|
Posted by choowie on December 17, 2004, 8:07 pm
If you were Registered and logged in, you could reply and use other advanced thread options
Did anyone find a solution to forbid Instant Messaging (yahoo, msn, aol,
....) by applying a specific rulebase on the cisco/checkpoint firewall? The
problem is these Instant Messaging software use HTTP protocols to sneak thru
firewalls. Maybe something could be done on the proxy server?
Thanks.
--
Choowie
|
|
Posted by Charles Newman on December 17, 2004, 8:27 pm
If you were Registered and logged in, you could reply and use other advanced thread options
> Did anyone find a solution to forbid Instant Messaging (yahoo, msn, aol,
> ...) by applying a specific rulebase on the cisco/checkpoint firewall? The
> problem is these Instant Messaging software use HTTP protocols to sneak
thru
> firewalls. Maybe something could be done on the proxy server?
Get cybersitter and use that. I used that before it started clashing
with programs on my network server, and it blocked these services
quite well. Cybersitter will work on a network server, and filter all
the machines behind it. If you need to block instant messaging,
CyberSitter is your best solution, provided it does not clash with
any programs running on your network server. Some programs
running servers on your machine may clash with CyberSitter, but
if that will not be a problem, then I recommend CyberSitter, and
blocking the categories of Free Email and Online Chat, that will
stop the three major messenger services (MSN, AIM, Yahoo)
>
> Thanks.
>
> --
> Choowie
>
>
|
|
Posted by Mark S on December 19, 2004, 2:12 pm
If you were Registered and logged in, you could reply and use other advanced thread options Sonicwall and Netscreen firewalls will do this (I think the Sonicwall
supports more options).
> Did anyone find a solution to forbid Instant Messaging (yahoo, msn, aol,
> ...) by applying a specific rulebase on the cisco/checkpoint firewall? The
> problem is these Instant Messaging software use HTTP protocols to sneak
thru
> firewalls. Maybe something could be done on the proxy server?
>
> Thanks.
>
> --
> Choowie
>
>
|
|
Posted by Jose Maria Lopez Hernandez on December 19, 2004, 9:31 pm
If you were Registered and logged in, you could reply and use other advanced thread options choowie wrote:
> Did anyone find a solution to forbid Instant Messaging (yahoo, msn, aol,
> ....) by applying a specific rulebase on the cisco/checkpoint firewall? The
> problem is these Instant Messaging software use HTTP protocols to sneak thru
> firewalls. Maybe something could be done on the proxy server?
>
> Thanks.
>
Some people block the IP addresses this programs as primary servers,
the ones they connect to login. Others use some strings extracted from
the login sessions of this programs to block them. You can find more
information on Internet, there are some sites that have information
about this subject. You can also use a sniffer as ethereal to create
your own rules.
--
Jose Maria Lopez Hernandez
Director Tecnico de bgSEC
jkerouac@bgsec.com
bgSEC Seguridad y Consultoria de Sistemas Informaticos
http://www.bgsec.com ESPAŅA
The only people for me are the mad ones -- the ones who are mad to live,
mad to talk, mad to be saved, desirous of everything at the same time,
the ones who never yawn or say a commonplace thing, but burn, burn, burn
like fabulous yellow Roman candles.
-- Jack Kerouac, "On the Road"
|
| Similar Threads | Posted | | Regarding the skype instant messanger and firewall | July 2, 2005, 5:57 am |
| Yahoo, MSN, AOL etc instant messenger bloacking via firewall | July 21, 2004, 9:26 am |
| Regarding auto configure option in AOL instant messanger. | June 27, 2005, 5:58 am |
| Yahoo, MSN, AOL, etc Instant Messenger ports for firewall blocking | July 21, 2004, 9:25 am |
| Content Filter | February 1, 2005, 1:40 am |
| which content filter is the best? | February 1, 2005, 12:15 pm |
| header filter ! | March 3, 2005, 1:31 pm |
| Filter *.wmf files | January 2, 2006, 10:24 am |
| MAC filter on server | January 28, 2007, 7:17 pm |
| Kill Filter | January 2, 2008, 5:29 am |
|