<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to block instant messaging applications (socks protocol) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525315#M525752</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much. It is good now.&lt;/P&gt;&lt;P&gt;I have three small questions please &lt;/P&gt;&lt;P&gt;1- I don't know how tu use "netstat" command to see what servers messenger is connecting to.&lt;/P&gt;&lt;P&gt;2- How I can see the statistics about my "acl-inside"&lt;/P&gt;&lt;P&gt;3- After changing my TFTP server IP address on my Pix, I'm not able to save Pix configuration on my tftp server. I have the following error message "Building configuration &lt;/P&gt;&lt;P&gt;TFTP write /FAS/Pixconf at 10.75.3.13 on interface 1 Timed out attempting to connect"&lt;/P&gt;&lt;P&gt;[FAILED]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ferdinand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Apr 2006 08:02:36 GMT</pubDate>
    <dc:creator>fmemevegny</dc:creator>
    <dc:date>2006-04-11T08:02:36Z</dc:date>
    <item>
      <title>How to block instant messaging applications (socks protocol) on my pix 515</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525307#M525732</link>
      <description>&lt;P&gt;I would like to block all instant messaging applications trafic on my pix 515. Some of them use socks protocol. Can someone help me to block these applications or this socks protocol on my pix 515 ?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:49:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525307#M525732</guid>
      <dc:creator>fmemevegny</dc:creator>
      <dc:date>2020-02-21T08:49:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525308#M525736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This was just answered by a thread below.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group service MSN_Messenger_tcp tcp &lt;/P&gt;&lt;P&gt;description MSN Messenger tries to use these ports &lt;/P&gt;&lt;P&gt;port-object eq www &lt;/P&gt;&lt;P&gt;port-object eq 1863 &lt;/P&gt;&lt;P&gt;port-object eq 7001 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;object-group network MSN_Messenger_hosts &lt;/P&gt;&lt;P&gt;description hosts that MSN Messenger lives on &lt;/P&gt;&lt;P&gt;network-object 65.54.195.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;network-object 65.54.225.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;network-object 65.54.226.0 255.255.254.0 &lt;/P&gt;&lt;P&gt;network-object 65.54.228.0 255.255.254.0 &lt;/P&gt;&lt;P&gt;network-object host 65.54.240.61 &lt;/P&gt;&lt;P&gt;network-object host 65.54.240.62 &lt;/P&gt;&lt;P&gt;network-object 207.46.104.0 255.255.252.0 &lt;/P&gt;&lt;P&gt;network-object 207.46.108.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;network-object 207.68.171.0 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-inside deny tcp any object-group MSN_Messenger_hosts object-group MSN_Messenger_tcp &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply this to an acl on your inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Apr 2006 22:37:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525308#M525736</guid>
      <dc:creator>Patrick Laidlaw</dc:creator>
      <dc:date>2006-04-06T22:37:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525309#M525739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much for your help.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 16:31:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525309#M525739</guid>
      <dc:creator>fmemevegny</dc:creator>
      <dc:date>2006-04-07T16:31:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525310#M525742</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ferdinand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was wondering if you would rate this solution or check it if this solved your problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Apr 2006 20:06:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525310#M525742</guid>
      <dc:creator>Patrick Laidlaw</dc:creator>
      <dc:date>2006-04-07T20:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525311#M525746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I correctly do what you tell me, but after applying the ACL on my inside interface, Internet access become impossible ; users cannot accede to Internet.&lt;/P&gt;&lt;P&gt;Can you tell why ?&lt;/P&gt;&lt;P&gt;I need your help please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ferdinand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 16:25:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525311#M525746</guid>
      <dc:creator>fmemevegny</dc:creator>
      <dc:date>2006-04-10T16:25:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525312#M525748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you apply an explicit deny to the interface you also need to put an explicit permit.  Did you apply this on the inside interface going out?  If so, you need an &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list (ACLNAME) permit ip any any &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 19:08:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525312#M525748</guid>
      <dc:creator>joneschw1</dc:creator>
      <dc:date>2006-04-10T19:08:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525313#M525750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not put an explicit permit. I will do it tomorrow and will inform you.&lt;/P&gt;&lt;P&gt;However when I apply the ACL on the inside interface going out, I have error. But when I apply it on the inside interface going in, I have no error. &lt;/P&gt;&lt;P&gt;Can you tell me why ?&lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ferdinand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 20:01:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525313#M525750</guid>
      <dc:creator>fmemevegny</dc:creator>
      <dc:date>2006-04-10T20:01:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525314#M525751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ferdinand,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list acl-inside deny tcp any object-group MSN_Messenger_hosts object-group MSN_Messenger_tcp&lt;/P&gt;&lt;P&gt;access-list acl-inside permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry I was just giving you the exact line that you would need to block msn messenger. You may have to add more to your Messenger Hosts object group depending on the servers you connect to.  The easiest way to do this is by running netstat on your pc to see what servers messenger is connecting to.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Patrick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Apr 2006 22:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525314#M525751</guid>
      <dc:creator>Patrick Laidlaw</dc:creator>
      <dc:date>2006-04-10T22:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: How to block instant messaging applications (socks protocol)</title>
      <link>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525315#M525752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Patrick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much. It is good now.&lt;/P&gt;&lt;P&gt;I have three small questions please &lt;/P&gt;&lt;P&gt;1- I don't know how tu use "netstat" command to see what servers messenger is connecting to.&lt;/P&gt;&lt;P&gt;2- How I can see the statistics about my "acl-inside"&lt;/P&gt;&lt;P&gt;3- After changing my TFTP server IP address on my Pix, I'm not able to save Pix configuration on my tftp server. I have the following error message "Building configuration &lt;/P&gt;&lt;P&gt;TFTP write /FAS/Pixconf at 10.75.3.13 on interface 1 Timed out attempting to connect"&lt;/P&gt;&lt;P&gt;[FAILED]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Ferdinand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Apr 2006 08:02:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-block-instant-messaging-applications-socks-protocol-on-my/m-p/525315#M525752</guid>
      <dc:creator>fmemevegny</dc:creator>
      <dc:date>2006-04-11T08:02:36Z</dc:date>
    </item>
  </channel>
</rss>

