxy or a dedicated service. I’ve used whatsapp business api for reliable message automation, and it works well with custom integrations. For your pfSense rules, maybe allow that IP full access and block others via a floating rule with destination aliases.