Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules for Skype

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 6 Posters 13.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V
      vjun
      last edited by

      Hi all,

      I am using pfSense as NAT and proxy server.
      There are some specific computers that should have their Skype access blocked. I tried with L7 but it doesn't work. I add the Skype rules there then test creating a firewall rule for a specific IP and the L7 rule. Still able to connect.

      Some people suggested to use Snort. But the tutorials I found look different, as they show pfSense 1.2 and I am using 2.0.

      Can anybody help me?

      Thanks,
      V.

      1 Reply Last reply Reply Quote 0
      • N
        nexusN
        last edited by

        @vjun:

        Hi all,

        I am using pfSense as NAT and proxy server.
        There are some specific computers that should have their Skype access blocked. I tried with L7 but it doesn't work. I add the Skype rules there then test creating a firewall rule for a specific IP and the L7 rule. Still able to connect.

        Some people suggested to use Snort. But the tutorials I found look different, as they show pfSense 1.2 and I am using 2.0.

        Can anybody help me?

        Thanks,
        V.

        I needed no rules to get Skype work, including video chat, so I don't think it's rooted from pf.

        1 Reply Last reply Reply Quote 0
        • V
          vjun
          last edited by

          I think you didn't understand.

          I was asking for rules to block Skype.

          1 Reply Last reply Reply Quote 0
          • D
            dhatz
            last edited by

            It's hard to block Skype.

            Your best bets would be:

            1. L7
            2. if feasible in your setup, you could try blocking all ports except 80,443 then fwd that traffic to Squid, and do something like this http://wiki.squid-cache.org/ConfigExamples/Chat/Skype
            3. Snort
            1 Reply Last reply Reply Quote 0
            • J
              jigpe
              last edited by

              Get all CIDR of skype, create alias and put all the ips, create alias for skype's ports..After done editing your alias, go to firewall LAN create a rule to reject cidr and ports of skype. Hope this help.

              jigp

              1 Reply Last reply Reply Quote 0
              • R
                rajeewa
                last edited by

                Read this article was very helpful to u ;D

                http://www.carbonwind.net/Firewalls/BlockingSkypewithPfsenseandSnort/BlockingSkypewithPfsenseandSnort.htm

                1 Reply Last reply Reply Quote 0
                • pozoleroP
                  pozolero Rebel Alliance
                  last edited by

                  You can restrict navigation by ip address and skype won't connect  ;D

                  I have this at work…

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.