LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-30-2008, 06:18 PM   #1
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Rep: Reputation: 60
Dansguardian, SQUID and AIM TCP443


I use Dansguardian, and SQUID as my proxy and web filter. I had to block a user ip from going to the internet and thought that all was well. I had a task that I had to take care of and when I was on my way to do it I passed by his desk and heard him using AIM. I looked at my logs and I could see that he was using AIM and TCP port 443. I though that if I blocked his ip via bannediplist in DANSGUARDIAN that it would stop all traffic. The user cannot use the internet but he can use AIM. I know that I can block at the firewall but why isnt DANSGUARDIAN doing its job?

Last edited by metallica1973; 12-31-2008 at 11:41 AM.
 
Old 12-30-2008, 06:47 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Are you positive that connections to port 443 are going through DansGuardian?

Could it be that they are going through Squid instead?
 
Old 12-31-2008, 11:42 AM   #3
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
I believe that you are right. I thought that the whole intention of dansguardian was to control all access to the internet. I dont want to have to bounce back and forth between squid and dansguardian to control my users. What can I do? Is there a setting in dansguardian that I do not have setup correctly?
 
Old 12-31-2008, 12:10 PM   #4
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Are you sure DansGuardian works with HTTPS? I mean, obviously it won't do content filtering for HTTPS, so it would be limited to URL filtering - which is something you can do in Squid so it would be kinda redundant. Maybe it just forwards the HTTPS tunnels to Squid without making any considerations? I don't know. Maybe go through the documentation or do some tests.

Personally, I'd probably just make sure clients use Squid for HTTPS and DG for HTTP. For example, by making an ACL in Squid allowing access to port 80 only from localhost (or wherever your DG is). The ACL for port 443 would allow access from any client. Iptables would do transparent redirection to DG for port 80, and clients would need to specifically use Squid for port 443. Then blocking AIM would just be a matter of looking at the log file and performing an appropriate ACL ban.

Last edited by win32sux; 12-31-2008 at 12:12 PM.
 
Old 01-06-2009, 09:27 PM   #5
metallica1973
Senior Member
 
Registered: Feb 2003
Location: Washington D.C
Posts: 2,190

Original Poster
Rep: Reputation: 60
thanks, dude I will look into squid ACL's
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Squid and Dansguardian gautamnarayan Linux - Enterprise 2 11-11-2008 01:56 PM
Dansguardian + Squid SBN Linux - Server 2 07-12-2007 07:16 AM
Dansguardian and Squid yeeha! Linux - Networking 4 08-21-2006 01:22 AM
dansguardian + squid shafey Linux - Security 2 12-31-2005 11:42 AM
Dansguardian/Squid HELP! Prizam Linux - Software 3 09-23-2005 06:30 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:54 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration