maniac Posted January 24, 2013 Posted January 24, 2013 Hello All, I am trying to block the use of iMessage and Facetime on iPads on our wireless network. I know the ports I need to block, but can anyone shed light on how I might program this into a meru wireless system, or into the settings for a Vlan on an HP managed switch? I am not the most experienced person when dealing with these types of systems, so an 'idiots guide' would be helpful! Cheers, Mike.
CyberNerd Posted January 24, 2013 Posted January 24, 2013 It would be better to do it on the firewall by VLAN.
twin--turbo Posted January 24, 2013 Posted January 24, 2013 Meru Configuration > QOS > System Settings > QOS and Firewall Rules. Rob 1
twin--turbo Posted January 24, 2013 Posted January 24, 2013 It would be better to do it on the firewall by VLAN. If there system is configured so that the client user/machines are on a vlan that can be controlled by the FW. It can be done on Meru Firewall, and on the HP usigng ACL's on the vlan. Rob
maniac Posted January 24, 2013 Author Posted January 24, 2013 It would be better to do it on the firewall by VLAN. I've been told by our broadband support that iDevices using iMessage and Facetime between each other internally don't go anywhere outside the network, the communication is directly between the devices, hence the need to block this internally and not on the firewall. Our firewall is not aware of our internal VLANS anyway, but we do have a good setup with seperate VLANS for various aspects of the system all on managed switches. Cheers twin--turbo I will have a look at those settings on the Meru controller, that should be a good enough pointer to get me going. Regards, Mike.
twin--turbo Posted January 24, 2013 Posted January 24, 2013 You may need to block all inter-client traffic on the wireless to prevent clients talking to each other. This is not too hard with Meru's firewall. Rob
maniac Posted January 24, 2013 Author Posted January 24, 2013 You may need to block all inter-client traffic on the wireless to prevent clients talking to each other. This is not too hard with Meru's firewall. Rob Any ideas how? I'm not overly familiar with the Meru configuration, it was setup for us and I've only made minor changes to it since. I could get the company who set it up to come in and do this, but obviously they'll charge us so I thought I'd have a look myself first, afterall how hard could it be. More tricky than I thought as I don't really understand the way the firewall settings work on the Meru box.
twin--turbo Posted January 24, 2013 Posted January 24, 2013 Well to block P2P traffic have a rule Src IP (IP of wifi network ) mask ( Mask of wifi Network ) Dest IP (IP of wifi network) mask (Mask of wif Network) Set it to match on Src and Dest IP Action DROP You will need a rule befor that with the destination as your default route for that vlan to pass. ( so that traffic can get to the rest of the network ) And then some further rules to block and other ports you don't want to go through the router. Rob
mhowell Posted January 25, 2013 Posted January 25, 2013 Mike Happy to help out directly if you need it, [email protected] and [email protected] It's something a lot of schools are looking to do and its a regular question thx
twin--turbo Posted January 25, 2013 Posted January 25, 2013 Mike Happy to help out directly if you need it, [email protected] and [email protected] It's something a lot of schools are looking to do and its a regular question thx And that's how we know how it's done thanks to Mark & Paul. Better to stop the traffic sooner rather than later in teh chain if possible Rob
grcmptrnrd Posted May 7, 2015 Posted May 7, 2015 Sorry to drag up an old thread, but my question is somewhat related. Can the Meru firewall be set up to only allow a client to use it's DHCP-assigned IP? Question comes up as our web filter relies on IP addresses and students can change their IP manually (BYOD & student-owned Chromebooks) & try to find one in range that's still authenticated as someone else but currently unused and cause mischief. I thought this may be possible as the Meru WiFi is already inspecting DHCP packets for client type identification.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now