Forums

Skip to content

Advanced search
  • Quick links
    • Unanswered topics
    • Active topics
    • Search
  • FAQ
  • Login
  • Register
  • Board index Assistance Networking & Security
  • Search

Internet Restrictions

Having problems getting connected to the internet or running a server? Wondering about securing your box? Ask here.
Post Reply
Advanced search
5 posts • Page 1 of 1
Author
Message
alexluna
n00b
n00b
Posts: 27
Joined: Thu Oct 05, 2006 6:09 pm

Internet Restrictions

  • Quote

Post by alexluna » Thu Feb 28, 2008 10:28 pm

Hi all!!

i Have seen that there are routers that just allow to view web content, i would like to allow to my clients just browser the web, no MSN, no radio, no video.

how i could do that?
Top
coolsnowmen
Veteran
Veteran
User avatar
Posts: 1479
Joined: Wed Jun 30, 2004 6:52 pm
Location: No.VA

  • Quote

Post by coolsnowmen » Thu Feb 28, 2008 10:49 pm

blocking outbound access to TCP port 1863, and outbound HTTP access to messenger.hotmail.com. should stop msn

allow only requesting port 80 out....
block all incoming


and blocking ALL UDP access would stop streaming

(I think)

edit: it appears alot of things can still tunnel through TCP/port 80, (with the express purpose of evading filtering) so if something is getting through like that, you need to get even lower into packet/content inspection
emerge: there are no ebuilds to satisfy "moo"
Top
alexluna
n00b
n00b
Posts: 27
Joined: Thu Oct 05, 2006 6:09 pm

  • Quote

Post by alexluna » Thu Feb 28, 2008 11:55 pm

something like layer 7?
Top
coolsnowmen
Veteran
Veteran
User avatar
Posts: 1479
Joined: Wed Jun 30, 2004 6:52 pm
Location: No.VA

  • Quote

Post by coolsnowmen » Fri Feb 29, 2008 12:08 am

I am not experienced with it, I also don't like how the OSI model describes things

But I'll attempt and say 6/7, as the "tunneling" app is doing this to evade detection, I don't know how you block it. Except I understand the idea of fingerprinting the payload.
Say you accept the TCP/IP connection out to port 80, but the first String back says
"Contentent type: radio, prepare for music", and you match that and reject the connection.

As in, if layer 6 species protocol like http versus ftp, something could be TCP/IP over port 80 but not be an http stream. So then you filter out all non http traffic, and that is filtering at layer 6.

So the smart person, writes their app, to encapsulate their traffice on TCP.IP on port 80, in http, and you are non the wiser, now you need to filter at level 7

At least that is how I understand it, again, I've only done protocol(UDP/ICMP/TCP), IP, and port matching
emerge: there are no ebuilds to satisfy "moo"
Top
coolsnowmen
Veteran
Veteran
User avatar
Posts: 1479
Joined: Wed Jun 30, 2004 6:52 pm
Location: No.VA

  • Quote

Post by coolsnowmen » Sat Mar 08, 2008 6:46 am

http://forums.gentoo.org/viewtopic-t-67 ... ight-.html
emerge: there are no ebuilds to satisfy "moo"
Top
Post Reply

5 posts • Page 1 of 1

Return to “Networking & Security”

Jump to
  • Assistance
  • ↳   News & Announcements
  • ↳   Frequently Asked Questions
  • ↳   Installing Gentoo
  • ↳   Multimedia
  • ↳   Desktop Environments
  • ↳   Networking & Security
  • ↳   Kernel & Hardware
  • ↳   Portage & Programming
  • ↳   Gamers & Players
  • ↳   Other Things Gentoo
  • ↳   Unsupported Software
  • Discussion & Documentation
  • ↳   Documentation, Tips & Tricks
  • ↳   Gentoo Chat
  • ↳   Gentoo Forums Feedback
  • ↳   Duplicate Threads
  • International Gentoo Users
  • ↳   中文 (Chinese)
  • ↳   Dutch
  • ↳   Finnish
  • ↳   French
  • ↳   Deutsches Forum (German)
  • ↳   Diskussionsforum
  • ↳   Deutsche Dokumentation
  • ↳   Greek
  • ↳   Forum italiano (Italian)
  • ↳   Forum di discussione italiano
  • ↳   Risorse italiane (documentazione e tools)
  • ↳   Polskie forum (Polish)
  • ↳   Instalacja i sprzęt
  • ↳   Polish OTW
  • ↳   Portuguese
  • ↳   Documentação, Ferramentas e Dicas
  • ↳   Russian
  • ↳   Scandinavian
  • ↳   Spanish
  • ↳   Other Languages
  • Architectures & Platforms
  • ↳   Gentoo on ARM
  • ↳   Gentoo on PPC
  • ↳   Gentoo on Sparc
  • ↳   Gentoo on Alternative Architectures
  • ↳   Gentoo on AMD64
  • ↳   Gentoo for Mac OS X (Portage for Mac OS X)
  • Board index
  • All times are UTC
  • Delete cookies

© 2001–2026 Gentoo Foundation, Inc.

Powered by phpBB® Forum Software © phpBB Limited

Privacy Policy

 

 

magic