NETWORK PRESENCE ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT
 


Search
display results
words begin  exact words  any words part 

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [FW-1] Messenger



Here is how to block MSN Messenger:

All you have to do is block access to the login servers. If the user can't
login, they can't use IM.

Create 8 different Network Objects (Workstations).

MSN1    64.4.13.170
MSN2    64.4.13.179
MSN3    64.4.13.175
MSN4    64.4.13.82
MSN5    207.68.172.251
MSN6    207.68.178.244
MSN7    63.121.98.69
MSN8    64.4.13.17

Then create a group called MSN_Network.

Source          Your internal and external access users
Dest            MSN_Network
Service         Any
Action          Drop
Track           Long (or Alert) if you want to slap fingers)

This methodology works successfully for all IM types.

Hope this clarifies the issue.

Cheers,
Chris


 -----Original Message-----
From:   Steve Crume [mailto:[email protected]]
Sent:   Wednesday, February 13, 2002 5:17 PM
To:     [email protected]
Subject:        Re: [FW-1] Messenger

  Yes it is unfortunate that any of your present users can now download the
new MSN messenger and circumvent past port blocking  methods.  You will
either have to port block port 80 going in/out or block all 169.69.0.0 and
207.68.0.0. network addresses.  Almost all the servers MSN uses come from a
multitude of servers on these networks.  If you load the MSN messenger and
log on you can follow the trail of servers that your client will
contact(seldom the same).  Unfortunately I do not know if too many people
are willing to block so many network addresses.  Microsoft is spending allot
of money to circumvent company firewalls making it near impossible to stop
there services from intruding into the corporate world.  Reminds me of SPAM.
What about it Bill? where is that security you promised.

-----Original Message-----
From: Andrade Guerra, Marcelo [mailto:[email protected]]
Sent: Wednesday, February 13, 2002 4:05 PM
To: [email protected]
Subject: [FW-1] Messenger


I guru´s of the firewall :P

I need block messenger service, but messenger now use tcp port 80, i need
help please.


Thanks

Saludos

Marcelo Andrade Guerra
MCSE
Gerencia de Software
Sonda S. A.

* mailto:[email protected]
Http://www.sonda.com
*   Teatinos 550 3er. Piso
*    5605558
*    Fax: 2471031

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================

=================================================
To set vacation, Out Of Office, or away messages,
send an email to [email protected]
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
[email protected]
=================================================



 
----------------------------------

ABOUT SERVICES PRODUCTS TRAINING CONTACT US SEARCH SUPPORT SITE MAP LEGAL
   All contents © 2004 Network Presence, LLC. All rights reserved.