Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


1 post

Wannabe Geek


Topic # 6543 2-Feb-2006 14:31
Send private message

How can I block stuff like msn chat or aim. or what ports does IE need to operate so I can block everything else.

Create new topic
1420 posts

Uber Geek

Trusted

Reply # 27716 2-Feb-2006 18:51
Send private message

May not be a good idea to block to many ports. Generally your router should allow normal things like web browsing, email, ftp, etc. Incoming obscure ports/IP's should already be blocked if your router has PAT and NAT.

What you need to do is block the application (which is what I do) and Zone Alarm is good at blocking programs. It will ask you if you want allow MSN access to the internet just say no and 'remember this setting'.

Hawkes Bay
8477 posts

Uber Geek
+1 received by user: 4

Mod Emeritus
Trusted
Lifetime subscriber

  Reply # 27728 2-Feb-2006 23:36
Send private message

Block anything you dont want people using. The more blocked ports the better if you want to lock things down and prevent users from doing unproductive things or wasting bandwidth.

(Not such a happy scenario for the (l)user, but hey, thats life.)

Check out this list of ports and applications, and if you are still hungry after that, have some pudding.







BDFL - Memuneh
61333 posts

Uber Geek
+1 received by user: 12080

Administrator
Trusted
Geekzone
Lifetime subscriber

Reply # 27744 3-Feb-2006 08:09
Send private message

Apply Deny All first and then open only the ports you need - at first these will be absolutely none.

Most routers only allow configuration of Incoming connection filtering, so really you shouldn't have any incoming connection allowed at all, unless you run a server of any kind.

As for blocking your users from accessing outgoing connections: routers will not do it for the reason I wrote in the previous paragraph. If this is your need, then you should consider a hardware firewall for an entire organisation (there are some boxes that will do this, including for example Chili box and some other dedicate appliances) or consider releasing a software firewall with central configuration where an administrator can deploy policies that can not be changed locally by users.





Create new topic

Twitter »

Follow us to receive Twitter updates when new discussions are posted in our forums:



Follow us to receive Twitter updates when news items and blogs are posted in our frontpage:



Follow us to receive Twitter updates when tech item prices are listed in our price comparison site:



Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.

Alternatively, you can receive a daily email with Geekzone updates.