Re: Block Skype using ISA 2004



Hi Daniel,

answered this one via email.

Best Regards,
Sascha

"Daniel" wrote:

Hi, what network sniffer software do you use to detect skype 2.0 signature ?

Daniel

"SaschaC" <SaschaC@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
news:62BB1A5E-B5D6-4D12-9BC3-4A68B079D5C7@xxxxxxxxxxxxxxxx
Hi,

- close all not necessary outgoing (and of course incoming) ports
- blocking specific http traffic could be accomplished per http filtering
...
https://blogs.technet.com/isablog/archive/2006/07/03/439980.aspx

Therefor you need the correct User-Agent: Skype signature
e.g. for Skype 2.0.0.69 the signature is "User-Agent: SkypeÖ 2.0"

In chapter 3 you will find a how to obtain a signature
http://www.microsoft.com/technet/isa/2004/plan/httpfiltering.mspx

Because Skype is programmed and even gets improved in bypassing nearly
every
barrier, it might be necessary to improve and change the settings to block
skype.

One uncomfortable solution for users is to activate authentication for
outgoing https/443 traffic but it will help.

Here is just an organisational approach (no 5)
http://www.isaserver.org/pages/newsletters/june2006.asp

Hope it'll help in your case,
Sascha

"James_d" wrote:

Ok.

If you wish to allow http and https access for users to access the web
how
do you block skype?

"SaschaC" wrote:

HI James,

here are the official infos from skype what ports should be opened or
avaible
http://www.skype.com/help/guides/firewall.html

just turn it around and skype is locked out.

Regards,
Sascha

"James_d" wrote:

Is it possible to block Skype using ISA 2004
Thanks

James



.



Relevant Pages

  • Re: Block Skype using ISA 2004
    ... what network sniffer software do you use to detect skype 2.0 signature? ... close all not necessary outgoing ports ... blocking specific http traffic could be accomplished per http filtering ...
    (microsoft.public.isa)
  • Re: RCP/HTTPS on SBS 2003 Server
    ... Certianly not needed for RPC over HTTP. ... Did you open the correct ports on your server's router as well? ... So we know all the server components are installed> correctly. ...
    (microsoft.public.windows.server.sbs)
  • RE: Netcat through Squid HTTP Proxy
    ... You can configure squid to only allow tunneling on certain ports like ... > There is a POC shell program that uses XML-RPC called Monkey ... The HTTP requests can be sent via ...
    (Pen-Test)
  • Re: Newbie question about ports.
    ... Can you do a CVSup to update your ports via http? ... Cvsup does not support http, but neither does it use ftp (see man cvsup, ... openable through your firewall. ...
    (freebsd-questions)
  • Re: Media services - cannot connect to media from internet
    ... If I disable HTTP and RTSP on the server, and only have MMS enabled, then I ... open for both UDP and TCP, no ports are being blocked outbound. ...
    (microsoft.public.windowsmedia)