Blocking all P2P network in firewall

HypNoTic

Member
Mar 23, 2001
137
0
0
Hi,

Our corporate users suddenly re-discovered P2P network (Morpheus mainly) and i'd like to block all those nasty little things right out of the box. Dont you know where i can found a complete listing of port to block in our Pix ?

Thanks,

-HypNoTic
 

HypNoTic

Member
Mar 23, 2001
137
0
0
Well, here's a common listing for those of you that might be interested. Although i still think the best way to hardeing a firewall is to block all outbound connection and just open the required ports, but my boss does not think like that...



AIMSTER - PORT 5025

AUDIOGALAXY - PORT 9000

BEARSHARE, XOLOX, LIMEWIRE & MOST GNUTELLA CLIENTS - PORTS 6345, 6346, 6347, 6348, 6349

WINMX/OLD NAPSTER - PORT 6699

NEW NAPSTER - PORTS 8875, 8876, 8888

KAZAA/MORPHEUS - PORT 1214

EDONKEY2000 - PORTS 4661, 4662, 4665

GNOTELLA - PORTS 23, 80, 6667, 8080
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Gnotella at 23 and 80? Um, be real careful blocking those or you will have some mighty unhappy users
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
strange - first rule of a firewall is block all, then you add needed ports and addresses. Guess your boss is clueless.

If some of those are using port 80 then that blows. I'm seeing more and more non HTTP apps use port 80. downright dispicible.

Let us know what rules you've put in place and what P2P apps they've blocked when you get done testing.

Also, where did you find the port information? Maybe there are some logon servers these apps talk to and you could block those addresses as well (any port number) to keep them from registering. This is how we eliminated instant messengers like AIM, MS, Yahoo, ICQ.
 

mboy

Diamond Member
Jul 29, 2001
3,309
0
0
Yeah, that damn Weatherbug crap uses port 80. Had to block like 4 weatherbug domain names to rid myself of it. Pain in the arse.
Block port 80 on your boses computer, see what happens

Mine doesnt know the difference between port 80, port 21 or a port-a-pottie for that matter
 

narzy

Elite Member
Feb 26, 2000
7,007
1
81
Originally posted by: spidey07
strange - first rule of a firewall is block all, then you add needed ports and addresses. Guess your boss is clueless.

If some of those are using port 80 then that blows. I'm seeing more and more non HTTP apps use port 80. downright dispicible.

Let us know what rules you've put in place and what P2P apps they've blocked when you get done testing.

Also, where did you find the port information? Maybe there are some logon servers these apps talk to and you could block those addresses as well (any port number) to keep them from registering. This is how we eliminated instant messengers like AIM, MS, Yahoo, ICQ.

teehee almost exactly what I was going to say, except not calling the boss clueless (insulting people makes you look like a huge ass not you personally but in general.) Instead of trying to battle users by blocking ports as they abuse them, block them before they can be abused. if your at work, most likely you only need the web, and E-mail, if you have your network layered logicly you can block the apropriate ports at the border and still freely use programs that need to be used in building between computers without a problem, if you need to open ports as needed. as to non HTTP apps using port 80, one solution (don't know if it even exists but am throwing it out there anyway) is to filter traffic to verify what is comming in and out of a port is what is SUPPOSED to be comming in and out of that port, basicly verifying ex. HTTP data is infact HTTP data.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |