Jump to content

Recommended Posts

Posted (edited)

Something worth discussion and has been on my radar for some time.

 

With more and more traffic moving to HTTPS how much HTTP traffic do you actually see on your network going to the internet?

 

We have been tightening up our firewall policies recently and this was one I thought about. When I did a search of logs to see what HTTP traffic there was it was very little, mainly to Microsoft if I recall, so by blocking HTTP and only allowing it to what is needed could you see any issues? Might help with some of those rogue websites and help with the security of any data leaving site. Not made the move yet but wondered what you all thought?

Edited by 6Foot2
Posted

I think Edge and Chrome now choose https over http for URLs typed.

 

Certificate CRL/OCSP uses http.

 

You have to do a detailed audit. I managed to parse the Windows Firewall log a while back with a similar aim.

Posted
I suppose the only real way is to try it and see what happens. Looking at our logs over 30 day period the traffic is minimal and majority goes to Microsoft which is easily sorted.
Posted
I suppose the only real way is to try it and see what happens. Looking at our logs over 30 day period the traffic is minimal and majority goes to Microsoft which is easily sorted.

 

That could be Windows update. I know it uses HTTP as well as HTTPS.

Posted

Not sure didn't dig into it too deep, in theory all Windows Updates should be coming from out patch management solution hosted in house but its something easily resolved.

 

Clearly I am the only one mad enough to look at something like this then!!

Posted
Clearly I am the only one mad enough to look at something like this then!!

 

IME you've got to have a very good reason to introduce a breaking change, and I'm not sure you've even convinced yourself of the benefits.

  • Thanks 1
Posted

Would probably be one the last things I'd close.

 

Block it for yourself and only your machine and perhaps your personal device on BYOD.

 

I've seen some HTTP calls on Win11 to some random places that when blocked, destroy the taskbar. Why....no idea!

 

I mean, try it, but I imagine it's the least of your worries! :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...