+ Post New Thread
Results 1 to 6 of 6
Internet Related/Filtering/Firewall Thread, Blocking Skype with Smoothwall in Technical; We have a full Smoothie box and are suffering from a handful of Mac users getting through with Skype. It ...
  1. #1
    MartinT's Avatar
    Join Date
    Jul 2007
    Location
    Ascot
    Posts
    169
    Thank Post
    19
    Thanked 12 Times in 12 Posts
    Rep Power
    17

    Blocking Skype with Smoothwall

    We have a full Smoothie box and are suffering from a handful of Mac users getting through with Skype. It seems that no matter what we do (minimum of ports open, skype.com blocked in Guardian), Skype gets through and hogs bandwidth.

    Is there anything we can do, or is a Skype-specific block coming (similar to the Block Kazaa etc. facility)?

  2. #2


    Join Date
    Dec 2005
    Location
    In the server room, with the lead pipe.
    Posts
    4,636
    Thank Post
    275
    Thanked 777 Times in 604 Posts
    Rep Power
    223
    Skype will tunnel over SSL. To block it properly you need to do packet inspection using the IPS (basically Snort) functionality built into Smoothwall.

    I just had a quick look in ours and there isn't a default for Skype that I can see. You can either look on sourcefire for a signature, write your own or ask the SW guys for a helping hand. (Pick option 3 first if you're at all unsure).

    There will be a performance impact, possibly a significant one, depending on your hardware. We use a span port and a separate Snort box so we don't impact browsing.

    Also remember to beat them with your aup. You could also rate-limit the offenders.

  3. #3


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,473
    Thank Post
    866
    Thanked 848 Times in 670 Posts
    Rep Power
    196
    Try blocking https connects to a bare IP in guardian (its a "special" class in policy table) - that, along with sufficiently tight port rules should do it ok.

  4. Thanks to tom_newton from:

    daneil16 (10th January 2014)

  5. #4
    MartinT's Avatar
    Join Date
    Jul 2007
    Location
    Ascot
    Posts
    169
    Thank Post
    19
    Thanked 12 Times in 12 Posts
    Rep Power
    17
    Thanks, Tom. I've implemented that and will test with various flavours of Windows and Apple Skype.

  6. #5
    MartinT's Avatar
    Join Date
    Jul 2007
    Location
    Ascot
    Posts
    169
    Thank Post
    19
    Thanked 12 Times in 12 Posts
    Rep Power
    17
    Success! I've added the filter "HTTPS URLs containing an IP address" for All Groups, Always, Block and it stops Skype from connecting. Many thanks, Tom.

  7. #6


    tom_newton's Avatar
    Join Date
    Sep 2006
    Location
    Leeds
    Posts
    4,473
    Thank Post
    866
    Thanked 848 Times in 670 Posts
    Rep Power
    196
    Heh, sometimes I amaze even myself

    Martin... i'm thinking we communicated by email in less enlightened days.. are you the Martin from Ascot who's been with Smoothwall for.. next to forever.. and who works at a school with a saint's name?

SHARE:
+ Post New Thread

Similar Threads

  1. Blocking Skype on Firewall
    By tinhnt in forum Internet Related/Filtering/Firewall
    Replies: 6
    Last Post: 27th June 2010, 04:06 AM
  2. Smoothwall https blocking help
    By cookie_monster in forum Network and Classroom Management
    Replies: 1
    Last Post: 22nd January 2010, 12:14 PM
  3. Smoothwall - IP URL blocking
    By Gatt in forum Internet Related/Filtering/Firewall
    Replies: 2
    Last Post: 10th November 2009, 10:22 AM
  4. Smoothwall SG question - blocking games
    By ssiruuk2 in forum Internet Related/Filtering/Firewall
    Replies: 14
    Last Post: 9th March 2009, 10:43 AM

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •