Re: [fw-wiz] Blocking Google Talk



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hello,

I prefer not to statically block ip addresses. I prefer to mitigate
network traffic based on network service and content.

Google Talk uses transport layer security for login (TCP 443) and XMPP
for XML Jabber communication (TCP port 5222) prior to clients talking
over RTP (typically UDP 8000+ but will vary). Google Talk does not use
SIP (TCP 5060).

Your solution should depend on your network.

1. With your network I would block all UDP that is not DNS and all
outbound TCP port 5222. You can't block TLS to google unless you want
your user's to log in to their mail accounts clear-text.

OR...

2. Block all inbound network traffic and most outbound traffic except to
a handful of services (ssh, smtp, pop3, http, https, etc...)

Typically I reccomend solution #2. If I wanted to allow google talk on
my network I would add these rules to my /etc/pf.conf file (assuming
youre using openBSD and not a commercial solution):

rtp_udp = "{ 8000><65535 }" # Adjust to google talk ports

pass out log quick on $EXT_NIC proto TCP from any to any port 5222
flags $SYN_ONLY keep state

pass out log quick on $EXT_NIC proto UDP from any to any port $rtp_udp
keep state

Also, I would make sure to encrypt jabber:
http://www.ietf.org/rfc/rfc3923.txt

Cheers

Phil

Paul D. Robertson wrote:
On Thu, 15 Jun 2006, Mike Powell wrote:


Does anyone have any ideas for blocking Google's new Google Talk client
without blocking the Google web site? The IP addresses that the Talk


As usual, it's always good to start at the source...

From: Google Team <talk-feedback@xxxxxxxxxx>

Hello,

Thank you for contacting the Google Talk Team. We understand that it is
sometimes necessary to disable instant messaging services on a network. If
you need to disable Google Talk on your network, we suggest blocking DNS
lookups to talk.google.com, by returning 127.0.0.1.

If we can be of further assistance, please respond to this message and a
member of the Google Talk Team will respond to you shortly.

Sincerely,

The Google Team

Paul
-----------------------------------------------------------------------------
Paul D. Robertson "My statements in this message are personal opinions
paul@xxxxxxxxxxxx which may have no basis whatsoever in fact."
http://fora.compuwar.net Infosec discussion boards

_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards




-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2.1 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFElwi1osz5/4IhOt4RAh/TAJ0Ssj6XyvKo2jbdGqAT5co5K+I5+QCeNRb3
5iBNOAgUAPVtlbMekgpoRGk=
=DAer
-----END PGP SIGNATURE-----
_______________________________________________
firewall-wizards mailing list
firewall-wizards@xxxxxxxxxxxxxxxxxxxxx
https://listserv.icsalabs.com/mailman/listinfo/firewall-wizards



Relevant Pages

  • Re: [fw-wiz] Blocking Google Talk
    ... network traffic based on network service and content. ... Google Talk uses transport layer security for login (TCP 443) and XMPP ... sometimes necessary to disable instant messaging services on a network. ...
    (Firewall-Wizards)
  • Why Google Will Kill Node Computing
    ... Why Google Will Kill Node Computing ... Twenty years ago, personal computers became the ... most advanced human communication system in widespread use. ... of the art human communication network. ...
    (comp.programming)
  • Re: will google build a WiMax with the 700MHze?
    ... WiMax network, that is free to use the network. ... The "C" block has a reserve in excess of $4.5 Billion and Google estimate it would take $12 Billion and 3years to build a 700Mhz network. ... Imagine a hybrid wireless broadband mesh network using 700-MHz connections for backhaul and some truly mobile links and WiFi for local service. ...
    (alt.internet.wireless)
  • Googles gamble
    ... The devil's best trick is to persuade us he doesn't exist, but Google ... These events emphasize network neutrality, ... The deal, as currently structured, substantially alters the Internet ...
    (alt.internet.search-engines)
  • Re: will google build a WiMax with the 700MHze?
    ... WiMax network, that is free to use the network. ... Even though Google have "Loads of Money" they will expect a return on their investment. ... Imagine a hybrid wireless broadband mesh network using 700-MHz connections for backhaul and some truly mobile links and WiFi for local service. ...
    (alt.internet.wireless)