Educause Security Discussion mailing list archives

Re: Ports/applications permitted for Guest Access


From: David Gillett <gillettdavid () FHDA EDU>
Date: Mon, 12 Sep 2011 09:29:49 -0700

On Sun, 11 Sep 2011 14:27:01 CDT, Shannon Roddy said:
In many ways, poorly managed or overly paranoid port based firewalls
are why we have a port 80/443 world.

  It has started to become an arms race:

Developers:  Here's a cool way to leverage Internet access that will make us
rich.

Network Administrators:  That app uses our resources in ways that range from
violations of local policy to violations of state and federal law.  Block
it!

Developers:  Network policy enforcement is our enemy.  Evade it by
pretending to be something else!

Network Administrators:  Blocked apps are getting through.  Deploy more
powerful tools to detect them!

And so forth....

David Gillett


Current thread: