LinuxQuestions.org
Have you listened to LQ Radio?
Go Back   LinuxQuestions.org > Forums > Linux > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices

Reply
 
Thread Tools
Old 12-06-2006, 01:37 PM   #1
aq_mishu
Member
 
Registered: Sep 2005
Location: Bangladesh
Distribution: RH 7.2, 8, 9, Fedora
Posts: 173
Thanked: 0
Blocking Yahoo messenger


[Log in to get rid of this advertisement]
Hi there, After a long time here. I am havin a prob in my office. It has become a culture to chat using yahoo messenger and msn messenger all the time instead of working. Now i need to stop both of these. Can i use a firewall to block ports?

Also give me a solution if i want to use proxy (transparent)... And is there any squid for win2k?? because then i'll need to deploy that too... please help me...
aq_mishu is offline     Reply With Quote
Old 12-06-2006, 02:01 PM   #2
Capt_Caveman
Moderator
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Thanked: 0
Many IM clients a designed to use a list of secondary ports if the primary ones are blocked. In fact most will use port 80, which makes it difficult to distinguish from standard web traffic. Easiest way to do this is to run squid on the gateway and use iptables to redirect traffic locally to the squid port (aka transparent proxying). That way to the setup will be transparent to the internal users and it saves you from having to manually reconfigure the tcp/ip settings on all of the client machines.

http://www.faqs.org/docs/Linux-mini/...rentProxy.html

I've heard good things about using Dansguardian as well.
Capt_Caveman is offline     Reply With Quote
Old 12-10-2006, 11:06 AM   #3
aq_mishu
Member
 
Registered: Sep 2005
Location: Bangladesh
Distribution: RH 7.2, 8, 9, Fedora
Posts: 173
Thanked: 0

Original Poster
Thanx

Thanx for the info. I also found this is the best way... But now i have to use a linux-box instead of my currently available router.
aq_mishu is offline     Reply With Quote
Old 12-10-2006, 03:42 PM   #4
Capt_Caveman
Moderator
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Thanked: 0
Quote:
Originally Posted by aq_mishu
Thanx for the info. I also found this is the best way... But now i have to use a linux-box instead of my currently available router.
I know it's a pain to make that transition, but once you do you'll find it to be much more powerful and flexible solution. Things like detailed logging and traffic shaping are reasonably easy to do with a linux box and are virtually absent from all but higher-end routers. Unless you have significant traffic load that requires dedicated hardware, then I'd seriously consider it.
Capt_Caveman is offline     Reply With Quote
Old 12-11-2006, 01:57 PM   #5
aq_mishu
Member
 
Registered: Sep 2005
Location: Bangladesh
Distribution: RH 7.2, 8, 9, Fedora
Posts: 173
Thanked: 0

Original Poster
hmmm... but i need one very important solution. It is not currently available... but have plan for this. If it can support, then i'll just go for it. That is my office is now using a so called broadband. But it is the worst thing they are using. I found a dial-up with a noisy connection is better than this one. Thus i have started to think about using EDGE using a EDGE modem. There i got more than 120kb at any time which is sufficient in my office for sharing with 4-5 PCs. But i have to dial-up and actually i then need demand dial using the EDGE modem as a normal modem used by COM ports. Is it possible in linux?? By the way, the EDGE modem will be connected to the box using a USB. I know it can be done in windows, but i need linux for my case...
aq_mishu is offline     Reply With Quote
Old 12-11-2006, 11:39 PM   #6
Capt_Caveman
Moderator
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658
Thanked: 0
I've never used it, but it looks like a number of usb EDGE modems appear to be supported under linux. You may want to start a new thread in the Linux - Networking or Linux - Hardware (do not post in both) specifically regarding getting your usb EDGE modem to work. Make sure to include specifics on the make and model number as well as the distro and version of linux you are planning to use. Probably a good idea to get it working stably on a test network first before rolling it out.

Might find this a useful discussion.
Capt_Caveman is offline     Reply With Quote
Old 12-18-2006, 05:25 AM   #7
born4linux
Senior Member
 
Registered: Sep 2002
Location: Philippines
Distribution: Slackware, RHEL&variants, AIX, SuSE
Posts: 1,118
Thanked: 3
Quote:
Originally Posted by Capt_Caveman
Many IM clients a designed to use a list of secondary ports if the primary ones are blocked. In fact most will use port 80, which makes it difficult to distinguish from standard web traffic.
and there are also tools that can tunnel through this proxy setup and act as a local socks proxy server on the client machine. (like socks2http).
preventing messenger access can't be done alone at the server level. you also need to do some "policing" at the users' side. unless, of course, if you run your firewall/proxy server in paranoid mode.

there are a lot of ways for a very persistent user who can't live without messenger clients around.
born4linux is offline     Reply With Quote
Old 12-18-2006, 05:55 AM   #8
matthewg42
Senior Member
 
Registered: Oct 2003
Location: UK
Distribution: Kubuntu (x86), Debian (PPC)
Posts: 3,495
Thanked: 6
I'd advise not only blocking the ports but also stipulating in your company IT policy that IM services are prohibited, and will lead to disciplinary action.
matthewg42 is offline     Reply With Quote
Old 12-18-2006, 07:52 AM   #9
unSpawn
Moderator
 
Registered: May 2001
Posts: 16,716
Blog Entries: 30
Thanked: 283
Moved: This thread is more suitable in the Linux Networking forum (taxonomy: +network +"block access") and has been moved accordingly to help your thread/question get the exposure it deserves.
unSpawn is offline     Reply With Quote

Reply

Bookmarks


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
blocking yahoo messenger jitheshmurali Linux - Security 2 05-14-2006 04:34 AM
using squid -blocking yahoo messenger gadekishore Linux - Software 1 10-19-2005 07:53 AM
blocking yahoo messenger with iptables mardanian Linux - Networking 5 04-24-2004 03:32 PM
blocking yahoo messenger with iptables linuxboy_inside Linux - Security 3 01-20-2004 10:12 PM
monitoring and/or blocking yahoo messenger at firewall chrisfirestar Linux - General 1 10-27-2003 10:06 AM


All times are GMT -5. The time now is 09:13 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
RSS2  LQ Podcast
RSS2  LQ Radio
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration