How do you do....it? Thread, Proxy sites now using 443 in Technical; Not sure if this is a new thing or not - i did a search and couldn't see a mention ...
-
23rd March 2007, 10:00 AM #1
- Rep Power
- 12
Proxy sites now using 443
Not sure if this is a new thing or not - i did a search and couldn't see a mention of it. Students are now using proxy sites that bypass our ISA server and any of counties restrictions because they are being set to use port 443. It took me a couple of days to work out what was going on in the logs. We have massive amounts of sites with a :443 ending. They can't simply be blocked by domain name as the name seems to be virtually random. It doesnt seem to link anyway if you try and click it.
Here is an example of whats in our logs
c-24-17-137-27.hsd1.wa.comcast.net:443
Any idea's how to get round it?
Blocking port 443?
Cheers
-
-
IDG Tech News
-
23rd March 2007, 10:08 AM #2 Re: Proxy sites now using 443
You could do, but blocking port 443 outbound would also block all secure HTTP connections (https://.......).
-
-
23rd March 2007, 10:12 AM #3 Re: Proxy sites now using 443
Block all 443 and then whitelist as required?
-
-
23rd March 2007, 10:15 AM #4 Re: Proxy sites now using 443
I concure, that'd be the only way to do it. You can't filter on content on https. As it's encrypted.
-
-
23rd March 2007, 10:28 AM #5 Re: Proxy sites now using 443
This is exactly how we do it in ISA 2004 Block all port 443 traffic and then get staff to request whitelist sites.
Student has no need for access to 443 really, the only ones that I found did need it was our sixth form and access to the UCAS site.
-
-
23rd March 2007, 10:29 AM #6
- Rep Power
- 12
Re: Proxy sites now using 443
The blocking :443 and then whitelist by agreement seems like the way forward.
Do i prepare myself for a lot of abuse from staff that can access their bank details, or more importantly can't buy their DVD's from Play.com?
:x
-
-
23rd March 2007, 10:40 AM #7 Re: Proxy sites now using 443
yes. and then you tell them that it is a security thing and they should not be using the school computers for private affaires
-
-
23rd March 2007, 10:57 AM #8 Re: Proxy sites now using 443
Infact, that really should be in your staff AUP anyway.
-
-
23rd March 2007, 11:47 AM #9 Re: Proxy sites now using 443
You can set ISA to unpack all the HTTPS traffic to inspect it can't you? It can then either send it unencrypted through school or repack it up after inspection.
-
-
23rd March 2007, 11:51 AM #10 Re: Proxy sites now using 443
You can man-in-the-middle SSL traffic, yes, but I don't recommend it. It's actually illegal in some countries, and rightly so - it is a gross invasion of privacy, and a security risk.
The "HTTPS" whitelist appears to be the way forward for most users.
-
-
23rd March 2007, 12:09 PM #11 Re: Proxy sites now using 443
On the Microsoft ISA Course it is pushed as a err how do you phrase it, Security Anti-Risk for the exact reasons it would be helpful here - that otherwise anyone could be wrapping anything up in SSL, virus's etc and you'd have no idea.
-
-
23rd March 2007, 03:27 PM #12
- Rep Power
- 12
Re: Proxy sites now using 443

Originally Posted by
Geoff Infact, that really should be in your staff AUP anyway.
I know. Another Reason the ICT-Co-ordinator should not be responsible for the AUP (imho)
-
-
23rd March 2007, 04:16 PM #13
- Rep Power
- 16
Re: Proxy sites now using 443

Originally Posted by
Geoff I concure, that'd be the only way to do it. You can filter on content on https. As it's encrypted.

Not wanting to be a pedant (or a pendant as GD would say). I gather that is a typo and that you do indeed mean can't filter on content?
Cheers,

Andy
-
-
23rd March 2007, 04:38 PM #14 Re: Proxy sites now using 443
indeed I did andy.
-
-
26th March 2007, 07:39 AM #15 Re: Proxy sites now using 443
The argument that was put to the Headmaster at this school was that if the Teachers were expected not to be able to do the odd personal thing online during their free periods or whatever, then they weren't going to do any work at home in their personal time either.
-
SHARE:
Similar Threads
-
By whatwherewhen in forum Links
Replies: 33
Last Post: 28th October 2008, 04:14 PM
-
By GavRob in forum Network and Classroom Management
Replies: 20
Last Post: 30th July 2007, 10:05 PM
-
By bishopsgarthstockton in forum Links
Replies: 77
Last Post: 7th December 2006, 12:29 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules