If you manage a network that needs/wants to block facebook, this article may help:

If you actually manage a network, I would recommend deploying a pi-hole and sticking a few extra blocklists into it. It's a litte more work, but does a better job and gives you some nice insight in what's going on DNS-wise.
