Firewall Wizards mailing list archives

Re: Blocking Kazaa


From: Paul Armstrong <army () cyber com au>
Date: Thu, 26 Jun 2003 15:04:06 +1000

On Wed, Jun 25, 2003 at 03:20:54PM -0300, Dante Fressone wrote:
Hi, I want to block kazaa from my pix fw blocking port 1214 TCP, but it
seems like it's using port 80 now,,,,and I can't drop that port because web
wont work.....

Any ideas?

Use a HTTP proxy such as Squid and only allow traffic to port 80 from the
proxy. 

This has other advantages such as faster response time for cached objects,
general filtering  (e.g. if your policy says people aren't allowed to download
anything with a .vbs extension) and will save you money if you pay by the byte
(or if you pay for pipe size and the traffic reduction means you don't need
such a large pipe).

Paul
_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: