<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Blocking VoIP Such as FaceTime in OpenDNS</title>
    <link>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175196#M1908</link>
    <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Trying to figure out how to block FaceTime on my home network.&lt;/P&gt;
&lt;P&gt;I have searched for ways to block Facetime and have only come up with blocking certain ports. &amp;nbsp;Yet.. &amp;nbsp;it seems that blocking the specified ports pretty much blocks everything else also (web, youtube etc.)&lt;/P&gt;
&lt;P&gt;Any help getting facetime blocked would be great.&lt;/P&gt;
&lt;P&gt;Wasn't sure if I could do it through OpenDNS.. ??&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Sun, 12 Feb 2017 19:50:56 GMT</pubDate>
    <dc:creator>iprey</dc:creator>
    <dc:date>2017-02-12T19:50:56Z</dc:date>
    <item>
      <title>Blocking VoIP Such as FaceTime</title>
      <link>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175196#M1908</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;Trying to figure out how to block FaceTime on my home network.&lt;/P&gt;
&lt;P&gt;I have searched for ways to block Facetime and have only come up with blocking certain ports. &amp;nbsp;Yet.. &amp;nbsp;it seems that blocking the specified ports pretty much blocks everything else also (web, youtube etc.)&lt;/P&gt;
&lt;P&gt;Any help getting facetime blocked would be great.&lt;/P&gt;
&lt;P&gt;Wasn't sure if I could do it through OpenDNS.. ??&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Sun, 12 Feb 2017 19:50:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175196#M1908</guid>
      <dc:creator>iprey</dc:creator>
      <dc:date>2017-02-12T19:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VoIP Such as FaceTime</title>
      <link>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175197#M1909</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;If you can identify the domains that facetime uses then OpenDNS can block it.&lt;/P&gt;
&lt;P&gt;Be aware that the FaceTime may not use domains, but may instead directly address IP addresses. Also, be aware, the domains can vary by operating system or even the specific app version that you are using.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Feb 2017 06:59:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175197#M1909</guid>
      <dc:creator>mattwilson9090</dc:creator>
      <dc:date>2017-02-13T06:59:12Z</dc:date>
    </item>
    <item>
      <title>Re: Blocking VoIP Such as FaceTime</title>
      <link>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175198#M1910</link>
      <description>&lt;DIV class="opendns-migrated-content"&gt;&lt;P&gt;From &lt;A href="https://discussions.apple.com/thread/3963202?start=0&amp;amp;tstart=0" rel="nofollow noreferrer"&gt;https://discussions.apple.com/thread/3963202?start=0&amp;amp;tstart=0&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;I have recently blocked iMessage at the firewall and thought I would share.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Blocking port 5223 alone is not enough (but still necessary) and &lt;STRONG&gt;blocking any domain names (ie. albert.apple.com etc.) will not work&lt;/STRONG&gt;.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The block needs to happen at the IP address level - here is the approach I took:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;There are three ranges of IPs that iMessage uses and need blocking:&lt;BR /&gt;17.173.0.1 to 17.173.255.255&lt;BR /&gt;17.178.0.1 to 17.178.255.255&lt;BR /&gt;17.133.0.1 to 17.133.255.255&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Obviously, these are large IP ranges and likely contain services that you still want to use (ie. App Store). There, explicitly ALLOW the following range to enable the App Store:&lt;BR /&gt;17.173.65.1 to 17.173.65.255&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Caveats:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;1. We have only just implemented this block and therefore there may be other Apple services we are not aware of yet that need to be included in the 'Allow' rule.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;2. This block also blocks FaceTime&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;3. With the block in place, the 'Messages' app appears to take a very long time to deliver the message but eventually reports it as delivered. The message does not actually get sent and thus not delivered.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;See also &lt;A href="https://support.apple.com/en-us/HT202078" rel="nofollow noreferrer"&gt;https://support.apple.com/en-us/HT202078&lt;/A&gt; about the ports being used.&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;Blocking VoIP Such as FaceTime&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;FaceTime is not really VoIP.&amp;nbsp; If you want to block VoIP, a widely used standard is SIP/RTP where you can block SIP by port (UDP+TCP 5060) and RTP by blocking high ports (UDP 7000-20000).&amp;nbsp; Another standard is IAX where you want to block ports UDP 5036 and 4569.&lt;/P&gt;
&lt;P&gt;However, I went through my OpenDNS domains stats and could identify lots of Apple related domains and CDNs.&amp;nbsp; Could well be that some are dedicated to FaceTime, so FaceTime could be blocked with OpenDNS.&amp;nbsp; You can find out only if you run a network sniffer.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 13 Feb 2017 13:43:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/opendns/blocking-voip-such-as-facetime/m-p/5175198#M1910</guid>
      <dc:creator>rotblitz</dc:creator>
      <dc:date>2017-02-13T13:43:29Z</dc:date>
    </item>
  </channel>
</rss>

