Full Disclosure mailing list archives

RE: blocking SkyPE?


From: <lists-security () nettracers com>
Date: Mon, 24 Jan 2005 14:29:14 -0800

 
I need to block SkyPE at the border of our network for many reasons.

Commercial, Off-The-Shelf: 

1)Fortinet stops this and I have used it for such...for T1 speeds you can
keep the cost under $1K and can be installed in bridge/transparent/inline
mode so as not to disturb your existing infrastructure.  

2)Checkpoint will do application/layer-7 inspection as well, but will cost
quite a bit more to purchase and implement.


Roll-your-own: 
  Probably will cost you more in time to do this, but you can use Snort to
detect and control an IPTables firewall...I have seen but not tried this
updated implementation of a dynamic IPTables config tool based on Snort
Rulesets:

 http://www.cipherdyne.com/

 http://www.cipherdyne.com/fwsnort/

Good Luck,
Bryan K. Watson
bwatson () nettracers com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: