Re: Block instant messaging with Pix 7?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: Block instant messaging with Pix 7?

From: Marc Teale <marct@supranet.net>
Date: Tue Feb 07 2006 - 05:40:22 CET

After much searching, I found the "port-misuse" command in the Cisco
Security Appliance Command Reference 7.0.4.

When you're in http-map configuration mode, enter:

port-misuse im drop log

This will prevent Yahoo Messenger, AIM, and MSN from hiding their
packets in HTTP traffic, but can really impair performance on the Pix.

Which is all great... but unless there's some other global way to check
packets, I'll still need to block several ranges of ports, and not be
certain that this will work.

Marc Teale
Received on Tue Feb 7 20:59:23 2006