ACL for IM's

Sep 07, 2005 4 Replies
ACL for IM's open original image

Anyone have a pre-made ACL to block IM chat programs ? I teach at a College and you'd be surprised with the number of students "Chatting" during class. I want to keep all other connectivity, but block IM ports. Wasn't sure if someone already has tackled this and has the ACL they could pass along ?



Thanks, Bill McCord


Bill -

You're going to have a tough time by jsut using ACLs as the IM clients can operate on pretty much any port. Your best bet is to either block them at the firewall with some kind of ALG or use an IPS type system that will sniff for IM traffic on a SPAN port and send RSTs. I think Akonix has something like that - try IMLogic too. There is one other way to block it... kind of a hack, but it works for the most part: Create a bogus DNS entry for the IM servers (ex: login.oscar.aol.com pointing to 192.168.1.1 or some other bogus address). It works well, but if you want to block all IM services it could be a lot of ongoing maintenance....

B

[...]

it works if you assume the guys will be using the FQDN, for my part in order to escape the ISS Proventia G inline IDS/IPS preventing AOL, Jabber, etc , I use

formatting link
on the 443/tcp port. Few firewalls block https... and, tcpdump on my connection is just showing TLS traffic, the Proventia is by then useless.

Thanks,

/edgar

You should be able to accomplish this with nbar. Here is a good thread to reveiw:

formatting link

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required