Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Astaro Gateway Products > Web Security: HTTP/HTTPS/FTP, IM/P2P, Web Filtering and Antivirus

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 02-19-2010, 07:26 PM
Junior Member
 
Join Date: Feb 2010
Posts: 1
Exclamation Blocking Web Messengers

Hello guys, i would like to know if any of you know the way(s) to block web messengers, i mean the onea that you can use from your mail client (such as yahoo, google, hotmail), that little application . The problem is that our CEO sent us the direction to block al IM, and thats the only problem i have right now . If any of you can help me with this issue, please help me!

IŽll thank you 4EVER!
Reply With Quote
  #2 (permalink)  
Old 02-19-2010, 07:38 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,624
Default

Use your browser to send messages on each one you want to block, then look in the Astaro 'Content Filter (HTTP)' log to see the FQDN of the servers. Add these to 'Always block'. For Google chat, it's something like b.google.com. If the traffic isn't going through the HTTP/S Proxy, you can define DNS Groups and write packet filter rules to block the traffic.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #3 (permalink)  
Old 02-19-2010, 07:41 PM
mbrophy's Avatar
Member
 
Join Date: Mar 2009
Posts: 79
Default

We use the standard settings for IM/P2P blocking and GMail chat gets stopped cold with no problems. Not sure about the other clients.
Reply With Quote
  #4 (permalink)  
Old 02-19-2010, 09:29 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,624
Default

I just reran my experiment. In IM/P2P, I chose "Block completely" for 'Google Talk/Jabber'. I fired up the live logs for 'Content Filter (HTTP)' and 'IM/P2P Classifier'. I also went into my packet filter rules to select logging of all outbound traffic. I still was able to establish a chat session between two different gmail accounts on two different computers, one "outside" the Astaro and the other in 'Internal (Network)'. Nothing appeared in the log. I did the same with Yahoo Chat from inside Yahoo mail.

MBrophy, can you check your 'IM/P2P Classifier' log and confirm that it shows the blocking of gmail chat when done from inside gmail? I don't use this, so I wonder what I need to do differently to configure the blocking of email chat with IM/P2P.

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!

Last edited by BAlfson; 02-20-2010 at 10:21 AM. Reason: spelling
Reply With Quote
  #5 (permalink)  
Old 02-22-2010, 03:01 PM
Senior Member
 
Join Date: Apr 2008
Posts: 189
Default

I have the IM/P2P set to block completely and when I go to MSN Canada - The all-new MSN Canada, home of world-class services such as Hotmail, Windows Live Messenger, and News, Sports, Financial and Entertainment services it doesn't seem to be working which works for me...
Reply With Quote
  #6 (permalink)  
Old 02-22-2010, 03:17 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,624
Default

Yes, but is the reason the IM/P2P - is that what the IM/P2P log indicates?

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #7 (permalink)  
Old 02-22-2010, 03:36 PM
mbrophy's Avatar
Member
 
Join Date: Mar 2009
Posts: 79
Default

sorry for the delay.

Here is how I am setup that allows me access to GMail, but no to chat.
Attached Images
File Type: jpeg astaro.jpeg (66.5 KB, 14 views)
Reply With Quote
  #8 (permalink)  
Old 02-22-2010, 06:00 PM
BAlfson's Avatar
Moderator
 
Join Date: Mar 2007
Location: Oklahoma City
Posts: 6,624
Default

I have no exceptions, I had "Block" and now I have "Log" - in neither case does the chat from a gmail window appear in the IM/P2P log. Do you see gmail chat blocked in your IM/P2P log?

Cheers - Bob
__________________
ACE V7 - Astaro Preferred Partner since V3
Addicted to my iPhone!
Reply With Quote
  #9 (permalink)  
Old 02-22-2010, 06:12 PM
mbrophy's Avatar
Member
 
Join Date: Mar 2009
Posts: 79
Default

Blocked.

10.x VLan is private network
172.16.x address is Astaro LAN interface so my IE settings look something like this

172.16.x.x:8083


-Mark
Attached Images
File Type: jpeg astaro2.jpeg (9.3 KB, 7 views)
File Type: jpeg astaro3.jpeg (11.7 KB, 5 views)
Reply With Quote
  #10 (permalink)  
Old 02-22-2010, 11:29 PM
Junior Member
 
Join Date: Feb 2010
Posts: 5
Default

I had a similar problem, the IM/P2P proxy does a good job of blocking IM clients but I found some people still using AIM Express and MSN via Web Messengers. In HTTP/S under URL Filtering Categories there is a category called 'Information and Communications'. One of the sub-categories of this category is 'Instant Messaging'. I created a new Filter Category called Instant Messaging and placed this subcategory in it and I add it as a blocked category where needed in HTTP/S Profiles. It worked great for AIM Express and MSN Web clients, I'm not sure about Google Chat.

Another useful sub-category is 'anonymizers' by creating a filter category for this one you can block the really smart guys who now how to use external proxies or VPN's to bypass your filtering.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:21 AM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.