Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Rules for Skype

    Scheduled Pinned Locked Moved Firewalling
    7 Posts 6 Posters 13.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • V Offline
      vjun
      last edited by

      Hi all,

      I am using pfSense as NAT and proxy server.
      There are some specific computers that should have their Skype access blocked. I tried with L7 but it doesn't work. I add the Skype rules there then test creating a firewall rule for a specific IP and the L7 rule. Still able to connect.

      Some people suggested to use Snort. But the tutorials I found look different, as they show pfSense 1.2 and I am using 2.0.

      Can anybody help me?

      Thanks,
      V.

      1 Reply Last reply Reply Quote 0
      • N Offline
        nexusN
        last edited by

        @vjun:

        Hi all,

        I am using pfSense as NAT and proxy server.
        There are some specific computers that should have their Skype access blocked. I tried with L7 but it doesn't work. I add the Skype rules there then test creating a firewall rule for a specific IP and the L7 rule. Still able to connect.

        Some people suggested to use Snort. But the tutorials I found look different, as they show pfSense 1.2 and I am using 2.0.

        Can anybody help me?

        Thanks,
        V.

        I needed no rules to get Skype work, including video chat, so I don't think it's rooted from pf.

        1 Reply Last reply Reply Quote 0
        • V Offline
          vjun
          last edited by

          I think you didn't understand.

          I was asking for rules to block Skype.

          1 Reply Last reply Reply Quote 0
          • D Offline
            dhatz
            last edited by

            It's hard to block Skype.

            Your best bets would be:

            1. L7
            2. if feasible in your setup, you could try blocking all ports except 80,443 then fwd that traffic to Squid, and do something like this http://wiki.squid-cache.org/ConfigExamples/Chat/Skype
            3. Snort
            1 Reply Last reply Reply Quote 0
            • J Offline
              jigpe
              last edited by

              Get all CIDR of skype, create alias and put all the ips, create alias for skype's ports..After done editing your alias, go to firewall LAN create a rule to reject cidr and ports of skype. Hope this help.

              jigp

              1 Reply Last reply Reply Quote 0
              • R Offline
                rajeewa
                last edited by

                Read this article was very helpful to u ;D

                http://www.carbonwind.net/Firewalls/BlockingSkypewithPfsenseandSnort/BlockingSkypewithPfsenseandSnort.htm

                1 Reply Last reply Reply Quote 0
                • pozoleroP Offline
                  pozolero Rebel Alliance
                  last edited by

                  You can restrict navigation by ip address and skype won't connect  ;D

                  I have this at work…

                  1 Reply Last reply Reply Quote 0
                  • First post
                    Last post
                  Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.