Welcome, Guest. Please login or register.
Did you miss your activation email?
+  pfSense Forum
|-+  pfSense English Support» Packages» Using snort : how to block a specific traffic not a host
Username:
Password:
 
 

Pages: [1]   Go Down
  Print  
Author Topic: Using snort : how to block a specific traffic not a host  (Read 834 times)
0 Members and 1 Guest are viewing this topic.
sadoki
Newbie
*
Offline Offline

Posts: 4


View Profile
« on: October 28, 2009, 08:39:11 am »

Hi to all,

I'm using pfsense and snort to bloc skype on our company network, this is working great : every host that attempts to use skype is blocked.
But actually, we need to do not bloc all traffic from this host, we want to keep the ability to use internet and just bloc skype traffic.
Is it possible with snort?

Thanx
Logged
artifact
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #1 on: December 18, 2009, 07:25:53 am »

Hi to all,

I'm using pfsense and snort to bloc skype on our company network, this is working great : every host that attempts to use skype is blocked.
But actually, we need to do not bloc all traffic from this host, we want to keep the ability to use internet and just bloc skype traffic.
Is it possible with snort?

Thanx



I have the same question, Please could someone answer this?
Logged
artifact
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #2 on: December 18, 2009, 08:09:53 am »

Ok, i found that if u use snort on interface WAN then on login, there is blocked skype login server.

Code:
Rule 5999 tcp $EXTERNAL_NET any $HOME_NET any P2P Skype client login

This rule add destination ip to blocked list for next time. The same as 5998.

Code:
5693 tcp $HOME_NET any $EXTERNAL_NET $HTTP_PORTS P2P Skype client start up get latest version attempt

Is not blocking ip address. There is 10 Alerts about this rule, but nothing is added to blocked list. Why it is so?

Tnx
Logged
artifact
Newbie
*
Offline Offline

Posts: 14


View Profile
« Reply #3 on: December 22, 2009, 01:26:54 am »

Does anyone ever blocked skype with pfsense?
Logged
EscArtist
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #4 on: January 16, 2010, 08:02:39 am »

Does anyone ever blocked skype with pfsense?

I have been trying to get pfsense 1.2.3 and snort package to block skype for the last 3 days without success.

Also I have noticed that pfsense doesn't completely block MSN and Yahoo messengers.
Logged
jamesdean
Global Moderator
Sr. Member
*****
Offline Offline

Posts: 218



View Profile
« Reply #5 on: January 20, 2010, 05:17:35 pm »

Hi to all,

I'm using pfsense and snort to bloc skype on our company network, this is working great : every host that attempts to use skype is blocked.
But actually, we need to do not bloc all traffic from this host, we want to keep the ability to use internet and just bloc skype traffic.
Is it possible with snort?

Thanx


You need to write a snort rule that blocks known content of skype or addjust the rule for you company network.

James
« Last Edit: January 20, 2010, 05:21:30 pm by jamesdean » Logged

PLease post your Pfsense Version and Snort Version when asking questions. Thank you.
EscArtist
Newbie
*
Offline Offline

Posts: 9


View Profile
« Reply #6 on: January 21, 2010, 02:26:01 am »

Hi to all,

I'm using pfsense and snort to bloc skype on our company network, this is working great : every host that attempts to use skype is blocked.
But actually, we need to do not bloc all traffic from this host, we want to keep the ability to use internet and just bloc skype traffic.
Is it possible with snort?

Thanx


You need to write a snort rule that blocks known content of skype or addjust the rule for you company network.

James

As far as I noticed it's not possible to create your own rules or am i missing something?

I reinstalled everything and noticed that some IP addresses get blocked once skype starts up, so I am assuming that the detection works. However skype gets connected either way.

Logged
Pages: [1]   Go Up
  Print  
 
Jump to:  

 

Page created in 0.29 seconds with 19 queries.