Astaro User Bulletin Board
Go Back   Astaro User Bulletin Board > Closed Forums (read only) > ASG V7.500 BETA (closed)

Welcome to the Astaro User Bulletin Board.
If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 06-09-2009, 08:35 AM
Wizard
 
Join Date: Jul 2008
Posts: 1,407
Default [INFO] [7.450] Google Talk browser/standalone logging

Hi Friends !

if i am using gmail chat in browser does astaro suppose to monitor that also ?
if so i could not see any log for that
how to setup a gtalk program
gives error could not authenticate to server

Thanks

Last edited by utm_kid; 06-09-2009 at 09:21 AM.
  #2 (permalink)  
Old 06-09-2009, 10:31 AM
Senior Member
 
Join Date: Jul 2008
Posts: 121
Default

gmail chat web based (using browser) uses your http/https so they are monitored but you need to look at httpproxy logs - although I don't know how much you can get out of it since it will appear as websurfing.

for stand alone client, google has detail instruction here Required ports to use Google Talk - Google Talk Help
  #3 (permalink)  
Old 06-09-2009, 12:15 PM
Wizard
 
Join Date: Jul 2008
Posts: 1,407
Default

Quote:
Originally Posted by dmzalarm View Post
gmail chat web based (using browser) uses your http/https so they are monitored but you need to look at httpproxy logs - although I don't know how much you can get out of it since it will appear as websurfing.

for stand alone client, google has detail instruction here Required ports to use Google Talk - Google Talk Help
Thanks Dear Friend !
  #4 (permalink)  
Old 06-09-2009, 01:24 PM
srrudolph's Avatar
Moderator
 
Join Date: May 2006
Location: Karlsruhe
Posts: 131
Default

the information by dmzalarm is correct.

although the gmail chat is also google talk, this one is work via HTTP/HTTPS, so it's monitored by the HTTP Proxy.

the standalone client of google talk (and any other XMPP client) can be monitored via IM/P2P Security >> Instant Messaging >> Protocols (so IM/P2P Classifier is the correct log file to checkout what's going on).
__________________
Sascha Rudolph ~ Senior Software Developer ~ Astaro AG
GPG Key Fingerprint: E4BC 501C 0B97 D89E CBE3 9AE5 E321 B8A1 2013 1B78
  #5 (permalink)  
Old 06-16-2009, 02:53 PM
Wizard
 
Join Date: Jul 2008
Posts: 1,407
Default

Quote:
Originally Posted by srrudolph View Post
the information by dmzalarm is correct.

although the gmail chat is also google talk, this one is work via HTTP/HTTPS, so it's monitored by the HTTP Proxy.

the standalone client of google talk (and any other XMPP client) can be monitored via IM/P2P Security >> Instant Messaging >> Protocols (so IM/P2P Classifier is the correct log file to checkout what's going on).
Yes Sir ,if it is so then it has control on IM section,if it is http/https then there should be control trough http/s its using some differant protolcol (?)xmpp please see report image blow

Last edited by utm_kid; 07-09-2009 at 03:54 PM.
  #6 (permalink)  
Old 06-17-2009, 02:40 AM
Senior Member
 
Join Date: Jul 2008
Posts: 121
Default

The only way possible of logging gtalk webclient would be using IPS sid 12303, webclient doesn't use xmpp so it won't fall under IM section.

Using snort for gtalk control can only give you logging/reporting or deny. I would think this is up to individual admins to make that decision and not up to folks at Astaro.
  #7 (permalink)  
Old 06-21-2009, 03:18 AM
Wizard
 
Join Date: Jul 2008
Posts: 1,407
Default

Quote:
Originally Posted by dmzalarm View Post
The only way possible of logging gtalk webclient would be using IPS sid 12303, webclient doesn't use xmpp so it won't fall under IM section.

Using snort for gtalk control can only give you logging/reporting or deny. I would think this is up to individual admins to make that decision and not up to folks at Astaro.
Dear DMZalarm,

where i can find more about IPS sid 12303 ,

Thanks
  #8 (permalink)  
Old 06-21-2009, 04:30 PM
Senior Member
 
Join Date: Jul 2008
Posts: 121
Default

In Astaro, it is "POLICY Google Chat web client connection"

In standard snort installation, it is "alert tcp $HOME_NET any -> $EXTERNAL_NET $HTTP_PORTS (msg:"POLICY Google Chat web client connection"; flow:established,to_server; uricontent:"/talkgadget/popout"; nocase; classtypeolicy-violation; sid:12303; rev:3"
  #9 (permalink)  
Old 06-24-2009, 07:03 PM
 
Join Date: Jun 2009
Posts: 0
Default

Code:
Astaro Beta Report
--------------------------------
Version: 7.450
Type: INFO
State: NONE
Reporter: utm_kid
Contributor: 
MantisID: 
--------------------------------
  #10 (permalink)  
Old 06-27-2009, 03:20 PM
Wizard
 
Join Date: Jul 2008
Posts: 1,407
Default

Quote:
Originally Posted by Astaro Beta Bot View Post
Code:
Astaro Beta Report
--------------------------------
Version: 7.450
Type: INFO
State: NONE
Reporter: utm_kid
Contributor: 
MantisID: 
--------------------------------
Hi Friends !

After ips update on 26th gtalk (gmail based -irc ) not working it was working fine !

and there are rules for chat on the ips
if it is blocked by IPS which ips rule i should disable there are two rules for instant messaning i tryed that still no help

Thanks

Last edited by utm_kid; 06-28-2009 at 04:25 PM.
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 10:45 PM.

 

Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2010, Jelsoft Enterprises Ltd.


These pages are specifically maintained for the discussion of firewall issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases. issues within the Open Source community, and might already reflect new alpha/beta releases under development. Please refer to our product specifications for the functionality of the actual release. Discussions of new/enhanced functionality does not constitute a commitment of Astaro, to integrate this functionality into future releases.