MatthewL Posted October 15, 2024 Posted October 15, 2024 (edited) Something worth discussion and has been on my radar for some time. With more and more traffic moving to HTTPS how much HTTP traffic do you actually see on your network going to the internet? We have been tightening up our firewall policies recently and this was one I thought about. When I did a search of logs to see what HTTP traffic there was it was very little, mainly to Microsoft if I recall, so by blocking HTTP and only allowing it to what is needed could you see any issues? Might help with some of those rogue websites and help with the security of any data leaving site. Not made the move yet but wondered what you all thought? Edited October 15, 2024 by 6Foot2
dmj Posted October 15, 2024 Posted October 15, 2024 Sounds like it will break things for very little benefit. 1
free780 Posted October 15, 2024 Posted October 15, 2024 I think Edge and Chrome now choose https over http for URLs typed. Certificate CRL/OCSP uses http. You have to do a detailed audit. I managed to parse the Windows Firewall log a while back with a similar aim.
tom_newton Posted October 15, 2024 Posted October 15, 2024 A lot of port 80 traffic will be "can I get to the internet" checks, which run on 80 so they can be redirected to login pages. 1
MatthewL Posted October 15, 2024 Author Posted October 15, 2024 I suppose the only real way is to try it and see what happens. Looking at our logs over 30 day period the traffic is minimal and majority goes to Microsoft which is easily sorted.
FN-GM Posted October 15, 2024 Posted October 15, 2024 I suppose the only real way is to try it and see what happens. Looking at our logs over 30 day period the traffic is minimal and majority goes to Microsoft which is easily sorted. That could be Windows update. I know it uses HTTP as well as HTTPS.
MatthewL Posted October 16, 2024 Author Posted October 16, 2024 Not sure didn't dig into it too deep, in theory all Windows Updates should be coming from out patch management solution hosted in house but its something easily resolved. Clearly I am the only one mad enough to look at something like this then!!
dmj Posted October 16, 2024 Posted October 16, 2024 Clearly I am the only one mad enough to look at something like this then!! IME you've got to have a very good reason to introduce a breaking change, and I'm not sure you've even convinced yourself of the benefits. 1
PaddyNewman Posted October 17, 2024 Posted October 17, 2024 Would probably be one the last things I'd close. Block it for yourself and only your machine and perhaps your personal device on BYOD. I've seen some HTTP calls on Win11 to some random places that when blocked, destroy the taskbar. Why....no idea! I mean, try it, but I imagine it's the least of your worries!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now