How to block Remote Desktop software?

Does anyone know of an effective way to block remote desktop applications like GoToMyPC.com, PCanywhere, Fog Creek Copilot etc. at the network level, that doesn't require me to manually find the relevant IP addresses, etc.?

For example does someone host updated IPS signatures, or updated IP lists that could be used in an IPS?

Has anyone else on this list had this challenge, and how did you solve it?

Kind regards, Daniel Tams

Reply to
Daniel Tams
Loading thread data ...

Why do you allow unrestricted outbound?

Why does your company not just allow outbound to specific sites that are approved?

Reply to
Leythos

I work with Proventia stuff frequently and I know IBM ISS Proventia IPS has signatures for these:

formatting link
formatting link
formatting link
formatting link
The protocol detection signatures are generally low or medium, but you could configure them in a profile to drop such traffic if you use the IPS inline in blocking mode.

Being more draconian in egress and inbound filtering can also deal with this, but sensing it on a network level often has uses in environments that aren't as militaristically locked down as other posters suggest. Also, generally those intent on using such technologies will use ports that are allowed to subvert whatever rote policies are in place.

Reply to
Todd H.

I think Untangle

formatting link
does at least some of these in its various applications (webfilter, protocol filter, etc). gr

Reply to
gr

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.