1848590 Members
3791 Online
104033 Solutions
New Discussion

Re: Block Skype

 
Daniel Caçador
Regular Advisor

Block Skype

Oi!
How I block skype? I am using proxy squid and the IPTables.

Thanks!
2 REPLIES 2
Steven E. Protter
Exalted Contributor

Re: Block Skype

Shalom,

Figure out what ports skype uses and use iptables to block it.

Lets say its port 33500

iptables -A INPUT -p all --dport 33500 -j DROP

Some variation of that.

Or you could do this:

http://www.fs-security.com

Install firestarter. Configure the firewall in a corporate way, e.g. blacklist everything only allow the ports you want inbound and outbound. Firestarter is an iptables code generator and lets you use an X gui to save coding time.

SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Geoff Wild
Honored Contributor

Re: Block Skype

It may be possible to use the following:

Block the hard coded nodes IPs for Skype : (this must be done on the gateway or the firewall)

66.235.180.9
66.235.181.9
80.160.91.12
80.161.91.25
212.72.49.141
212.72.49.142
212.72.49.143
195.215.8.141
195.215.8.145
64.246.49.61
64.246.49.60
64.246.48.23

Use iptables to block them from a linux gateway:

iptables -A FORWARD -p udp -i eth1 -d 66.235.180.9 -j DROP
.........
.....
....
iptables -A FORWARD -p udp -i eth1 -d 64.246.48.23 -j DROP

that was to UDP packets , repeat the same for TCP :

iptables -A FORWARD -p tcp -i eth1 -d 66.235.180.9 -j DROP
.........
.....
....
iptables -A FORWARD -p tcp -i eth1 -d 64.246.48.23 -j DROP


Other methods to block skype is by using a proxy server and disabling IP string addressed and rejecting the CONNECT command. But using proxy server just to prevent users from using skype is not a good idea.



Rgds...Geoff
Proverbs 3:5,6 Trust in the Lord with all your heart and lean not on your own understanding; in all your ways acknowledge him, and he will make all your paths straight.