<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Blocking Skype in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593603#M65393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are three GUI based options to connect to IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Using ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Try to connect to 'Intrusion Prevention System' device from with ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Using IDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Try &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;SENSOR&gt; in a browser and you'll get an option to install/run IDM.&lt;/SENSOR&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Using IME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; Check this link:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps9610/index.html"&gt;http://www.cisco.com/en/US/products/ps9610/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Once installed, try to add your sensor to IME. You can manage upto 5 sensors using IME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you're connected to your sensor via one of the above methods, the following link should carry you through the steps of creating a customer signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html#wp2145569"&gt;http://www.cisco.com/en/US/partner/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html#wp2145569&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll need 'service http' type customer signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 28 Mar 2011 13:19:22 GMT</pubDate>
    <dc:creator>padatta</dc:creator>
    <dc:date>2011-03-28T13:19:22Z</dc:date>
    <item>
      <title>Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593600#M65388</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is my first post in the IPS section, so I am a IPS newbie.....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone tell me how I can block any skype traffic and facebook traffic using my IPS SSM-10 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Colin&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:18:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593600#M65388</guid>
      <dc:creator>IrishMann</dc:creator>
      <dc:date>2019-03-10T12:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593601#M65389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use signature &lt;SPAN class="data1"&gt;11251 to block skype. &lt;/SPAN&gt;&lt;SPAN class="data2"&gt;This signature fires when a Windows Skype client&amp;nbsp; connect to the Skype server to synchronize its version. So you can configure 'drop packet inline' along with 'produce alert' as an action. Therefore you can identify the host trying to use 'skype' client and proceed accordingly. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To block facebook, you can create a customer signature which matches /facebook./com/ in http header and configure actions like 'reset', 'deny connection', etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 14:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593601#M65389</guid>
      <dc:creator>padatta</dc:creator>
      <dc:date>2011-03-25T14:54:53Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593602#M65391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Padatta,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where can I create and apply that custom signature ? I am using ASDM 6.2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Mar 2011 17:25:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593602#M65391</guid>
      <dc:creator>IrishMann</dc:creator>
      <dc:date>2011-03-25T17:25:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593603#M65393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are three GUI based options to connect to IPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Using ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Try to connect to 'Intrusion Prevention System' device from with ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Using IDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Try &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&lt;SENSOR&gt; in a browser and you'll get an option to install/run IDM.&lt;/SENSOR&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. Using IME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; Check this link:&amp;nbsp; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/ps9610/index.html"&gt;http://www.cisco.com/en/US/products/ps9610/index.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Once installed, try to add your sensor to IME. You can manage upto 5 sensors using IME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once you're connected to your sensor via one of the above methods, the following link should carry you through the steps of creating a customer signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html#wp2145569"&gt;http://www.cisco.com/en/US/partner/docs/security/ips/7.0/configuration/guide/idm/idm_signature_wizard.html#wp2145569&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You'll need 'service http' type customer signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Mar 2011 13:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593603#M65393</guid>
      <dc:creator>padatta</dc:creator>
      <dc:date>2011-03-28T13:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593604#M65395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hello,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Signature will not be compleletely effective in blocking Skype traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;BR /&gt;Signature 11251-0 only blocks exchanges with the host skype.com in the&lt;BR /&gt;packets. The only time this occurs is when the version is checked and not&lt;BR /&gt;during the actual phone calls. This is usually done when the client is started. &lt;BR /&gt;Again, this means that Skype traffic is not what fires this signature. &lt;BR /&gt;It is the client connecting to Skype to sync its version.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Skype uses an aggressive adaptive networking application that is designed to&lt;BR /&gt;reach the Internet. Skype sessions use an asymmetric key&lt;BR /&gt;exchange to distribute the 256 bit symmetric key employed by the AES cipher&lt;BR /&gt;for session encryption. Skype's initial outbound connection can use any&lt;BR /&gt;dynamic combination of TCP and UDP ports, including outbound ports 80 and&lt;BR /&gt;443, which are generally open for HTTP and HTTPS access. This renders&lt;BR /&gt;traditional port blocking filters completely ineffective. In addition, Skype&lt;BR /&gt;uses proprietary methods of NAT traversal similar to STUN (Simple Traversal&lt;BR /&gt;of UDP through NAT), ICE (Interactive Connectivity Establishment) and TURN&lt;BR /&gt;(Traversal Using Relay NAT) to ensure that you can reach the Internet and to&lt;BR /&gt;determine the client's eligibility to be a super node.&lt;BR /&gt;&lt;BR /&gt;Because Skype uses a proprietary, encrypted protocol, specifically designed&lt;BR /&gt;to avoid detection and penetrate NAT, Firewalls and other network&lt;BR /&gt;instrumentations there is no formal method for any DPI technology to perform&lt;BR /&gt;compliant inspection of Skype traffic flows.&lt;BR /&gt;&lt;BR /&gt;However there has been a bug filed on this and the development team is&lt;BR /&gt;working on it.&lt;BR /&gt;&lt;BR /&gt;Bug:&lt;/SPAN&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif; "&gt;CSCsh60496&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsh60496"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsh60496&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Sid Chandrachud&lt;BR /&gt;TAC security solutions&lt;BR /&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Mar 2011 23:38:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593604#M65395</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-03-28T23:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593605#M65399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wow ... that has to be one of the most informative posts I've read in a while.&amp;nbsp; Great info, Sid!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 00:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593605#M65399</guid>
      <dc:creator>mikecrowe4ICS_2</dc:creator>
      <dc:date>2011-03-29T00:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593606#M65402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Sid, excellent write up. Its no wonder I am killing myself trying to block this thing. Still no luck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again for the info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers &lt;SPAN __jive_emoticon_name="laugh" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/laugh.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Mar 2011 12:33:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593606#M65402</guid>
      <dc:creator>IrishMann</dc:creator>
      <dc:date>2011-03-29T12:33:51Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking Skype</title>
      <link>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593607#M65404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Siddharth,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any progress on this issue of blocking skype through IPS ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Fazal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 15 Mar 2012 05:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/blocking-skype/m-p/1593607#M65404</guid>
      <dc:creator>fazalunus</dc:creator>
      <dc:date>2012-03-15T05:50:19Z</dc:date>
    </item>
  </channel>
</rss>

