RE: Blocking messengers like msn, skype etc

From: n (n_at_discussions.microsoft.com)
Date: 12/01/04

  • Next message: Nitin: "Re: Failover, load balancing, and the like"
    Date: Tue, 30 Nov 2004 20:59:02 -0800
    
    

    i dont know exaclty how skype works but one way you could do it is if you
    setup a protocol rule to only allow http.
    then setup a destination set with the skype ip range/dns names.
    finally create a site and content rule to allow everything except the skype
    destination set.
    apply the protocol and site and content rules to your clients.

    since these things require authentication, if you block the skype
    authentication servers ip's/dns names it cant authenticate/connect *evil
    grin*.

    you could also use group policy to stop the progam from being run.

    not sure if thats the answer you were looking for.

    "Bernard Dijkhuizen" wrote:

    > Hello,
    >
    > I want to allow only normal http traffic on client pc's.
    > Now when a user start skype, he can chat and voicechat and I can only
    > prevent him from doing so by ad the skype to the list of non allowed apps in
    > the firewall client.
    >
    > Is there a way to block everything in http besides normal http traffic or is
    > that the beginning of new problems and should I just name every application
    > in the firewall client setting in ISA ?
    >
    > Or.... is there a better way...
    >
    > btw... I use ISA 2000
    >
    > Thanks a lot
    >
    > Bernard
    >
    >
    >


  • Next message: Nitin: "Re: Failover, load balancing, and the like"

    Relevant Pages

    • Re: Block Skype using ISA 2004
      ... close all not necessary outgoing ports ... blocking specific http traffic could be accomplished per http filtering ... Because Skype is programmed and even gets improved in bypassing nearly ...
      (microsoft.public.isa)
    • Re: [Full-disclosure] [inbox] Re: [ Capture Skype trafic ]
      ... but that document outlines HOW Bluecoat can and does block Skype. ... A packet or protocol anaylizer Proxy will block anything that is NOT ... Skype does not conform to HTTP ...
      (Full-Disclosure)
    • Re: [fw-wiz] IPS vs. Firewalls (why vs. ?)
      ... around 'default permit' or 'default deny'. ... discard anything that was not exactly plain HTTP. ... To truly understand what firewall administrators are up against, read the Skype firewall FAQ at http://www.skype.com/help/guides/firewall.html ... This option results in Skype working most reliably. ...
      (Firewall-Wizards)
    • Re: Not able to allow skype
      ... week ago I saw in the monitoring that it's trying to go over port 33033. ... Sometimes you are able to sign in to skype but not to call. ... will have trouble then connecting from home with a proxy filled in. ... Can it be something to do with the webproxy filter which is on for http ...
      (microsoft.public.isa)