SSFC Posted April 30, 2009 Posted April 30, 2009 We have recently implemented a network access solution so that students can access the wireless network and get filtered internet access. Currently we use Inty as our filter and firewall. Before we give the students the information to access this we want to make sure they can’t use up bandwidth playing multiplayer games (e.g. call of duty) or worse use the college internet connection to download copyrighted material. Ideally we would like to block all ports except for those needed (e.g.: 80, 25, etc) Has anyone implemented a similar blocking policy? If so what ports have you white listed? P.S The way our network is set up the policy would have to be college wide it’s not possible to isolate the wireless devices and apply a different policy.
pete Posted April 30, 2009 Posted April 30, 2009 Just a thought - wouldn't it be better to block 25 site-wide and then have a whitelist allow only for your mailservers/relays? Same with 80/443/21 and an in-house proxy server? Or can you not use rules on a per-ip/vlan level at all? 1
tech_guy Posted April 30, 2009 Posted April 30, 2009 D'oh and here was me reading the title of this thread and thinking we we're all going to go around agitating and smoking gitanes and muttering sacre bleu!
tom_newton Posted April 30, 2009 Posted April 30, 2009 We run with no ports open here for "general population" - all outbound access is proxied. This is a good way to start. I would always suggest you spend an hour or two on implications if you are opening a port out, and probably sleep on it if someone asks for a port in! 1
FN-GM Posted April 30, 2009 Posted April 30, 2009 One problem i could see is a website that might use other ports than 80 or 443
MattMitchell Posted May 11, 2009 Posted May 11, 2009 Definitely proxy only in my book. It might be worth considering getting a content filter too, as it's very easy to access sites using google/wayback machine cache...
ZeroHour Posted May 11, 2009 Posted May 11, 2009 One problem i could see is a website that might use other ports than 80 or 443 Yeh but there really are not many that do that. You only have 8080/80 and 443 to worry about as without the server being on 80 the url wont work without a port specified. For the odd sites you can always make a rule if possible saying if xsite.com allow port 90 etc. BTW love the title lol
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now