Re: [fw-wiz] Blocking Google Talk



On 6/15/06, Mike Powell <mikep@xxxxxxxxxxx> wrote:
We filter our internet-bound traffic through Microsoft's ISA 2004, and
it is protocol-aware for http (port 80 and 443) traffic, so I can't
think of a way to block the port 443 traffic as it appears to go through
the ISA server as a valid SSL connection, just like someone browsing an
SSL website.

There are products (e.g. Bluecoat) offering MITM interception and
analysis of SSL traffic.

While I don't think Bluecoat has handlers for Google Talk (or the
generic XMPP protocol it's built on) today, given that their products
are targeted at "IM migitation", I'd expect one soon.


Kevin Kadow

(P.S. We just finished an evaluation of Bluecoat, were generally
pleased with the proxy and streaming media features. One area where
the product fell short was "Enterprise" (hierarchical) management and
reporting, features said to be coming in the next few months.)
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: Installing ISA Server for first time
    ... Please note that though correct for HTTP SSL on non standard ports I'm not ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: Self Signed Certificates
    ... RWW works fine using SSL port 443. ... My config for the site is using port 444, windows authentication, SSL is ...
    (microsoft.public.windows.server.sbs)
  • Re: Installing ISA Server for first time
    ... the ISA 2004 can only allow SSL 443 port go through it. ... Microsoft is providing this information as aconvenience to you. ...
    (microsoft.public.windows.server.sbs)
  • Re: running an ssl webserver
    ... >> My machine is only listening for port 80 connections This is through ... >> How do i open an ssl port on this internal webserver. ... SSLRandomSeed startup builtin ...
    (comp.os.linux.security)
  • Re: No SSL on fetchmail?
    ... It depends on the port you connect to. ... encrypted via SSL. ... Connect to the server using the specified base ... So, if you want to use fetchmail on an IMAP server without using SSL, ...
    (comp.mail.misc)