RE: [fw-wiz] Blocking Kazaa

From: Jeff Falgout (JFalgout_at_co.jefferson.co.us)
Date: 06/27/03

  • Next message: Steve Rielly: "RE: [fw-wiz] I am having a problem with check point and I need a little help"
    To: <firewall-wizards@honor.icsalabs.com>
    Date: Fri, 27 Jun 2003 12:33:39 -0600
    
    

    >>> James Cutter <JamesCutter@thedoghousemail.com> 6/25/2003 11:31:44 PM
    >>>
    PIX can't do this. Other Cisco gear can't as well.
    There is a Peer to Peer firewall from Akonix (http://www.akonix.com/ )
    that you can use.

    another option that you might want to try is checkpoint NG (starting at
    FP3) that can block Peer-to-Peer (including kazaa) applications
    traversing the firewall on port 80.

    Original message:

    Hi, I want to block kazaa from my pix fw blocking port 1214 TCP, but it
    seems like it's using port 80 now,,,,and I can't drop that port because
    web wont work.....

    Any ideas?

    >>>>>>>>>>>>>>>>>>>>>>

    I've seen posts on other mailing lists suggesting opening up port 1214,
    yet throttling it down to the slowest speed possible.

    The thought is that Kazaa first tries to connect on port 1214 if that
    connection is refused, it jumps around and usually ends up on 80.
    Yet if you allow the first connection to be successful it won't switch
    ports. As the users start to download, the connection slows to a crawl.

    It may allow Kazaa to work, but it sure won't be an enjoyable product

    Haven't tried it personally though, so YMMV

    Jeff

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Steve Rielly: "RE: [fw-wiz] I am having a problem with check point and I need a little help"

    Relevant Pages

    • Re: Block kazaa traffic
      ... >I would like to get clear answer for the option to block kazaa or any ... >other open port. ... Unless your firewall allows for custom content-filtering rules, ...
      (comp.security.firewalls)
    • Re: Port 3060? What in the hell is going on?
      ... > If you want to block Kazaa on your network, ... > Tiny Personal Firewall on an ICS box is the ONLY ... > calls, for example, on port 80 as part of blocking ... > the server machine can do this. ...
      (comp.security.firewalls)
    • Re: blocking Kazaa and other P2P
      ... >>could suffice to block the use of Kazaa. ... firewalls, such as Tiny/Kerio Firewall. ... then do the port restrictions I mentioned above. ... software you are using, something a hardware firewall ...
      (comp.security.firewalls)
    • Re: Firewalls & Kazaa access
      ... www.kerio.com as a free firewall. ... How do I block any port? ... >>use kazaa lite k++ if you must use kazaa and block 1214 ...
      (microsoft.public.security)
    • Re: Block kazaa traffic
      ... > I would like to get clear answer for the option to block kazaa or any ... > other P2P traffic via firewall. ... > other open port. ... behind a firewall then the Hardware firewall takes precedence over the ...
      (comp.security.firewalls)