So I have been looking all morning on groups and I cant find anything
that answers this question. All I can find is how to enable ports but
not block. I need to block ports

Port 3689 TCP
Port 5353 UDP

Yes this is the ports itunes sharing uses. Its eating my bandwidth on
my network. Since all my users are within the firewall I cant use that
to block it. I was thinking that I could setup a group policy with
windows firewall and just block these ports but I can figure it out. I
went into the policy Windows Firewall: Define port exception and

3869:TCP:"*":disabled:Itunes Sharing
5353:UDP:"*":disabled:Itunes Sharing

but that didnt work. I have a feeling this is not the correct way to
do this but besides installed a local firewall on each box I cant
figure it out.

Re: Use Windows Firewall to Block ports wrote:
Easy: everything that is not enabled is blocked.

Oh, you want to block outbound connections. The Windows-Firewall doesn't
do that. If you don't want iTunes traffic: why are your users allowed to
use iTunes in the first place?

If you're only concerned about the traffic volume I'd suggest to do
traffic shaping on the border router.

"If a software developer ever believes a rootkit is a necessary part of
their architecture they should go back and re-architect their solution."
--Mark Russinovich

Re: Use Windows Firewall to Block ports
Re: Use Windows Firewall to Block ports
Chilly, you idiot - what part of "eating up all my bandwidth" didn't you

To block ITunes you need to have a firewall, not the windows firewall,
but a firewall to block access to the internet. You can also create a
script to remove the ITunes application from their machines - since they
really have no business with ITunes being installed on a company


Re: Use Windows Firewall to Block ports
Re: Use Windows Firewall to Block ports

If you're trying to stop outbound on XP's FW, then you can't do it.

You can run IPsec in conjection with XP's FW to stop inbound or outbound
traffic on a port.

Re: Use Windows Firewall to Block ports
you can use IPSec (without disabling the windows firewall) to create
a port filtering policy which you may then assign to the desired PCs
as an example, have a look here

using IPSec you'll be able to perform "outbound filtering" (the plain
vanilla XP firewall hasn't this capability) so, setting up blocking rules
for the undesired ports/protocol you'll be able to filter out them w/o
any need to install other s/w on the machines

